Skip to content

Commit 2d85443

Browse files
nasantiaCBonnell
andauthored
CSC-31: Maximum Validity Reduction (#48)
* Update CSBR.md for proposed validity period change Updating to mostly match ian's original verbiage. However, given that we want at least 6 months to reflect the change after enforcmeent, setting the date to January 1st of 2026 instead of the original June 15th of 2025 * Update CSBR.md removing previous line to avoid confusion, and updating to March * Update docs/CSBR.md accepting change in verbiage to be clear on certificate life for certificates issued before Co-authored-by: Corey Bonnell <dev@cbonnell.com> * Update docs/CSBR.md removing an extra space Co-authored-by: Corey Bonnell <dev@cbonnell.com> --------- Co-authored-by: Corey Bonnell <dev@cbonnell.com>
1 parent f8b33cc commit 2d85443

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

docs/CSBR.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2029,7 +2029,7 @@ CAs SHALL ensure that the Subscriber’s Private Key is generated, stored, and u
20292029

20302030
Subscribers and Signing Services MAY sign Code at any point in the development or distribution process. Code Signatures may be verified at any time, including during download, unpacking, installation, reinstallation, or execution, or during a forensic investigation.
20312031

2032-
The validity period for a Code Signing Certificate issued to a Subscriber or Signing Service MUST NOT exceed 39 months.
2032+
For Code Signing Certificates issued before March 1st, 2026, the validity period MUST NOT exceed 39 months. For Code Signing Certificates issued on or after March 1st, 2026, the validity period MUST NOT exceed 460 days.
20332033

20342034
The Timestamp Certificate validity period MUST NOT exceed 135 months. The Timestamp Certificate Key Pair MUST meet the requirements in [Section 6.1.5](#615-key-sizes). The CA or Timestamp Authority SHALL NOT use a Private Key associated with a Timestamp Certificate more than 15 months after the `notBefore` date of a Timestamp Certificate.
20352035

0 commit comments

Comments
 (0)