Definition

TLS certificates are digital credentials binding a public key to a domain identity, enabling encrypted HTTPS communication. Issuance requires proving domain control through validation methods vulnerable to DNS compromise.

Key Points

  • 2026-10-07: lets-encrypt default lifetimes drop 90 → 64 days (prod 2026-02-10; staging 2026-10-14); path to 45 days in 2028—requires acme-protocol ARI and automated renewal at ~⅔ lifetime (2026-10-07-lets-encrypt-64-day-certs-official)

  • 2026-10-06: Unauthorized certs minted for Google and major brands after cctld-registry-hijack — systemic weakness in DV issuance when registries compromised

  • Mitigation: Certificate Transparency monitoring, CAA records (post-hijack value), browser CRLSet blocking

  • CAA cannot prevent issuance during active DNS hijack — attacker can rewrite CAA records too

Sources