Guidance
Design and build a privately hosted Public Key Infrastructure
Principles for the design and build of in-house Public Key Infrastructure (PKI)
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 15 of 21
Short certificate lifetimes reduce the window of opportunity for an attacker, reducing the impact of a compromised key. This has the knock on effect of reducing reliance on revocation systems, making them easier to manage and maintain.
Short certificate lifetimes also provide an opportunity for you to evaluate whether an end entity still requires the certificate it's requesting.
If the private key has been stolen by an attacker, it will need to be regenerated, the certificate re-issued and the old certificate revoked. See principle 11 for more information.
End entity certificate lifetimes should be proportionate to the risk, use-case and administration overhead required to maintain the short-lived certificates.
Having short certificate lifetimes for an end entity will reduce the impact of compromise.
Root CAs
Root CAs should have longer lifetimes as they are the trust anchor for the entire PKI and renewing them requires all certificates in the chain to be reissued. Root CAs should, therefore, have appropriate protections in place to prevent them from being compromised.
Intermediate CAs
Intermediate CAs will have shorter lifetimes compared to the root CA. Their exact duration should depend on security threats, administration overhead, system availability and the costs of issuing new intermediate CA certificates.
Note that a certificate authority should not issue an end entity certificate after its own certificate is due to expire. The Intermediate CA certificates should be renewed before it gets to this point with the old certificate still being available so certificates that have already been issues can be validated.
A certificate authority should have a long certificate life time so it can, in turn, issue end certificates with a suitable life time.
Please note - both the Root and intermediate CA certificates will normally have life times of multiple years.


