|
|
Subscribe / Log in / New account

Short lived certificate

Short lived certificate

Posted Aug 29, 2025 14:37 UTC (Fri) by raven667 (subscriber, #5198)
In reply to: Short lived certificate by Cyberax
Parent article: Linux's missing CRL infrastructure

Do hosts not *also* get a stable management address, either EUI-64 based on the MAC (ff:fe old style) or the newer RFC7217 "stable privacy" address based on network prefix, interface, SSID, machine UUID? The temporary privacy addresses should be used for outbound connections based on their preferred lifetime but if you run services the management address should be usable, `scope global dynamic mngtmpaddr noprefixroute` vs `scope global temporary dynamic`.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds