Short lived certificate
Short lived certificate
Posted Aug 29, 2025 14:37 UTC (Fri) by raven667 (subscriber, #5198)In reply to: Short lived certificate by Cyberax
Parent article: Linux's missing CRL infrastructure
Do hosts not *also* get a stable management address, either EUI-64 based on the MAC (ff:fe old style) or the newer RFC7217 "stable privacy" address based on network prefix, interface, SSID, machine UUID? The temporary privacy addresses should be used for outbound connections based on their preferred lifetime but if you run services the management address should be usable, `scope global dynamic mngtmpaddr noprefixroute` vs `scope global temporary dynamic`.