[cabfpub] Draft Ballot 185 - Limiting the Lifetime of Certificates

Gervase Markham gerv at mozilla.org
Fri Feb 3 07:59:06 UTC 2017

On 02/02/17 14:17, García Jimeno, Oscar via Public wrote:
> I’d like to give you some numbers of SSL certificates issued by Izenpe.
> We have DV (1, 2 or 3 years), OV (1, 2 or 3 years) and EV (1 or 2 years)
> certificates:

There seems to be a lot of confusion in this thread between correlation
and causation.

While avoiding discussing what the prices actually are, I would note
that unless there is no price advantage either way, the distribution of
certificates among different term lengths is likely to be a function of
price as well as anything else. So it's not reasonable necessarily to
conclude that customers "prefer" or "need" _longer_ certs; they might
just "prefer" _cheaper_ certs :-)

In other words, you can't reason from e.g. "customers buy 3-year certs"
to "customers need/prefer 3-year certs" unless there is no price
advantage in the system you are studying.


