

I like that metaphor, I’m gonna save it. And agreed, there’s going to be issues with legacy systems.
Luckily, at my current job, all of our outside-facing legacy services already go through an SSL terminating reverse proxy. And we then use self-signed certs with much longer validity for internal traffic where needed.
Oh, I agree. This change will affect all CAs however. And their post seemed to contain the most amount of information.