root encryption certificates have lifetimes, set by the issuing authority. You’ve probably heard of random stories of web services having outtages because someone forgot to get new certificates issued before it was too late. It is the same concept here, except unrecoverable if missed, probably because you need the valid certificate to patch with the new one.
Up for debate is if they ever expected these units to be in service this long, or if they even had an option to get a longer lasting certificate back when they were designing them.
Up for debate is if they ever expected these units to be in service this long, or if they even had an option to get a longer lasting certificate back when they were designing them.

Comment