BBetterSign· X.509-SVID, self-renewing 1 / 3

An SVID is a short-lived X.509 certificate — and it is always about to expire
X.509-SVID TTL 1h
SAN: spiffe://acme/svc-a
issuer: static CA
expiring — renew against the CA, again
Renew it every hour against a central CA. Miss one renewal and the workload drops offline.
The same X.509-SVID, issued and verified against a provenance log
X.509-SVID valid
SAN: spiffe://acme/svc-a
trust root: provenance log
signed & replayable
A verifier checks it against the plog-derived trust bundle → ✓ verified, no CA online required
It is a standard X.509-SVID every SPIFFE-aware tool understands — the difference is where the trust comes from.
The SVID renews itself before it expires — each renewal a signed entry
X.509-SVID TTL reset ✓
SAN: spiffe://acme/svc-a
↻ auto-renewed · new short-lived cert issued
Never expired, never dropped. SVIDs auto-renew before expiry · verifiers converge · no CRL or OCSP lag · no manual renewal