Problem
Why do we include an expiration date in a public key certificate and also in a Kerberos ticket? What is the benefit of a longer lifetime (later expiration) to these credentials, and what is the benefit of a shorter lifetime? Why do we use a separate certificate status server (OCSP) with public key certificates when we do not use such a server with Kerberos?