Live data from Hacker News

Decreasing Certificate Lifetimes to 45 Days

letsencrypt.org

11–20 of 158 posts

Re: Decreasing Certificate Lifetimes to 45 Days

#12
post #3

"This change is being made along with the rest of the industry, as required by the CA/Browser Forum Baseline Requirements, which set the technical requirements that we must follow." I dont follow. Why? Why not an hour? A ssl failure is a very effective way to shut down a site. "you should verify that your automation is compatible with certificates that have shorter validity periods. To ensure your ACME client renews…

They've been slowly moving the time lower and lower. It will go lower than 45 days in the future, but the reason why we don't go immediately to 1 hour is that it would be too much of a shock.

>So every small site that took the LE bait needs expensive help to stay online.

It's all automated. They don't need help to stay online.

Re: Decreasing Certificate Lifetimes to 45 Days

#13

I'm sure this is for good reasons, but as someone that maintains a lot of ssl certificates, I'm not in love with this change. Sometimes things break with cert renewal, and it sometimes takes a chunk of time to detect and then sit down to properly fix those issues. This shortens the amount of time I will have to deal with that if it ever comes up (which is more often than you would expect), and increases the chances o…

What kind of issues do you usually face?

Forced changes for one.

Re: Decreasing Certificate Lifetimes to 45 Days

#14

I'm all for it -- it's hard to understate the extent to which LetsEncrypt has improved the WebPKI situation. Although the effective single-vendor situation isn't great, the "this is just something you only do via an automated API" approach is absolutely the right one. And certificate lifetimes measured in days work just fine with that. The only things that continue to amaze me are the number of (mostly "enterprise")…

It's not single-vendor. The ACME protocol is also supported by the likes of GlobalSign, Sectigo, and Digicert.

You've got to remember that the reduction to a 45-day duration is industry-wide - driven by the browsers. Any CA not offering automated renewal (which in practice means ACME) is going to lose a lot of customers over the next few years.

Re: Decreasing Certificate Lifetimes to 45 Days

#16

> The key advantage of [DNS-PERSIST-01] is that the DNS TXT entry used to demonstrate control does not have to change every renewal. > We expect DNS-PERSIST-01 to be available in 2026 Very exciting! https://datatracker.ietf.org/doc/html/draft-sheurich-acme-dn...

Big news for both the lazy homelab admin that can set a TXT once and ultimately be more secure without spraying DNS Zone Edit tokens all over their infra AND for the poor enterprise folks that have to open a ticket and wait 3 weeks for a DNS record.

Re: Decreasing Certificate Lifetimes to 45 Days

#17
post #3

"This change is being made along with the rest of the industry, as required by the CA/Browser Forum Baseline Requirements, which set the technical requirements that we must follow." I dont follow. Why? Why not an hour? A ssl failure is a very effective way to shut down a site. "you should verify that your automation is compatible with certificates that have shorter validity periods. To ensure your ACME client renews…

They've been slowly moving the time lower and lower. It will go lower than 45 days in the future, but the reason why we don't go immediately to 1 hour is that it would be too much of a shock. >So every small site that took the LE bait needs expensive help to stay online. It's all automated. They don't need help to stay online.

re too much shock, how so?

Re: Decreasing Certificate Lifetimes to 45 Days

#19
post #3

"This change is being made along with the rest of the industry, as required by the CA/Browser Forum Baseline Requirements, which set the technical requirements that we must follow." I dont follow. Why? Why not an hour? A ssl failure is a very effective way to shut down a site. "you should verify that your automation is compatible with certificates that have shorter validity periods. To ensure your ACME client renews…

They've been slowly moving the time lower and lower. It will go lower than 45 days in the future, but the reason why we don't go immediately to 1 hour is that it would be too much of a shock. >So every small site that took the LE bait needs expensive help to stay online. It's all automated. They don't need help to stay online.

Nope. I renew my LE certs manually. I take my http server down, run certbot, and pull http back online
Post reply on HN