Decreasing Certificate Lifetimes to 45 Days
letsencrypt.org
Decreasing Certificate Lifetimes to 45 Days
1–10 of 158 posts
Re: Decreasing Certificate Lifetimes to 45 Days
#2The only things that continue to amaze me are the number of (mostly "enterprise") software products that simply won't get with the times (or get it wrong, like renewing the cert, but continuing to use the old one until something is manually restarted), and the countless IT departments that still don't support any kind of API for their internal domains...
Re: Decreasing Certificate Lifetimes to 45 Days
#3I dont follow. Why? Why not an hour? A ssl failure is a very effective way to shut down a site.
"you should verify that your automation is compatible with certificates that have shorter validity periods.
To ensure your ACME client renews on time, we recommend using ACME Renewal Information (ARI). ARI is a feature we’ve introduced to help clients know when they need to renew their certificates. Consult your ACME client’s documentation on how to enable ARI, as it differs from client to client. If you are a client developer, check out this integration guide."
Oh that sounds wonderful. So every small site that took the LE bait needs expensive help to stay online.
Do they track and publish the sites they take down?
Re: Decreasing Certificate Lifetimes to 45 Days
#4> We expect DNS-PERSIST-01 to be available in 2026
Very exciting!
https://datatracker.ietf.org/doc/html/draft-sheurich-acme-dn...
Re: Decreasing Certificate Lifetimes to 45 Days
#5Re: Decreasing Certificate Lifetimes to 45 Days
#6Re: Decreasing Certificate Lifetimes to 45 Days
#7I'm all for it -- it's hard to understate the extent to which LetsEncrypt has improved the WebPKI situation. Although the effective single-vendor situation isn't great, the "this is just something you only do via an automated API" approach is absolutely the right one. And certificate lifetimes measured in days work just fine with that. The only things that continue to amaze me are the number of (mostly "enterprise")…
Yeah, no one's rewriting a bunch of software to support automating a specific, internet-facing, sometimes-reliable CA.
Yes it's ACME, a standard you say. A standard protocol with nonstop changing profile requirements at LE's whim. Who's going to keep updating the software every 3 months to keep up? When the WebPKI sneeze in a different direction and change their minds yet again. Because 45 will become 30 will become 7 and they won't stop till the lifetime is 6 hours.
"Enterprise" products are more often than not using internal PKI so it's a waste.
I would like to see the metrics on how much time and resources are wasted babysitting all this automation vs. going in and updating a certificate manually once a year and not having to worry the automation will fail in a week.
Re: Decreasing Certificate Lifetimes to 45 Days
#8Re: Decreasing Certificate Lifetimes to 45 Days
#9I'm sure this is for good reasons, but as someone that maintains a lot of ssl certificates, I'm not in love with this change. Sometimes things break with cert renewal, and it sometimes takes a chunk of time to detect and then sit down to properly fix those issues. This shortens the amount of time I will have to deal with that if it ever comes up (which is more often than you would expect), and increases the chances o…
Re: Decreasing Certificate Lifetimes to 45 Days
#10"This change is being made along with the rest of the industry, as required by the CA/Browser Forum Baseline Requirements, which set the technical requirements that we must follow." I dont follow. Why? Why not an hour? A ssl failure is a very effective way to shut down a site. "you should verify that your automation is compatible with certificates that have shorter validity periods. To ensure your ACME client renews…
To your actual content, unless you did something weird and special snowflake like, everything will just keep working with this.