6 day certificates!? Pinch me I'm dreaming

I was guessing that renewals in a 6-day would would happen sooner than 2/3, but that's just me, I'm worried things could go wrong and it can take time to even know there is a problem, that the problem is a cert problem, that it is an expired cert problem, why it expired, how many others are going to expire in the same bad way, how soon, and how to fix it.

Most certificate problems are not because of any problem with Let's Encrypt, but a "user" problem, because some users need funny certificate setups because they terminate for multiple domains and how those domains are defined drives how the certificates are ordered and there can be cracks in all that. And problems in that can take time to sort that out.

I would expect people to be renewing after just two days, or maybe daily. But what do I know? I would also expect people to think that is scary stuff, and no one here sees it that way.

I bring up the possibility of a catastrophic Let's Encrypt failure because no one could deny that is possible, and surely that should catch someone's attention.

Alas, this proposal addresses some revocation problems, so why worry that it might create other problems?

-kb, the Kent who has been part of maintaining a site with a lot more than just one Let's Encrypt certificate.

1 Like