Are shortlived certs have higher rate limit?

I had missed it. Thanks

Well, sure it's easy if we ignore the docs :slight_smile:

But, we can't well explain what you have seen from the published material.

Your test doesn't prove that 24H is the bucket refill cutoff. You only tested non-ARI renewal at 24H and rapid renewals (1min) so it could be anywhere between that. Or, it could be something entirely different as a limiting factor. What you proved is there is some rate limit on a non-ARI renewal.

Your cert uses a single IPv6 address as the identifier (not mixed with a domain name) so perhaps that is a factor. IP address certs are fairly new so you may be running into an LE bug.

We'll likely need to wait for @aarongable to clarify or someone to review the Let's Encrypt Boulder code.

2 Likes