# Certificate lifetime less than 90 days

**URL:** <https://community.letsencrypt.org/t/certificate-lifetime-less-than-90-days/81429>\
**Category:** Feature Requests\
**Created:** [January 2, 2019, 8:31pm UTC](https://community.letsencrypt.org/t/certificate-lifetime-less-than-90-days/81429 "2019-01-02T20:31:21Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![anon95262142](https://avatars.discourse-cdn.com/v4/letter/a/57b2e6/32.png) [@anon95262142](https://community.letsencrypt.org/u/anon95262142)\
**Post date:** [January 2, 2019, 8:31pm UTC](https://community.letsencrypt.org/t/certificate-lifetime-less-than-90-days/81429/1 "2019-01-02T20:31:21Z")

</div>

Personally, I would like certificate lifetime of 7 days or lower. That would make OCSP unneccesary since cached OCSP responses are valid for 7 days, making any revocation fully effective only after 7 days.

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [January 2, 2019, 8:37pm UTC](https://community.letsencrypt.org/t/certificate-lifetime-less-than-90-days/81429/2 "2019-01-02T20:37:29Z")

</div>

Thanks for the note! Currently we would still have to sign OCSP for such certificates under the Baseline Requirements, but I agree that this is one of two plausible paths forward for reliable revocation:

1. OCSP Must Staple
2. Short-Lived Certificates

Both have significant downsides: OCSP Must Staple has significant implementation problems in most web servers. Short-Lived Certificates would put a higher burden on CT logs, and would increase problems with client-side clock skew.

Right now we offer (1), and are continuing to evaluate (2) but don’t have any immediate plans.

---

<div class="post-metadata">

**Author:** ![anon95262142](https://avatars.discourse-cdn.com/v4/letter/a/57b2e6/32.png) [@anon95262142](https://community.letsencrypt.org/u/anon95262142)\
**Post date:** [January 2, 2019, 8:50pm UTC](https://community.letsencrypt.org/t/certificate-lifetime-less-than-90-days/81429/3 "2019-01-02T20:50:28Z")

</div>

I don’t mean that OCSP should not be generated for such certificates, only that OCSP stapling becomes unnecessary for them.

Usually clock skew does not exceed 1 minute in any sensible system, so I’m not sure how much does that apply.

---

<div class="post-metadata">

**Author:** ![anon95262142](https://avatars.discourse-cdn.com/v4/letter/a/57b2e6/32.png) [@anon95262142](https://community.letsencrypt.org/u/anon95262142)\
**Post date:** [January 2, 2019, 8:51pm UTC](https://community.letsencrypt.org/t/certificate-lifetime-less-than-90-days/81429/4 "2019-01-02T20:51:47Z")

</div>

Also is there any possibility of reducing OCSP response lifetime to make full revocation happen faster than 7 days?

---

<div class="post-metadata">

**Author:** ![anon95262142](https://avatars.discourse-cdn.com/v4/letter/a/57b2e6/32.png) [@anon95262142](https://community.letsencrypt.org/u/anon95262142)\
**Post date:** [January 4, 2019, 8:47pm UTC](https://community.letsencrypt.org/t/certificate-lifetime-less-than-90-days/81429/5 "2019-01-04T20:47:47Z")

</div>

@jsha Is there any hope that eventually OCSP responses will last less than 1 day?

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [January 4, 2019, 9:26pm UTC](https://community.letsencrypt.org/t/certificate-lifetime-less-than-90-days/81429/6 "2019-01-04T21:26:08Z")

</div>

It’s not been something on our roadmap so far.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [February 3, 2019, 9:26pm UTC](https://community.letsencrypt.org/t/certificate-lifetime-less-than-90-days/81429/7 "2019-02-03T21:26:29Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
