Consider ARI "replaced" status in expiration-mailer

In my experience in helping people in this community, most multiple-to-one consolidations I've seen have been: "oops, I screwed up, what hostnames should be on my cert?" I agree though, @mholt, a cert with any other name is... a different cert? To me this comes down to the "identity" of a cert, possibly its private key? Since "renewal certs" are generational (duplicates in the sense of the SAN set, which is what Let's Encrypt considers a cert's identity per the condition of the expiration notices), they typically, but not by requirement, have different keys from their forebears. This seems to be an identity crisis. :grin:

6 Likes