# \[Let's Encrypt Blog\] We Issued Our First Six Day Cert

**URL:** <https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972>\
**Category:** Praise\
**Created:** [February 20, 2025, 8:41pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972 "2025-02-20T20:41:36Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [February 20, 2025, 8:41pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/1 "2025-02-20T20:41:36Z")

</div>

They did it!

> **[We Issued Our First Six Day Cert](https://letsencrypt.org/2025/02/20/first-short-lived-cert-issued/)**
>
> Earlier this year we announced our intention to introduce short-lived certificates with lifetimes of six days as an option for our subscribers. Yesterday we issued our first short-lived certificate. You can see the certificate at the bottom of our...

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 20, 2025, 8:54pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/2 "2025-02-20T20:54:00Z")

</div>

🥳

(Can't see the cert yet on crt.sh unfortunately: [crt.sh | Serial#03b0b015c1a4e2641611731a711b711de0ef](https://crt.sh/?serial=03%3Ab0%3Ab0%3A15%3Ac1%3Aa4%3Ae2%3A64%3A16%3A11%3A73%3A1a%3A71%3A1b%3A71%3A1d%3Ae0%3Aef))

Edit: Hm, crt.sh seems to be b0rk3d badly: [https://crt.sh/monitored-logs](https://crt.sh/monitored-logs). All (relevant) logs are red and have a last get-sth-call of "2025-02-19 17:49:58" which is more than 24 hours ago.. 😕

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [February 20, 2025, 8:55pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/3 "2025-02-20T20:55:34Z")

</div>

> [@Osiris](#):
>
> Can't see the cert yet on crt.sh

Time to get an account at Censys 🙂

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 20, 2025, 8:58pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/4 "2025-02-20T20:58:37Z")

</div>

> [@MikeMcQ](#):
>
> Time to get an account at Censys 🙂

I have (had?) one, but crt.sh is easier as it doesn't require an account and/or login.

Interestingly enough, `helloworld.letsencrypt.org` does not actually use that certificate, at least not at the moment.

---

<div class="post-metadata">

**Author:** ![mholt](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mholt/32/70171_2.png) [@mholt](https://community.letsencrypt.org/u/mholt)\
**Post date:** [February 20, 2025, 8:59pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/5 "2025-02-20T20:59:24Z")

</div>

Excellent!

Now let us issue some 😏

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [February 20, 2025, 9:04pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/6 "2025-02-20T21:04:12Z")

</div>

> [@Osiris](#):
>
> Interestingly enough, `helloworld.letsencrypt.org` does not actually use that certificate, at least not at the moment.

Well no, the top of the blog post said that they revoked it right away. (But wait, I thought that one of the points of short-lived was that they didn't have revocation information?)

> [@mholt](#):
>
> Now let us issue some 😏

At least in staging, please? I just tried it (now that lego has support) and got an error that my account `is not permitted to use certificate profile "shortlived"`, so it looks like they're only issuing to themselves even in staging for now.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 20, 2025, 9:06pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/7 "2025-02-20T21:06:06Z")

</div>

> [@petercooperjr](#):
>
> Well no, the top of the blog post said that they revoked it right away.

Did not read that 🙄

> [@petercooperjr](#):
>
> But wait, I thought that one of the points of short-lived was that they didn't have revocation information?

It even has the OCSP URI 😲

---

<div class="post-metadata">

**Author:** ![Nummer378](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nummer378/32/49862_2.png) [@Nummer378](https://community.letsencrypt.org/u/Nummer378)\
**Post date:** [February 20, 2025, 9:10pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/8 "2025-02-20T21:10:22Z")

</div>

> [@petercooperjr](#):
>
> Well no, the top of the blog post said that they revoked it right away. (But wait, I thought that one of the points of short-lived was that they didn't have revocation information?)

Not yet, according to the various Boulder issues omitting revocation information for those certs is work in progress:

> <https://github.com/letsencrypt/boulder/issues/7673>
>
> Add a feature flag which, if enabled and the cert has a validity period less tha…n 7 days, results in OCSP and CRL info being omitted from the cert.

> <https://github.com/letsencrypt/boulder/issues/7310>
>
> This bug is an umbrella/tracking bug, acting as a one-stop-shop to see progress …on the multiple sub-tasks necessary to achieve this 2024 OKR.
> 
> Prerequisities:
> \- \[\] https://github.com/letsencrypt/boulder/issues/7309
> 
> Subtasks:
> \- \[x\] https://github.com/letsencrypt/boulder/issues/7339
> \- \[\] https://github.com/letsencrypt/boulder/issues/7673
> \- \[\] Optional: Restrict certain profiles to allow-lists of registration IDs, to allow slow controlled roll-out
> \- \[\] Configure a profile which sets a validity period of less than 10 days (and any other changes we want to bundle) in Staging
> \- \[\] Configure the same profile in prod

> <https://github.com/letsencrypt/boulder/issues/7996>
>
> Currently, the default ARI window is a 24-hour period centered around the point …2/3rds of the way through the certificate's validity period. For 90-day certs, that works great, giving clients a wide suggested window and a whole month to recover if renewal fails.
> 
> But that doesn't work so well for 6-day certs. A 24-hour-wide window is too large to be meaningful, and 1/3rd of the lifetime before expiration is only about two days to recover from failure.
> 
> Therefore, for short-lived certs, we should suggest a narrower window at an earlier point in the validity period. The current proposal is a 1-hour-wide window at the 50% mark. Whether this is achieved by scaling the window width and target point linearly with the validity period, or by hardcoding a cutoff, is still up in the air.

---

<div class="post-metadata">

**Author:** ![Nummer378](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nummer378/32/49862_2.png) [@Nummer378](https://community.letsencrypt.org/u/Nummer378)\
**Post date:** [February 20, 2025, 9:12pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/9 "2025-02-20T21:12:43Z")

</div>

> [@petercooperjr](#):
>
> At least in staging, please? I just tried it (now that lego has support) and got an error that my account `is not permitted to use certificate profile "shortlived"`, so it looks like they're only issuing to themselves even in staging for now.

There are still a bunch of rough edges around short-lived (i.e. ARI doesn't work properly for them right now) certificates that need to be ironed out. Maybe they want to fix some of that first, before opening up to the test audience more.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 20, 2025, 9:12pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/10 "2025-02-20T21:12:48Z")

</div>

Couldn't find an open (or closed) issue with a feature request for ACME profiles on the Certbot Github repo.. 🤔 [So I opened one..](https://github.com/certbot/certbot/issues/10194)

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [February 20, 2025, 9:21pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/11 "2025-02-20T21:21:38Z")

</div>

> [@petercooperjr](#):
>
> I thought that one of the points of short-lived was that they didn't have revocation information?

Their new Profile page says (emphasis mine):

> which means they **do not need to** contain any revocation information

But elsewhere they've said their short-lived certs **won't have it** so I am guessing this is just temp during the rollout.

> **[Profiles](https://letsencrypt.org/docs/profiles/)**
>
> A profile is a collection of characteristics that describe both the validation process required to get a certificate, and the final contents of that certificate. For the vast majority of Let’s Encrypt subscribers, you should never have to worry about...

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [February 20, 2025, 9:22pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/12 "2025-02-20T21:22:49Z")

</div>

Yeah, I didn't think it was against the rules. I guess I'm just confused why they said they were testing the revocation lifecycle if the plan is for these (upon full release) to just not have revocation information.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [February 20, 2025, 9:25pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/13 "2025-02-20T21:25:27Z")

</div>

As an aside, both `shortlived` and `tlsserver` profiles in the directory are noted as limited availability.

---

<div class="post-metadata">

**Author:** ![Nummer378](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nummer378/32/49862_2.png) [@Nummer378](https://community.letsencrypt.org/u/Nummer378)\
**Post date:** [February 20, 2025, 9:26pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/14 "2025-02-20T21:26:34Z")

</div>

> [@petercooperjr](#):
>
> revocation lifecycle

The blog post never said revocation lifecycle (but just cert lifecycle), so I thought this is really about the cert itself: How ARI works for those, how the DB shards them into the expired corner compared to normal 90 day certs and such, not a particular revocation test. They do have some state tracking for certs beyond doing OCSP signing (which is going away anyway).

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [February 20, 2025, 9:28pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/15 "2025-02-20T21:28:19Z")

</div>

Yes, but in staging tlsserver works and shortlived doesn't. (I haven't tried prod, but I assume classic is the only option the public can use there.)

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 20, 2025, 9:29pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/16 "2025-02-20T21:29:31Z")

</div>

> [@Nummer378](#):
>
> The blog post never said revocation lifecycle (but just cert lifecycle)

Sure, but the "(…) then immediately revoked it **so** (…)" (especially the last part of that snippet) suggests that revocation had some big deal in that cert lifecycle testing.

I guess this is just some preliminary testing, as this obviously is not the final short lived profile cert with the OCSP URI still included.. And with that I don't see this as a big deal, really.. Sure, it's nice they have it partly working, but it's just preliminary.. We'll probably have to wait many months until it's publicly available. Not sure if it was worth a blog post 🙂

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [February 20, 2025, 9:35pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/17 "2025-02-20T21:35:29Z")

</div>

> [@petercooperjr](#):
>
> Yes, but in staging tlsserver works and shortlived doesn't

Huh, I'll have to try that. I got thrown off seeing this from staging 'directory'

```nohighlight
[profiles] => Array
(
  [classic] => https://letsencrypt.org/docs/profiles#classic
  [shortlived] => https://letsencrypt.org/docs/profiles#shortlived (not yet generally available)
  [tlsserver] => https://letsencrypt.org/docs/profiles#tlsserver (not yet generally available)
)

```

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [February 20, 2025, 9:40pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/18 "2025-02-20T21:40:05Z")

</div>

I saw it too, I just didn't let it stop me from trying. 😏

---

<div class="post-metadata">

**Author:** ![mcpherrinm](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mcpherrinm/32/59604_2.png) [@mcpherrinm](https://community.letsencrypt.org/u/mcpherrinm)\
**Post date:** [February 20, 2025, 9:44pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/19 "2025-02-20T21:44:10Z")

</div>

Yes, there's lots of work to do before this is "done", including a lot of things around revocation.

The biggest reason we revoked it immediately is that if there was some sort of compliance problem discovered in our post-issuance review, we wouldn't have to rush and go revoke it.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 20, 2025, 10:06pm UTC](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972/20 "2025-02-20T22:06:42Z")

</div>

> [@mcpherrinm](#):
>
> we wouldn't have to rush and go revoke it

Wouldn't that only be necessary if for some strange reason the lifetime was too long so that it wouldn't be a short-lived cert? Or do short-lived certs still require revocation for things like misissuance?

[Next page](https://community.letsencrypt.org/t/lets-encrypt-blog-we-issued-our-first-six-day-cert/233972.md?page=2)
