Pros and cons of 90-day certificate lifetimes

90 days is very short for manual updates. It would be nice if the default would be 1 year, so that those who have to manually request and update certificates have less work to do. It would also not be much of an issue to use the 1 year period for websites where security issues are less critical.

You can then let people specify via a commandline option if they want shorter periods (90 days, 120 days etc.) for those who have bigger security concerns and who use automation.

I think this would make everyone happy.

2 Likes