Pros and cons of 90-day certificate lifetimes

Two points.

  1. The additional expirations and renewals associated with short lifetime certificates very well may be just as likely to increase accidental expirations.
  2. LE's objective should be quantity (widespread adoption and deployment of encrypted communications), not behavioral and business policy and process driving.

1a) Effect of accidental expirations is between user and site operator. Should not be an LE driver. I for one want to know when a site operator is not being attentive to their site. It's a red flag that the site is not being appropriately attended too and it's condition should not be trusted. People who go warning-blind, that is their problem. Not mine or LE's.

2a) I view the use of short lifetime certificates to drive automation (customer policy and process) to be inappropriate scope.

16 Likes