Pros and cons of 90-day certificate lifetimes

I don't think they really fall within the scope of LE's key goals, at least not at this early stage. I don't think it's unreasonable for a commercial product to use a better suited commercial service. It is not a part of LE's goals to be everything to everyone.

Let's Encrypt's primary goal is to provide a free certificate to anyone that owns a domain. In the case of embedded devices, who owns the domain? Is it the responsibility of the vendor, or the purchaser? How do current embedded devices renew their certs after a year? Do they renew their certs at all?

I don't see this as being a con, especially since having a one year certificate wouldn't solve the problem. (e.g. How long did that device sit on the shelf before being sold?) Any embedded system that can renew one year certs can renew 90 day certs. (Especially given LE's second goal, automation.)

They weren't. But they still afforded My1 vastly more respect than his posts deserved.

2 Likes