I am using Letsencrypt since 2 years and always receive notifications about certificates expiring.
This week I received a notification the certificate will expire in 19 days. Just 3 days before an update was tried but was declined.
I don’t want to generate traffic and unnecessary updates which anyway get declined. I get always notifications and are unable to setup a crontab so that I don’t get notifications.
I think the 90 days certificate validity is not so well chosen. When it would be 110 days, everybody could setup an easy 3 months update interval, if you miss that 5 days later Letsencrypt would send a notification and after 110 days deletes the certificate.
When sticking to the 90 days certificate validity it should be possible to update the certificate after 60 days so someone can setup an easy 2 months recurring crontab.
Please have a look into the certificate validity, notification day setting and allowed update date so that we do not generate unnecessary updates and don’t get always notifications.