logoalt Hacker News

mike_dtoday at 7:24 AM1 replyview on HN

I understand all of the benefits with regards to compromise and pushing automation, but I really hope they don't push the maximum lower.

It is already getting dangerously close to the duration of holiday freeze windows, compliance/audit enforced windows, etc.

Not to mention the undue bloat of CT logs.


Replies

ndsipa_pomutoday at 11:23 AM

> It is already getting dangerously close to the duration of holiday freeze windows, compliance/audit enforced windows, etc.

How do those affect automated processes though? If the automation were to fail somehow during a freeze window, then surely that would be a case of fixing a system and thus not covered by the freeze window.

> Not to mention the undue bloat of CT logs.

I'm not sure what you mean by "CT logs", but I assume it's something to do with the certificate renewal automation. I can't see that you'd be creating GBs of logs that would be difficult to handle. Even a home-based selfhosted system would easily cope with certificate logs from running it hourly.

show 1 reply