logoalt Hacker News

bawolffyesterday at 6:51 AM1 replyview on HN

There are reasons to do this, just not because of expiry.

The main reason to have multiple certs is so if your host (and cert prov key) is compromised, you can quickly switch to a backup, without first having to sort out getting a new cert issued.


Replies

miladyincontrolyesterday at 12:53 PM

If getting a new cert issued is some sort of thing you need to sort out, as in a process that takes time, you've already missed the target.

show 1 reply