logoalt Hacker News

mchermyesterday at 8:03 PM3 repliesview on HN

There is one little-discussed down side to ever shorter-lived certificates...


Replies

dizhnyesterday at 8:15 PM

Letsencrypt is not the only acme authority. ZeroSSL is the other popular one. There are others.

devrandyesterday at 8:11 PM

If you're using ACME to handle certificate rotation, can't you just configure multiple providers?

Analemma_yesterday at 8:05 PM

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong.

If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.

show 5 replies