logoalt Hacker News

Analemma_yesterday at 8:05 PM5 repliesview on HN

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong.

If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.


Replies

eqvinoxyesterday at 8:08 PM

Short-lived = 6 days. Even if you reissue after 2 or 3 days, that's… not a lot of breathing room.

show 2 replies
rcontiyesterday at 8:06 PM

You're holding your 6-day cert wrong

show 2 replies
gbear605yesterday at 8:08 PM

Only as long as LE isn’t down for 17 days, then we’re in big trouble.