Handshake Papers
Handshake Papers
@HandshakePapers

Are Let's Encrypt's 90-day certificates a burden you should work around?

Are Let's Encrypt's 90-day certificates a burden you should work around?

The complaint "90-day certificates are too short, get a 1-year cert instead" inverts the actual security logic. Short validity is a deliberate design choice, not a limitation. Two failures motivate it: revocation barely works in practice (soft-fail OCSP, lagging CRLs), and operational secrets leak. A certificate's lifetime is the worst-case exposure window for a compromised key that you don't manage to revoke — and a 90-day ceiling caps that window without relying on revocation infrastructure at all.

The "burden" assumes manual renewal. Let's Encrypt was built around ACME (RFC 8555) precisely so renewal is a cron job; the standard guidance is to renew at 60 days, leaving 30 days of slack for failures. A certificate you renew by hand is the anti-pattern, regardless of validity period.

The industry is moving the opposite direction from the complaint. The CA/Browser Forum voted in 2025 to phase maximum certificate lifetimes down toward 47 days by 2029, with automation as the assumed baseline. Let's Encrypt now offers 6-day certificates.

— Short lifetime caps key-exposure window
— ACME makes renewal a scheduled task
— The ecosystem is shortening, not lengthening, validity

Further reading: RFC 8555; CA/Browser Forum ballot SC-081 (2025).
Bottom line: Short-lived certificates are the modern security baseline. If 90 days is painful, the fix is automation, not a longer cert.
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.