Since the beginning of this year, Let’s Encrypt rolled out a new shortlived profile for certificates that make them valid for only 160 hours. The intention, as they say, is to encourage automation and reduce the window of certificate compromise (because revocation is somewhat a flakey thing).
Yet, I haven’t seen a lot of news about it since then. Hence the question: is this shorter cert thingy something you considered and deployed for your homelab?
As for me I’ve set up lego-acme with profile: “shortlived” on my rig. Lego runs on a bihourly cronjob, but only renews when a cert has >=3 days to expiry. It’s been pretty much a set-and-forget experience, although some more monitoring would be nice.
antsu@discuss.tchncs.de
Ooops@feddit.org
tburkhol@slrpnk.net 4 hours ago
I’m happy with 90 day certs for homelab stuff: I’m not worried about anyone MITMing my network. I figure the short lived certs are more important for people who provide services with a significant external user-base, or who process sensitive transactions.
I have my certbot set to check every 12 hours and renew at 60 days. Renewing every 3 days would be 20x more load on Let’s Encrypt systems, and that feels like abuse of a free service for my use case.
stratself@lemdro.id 3 hours ago
I think they encourage that increased frequency by offering shortlived certs to begin with…
Although do note that normal certificates will reduce its lifetime to 45 days over the next few years