Remix.run Logo
jakeogh an hour ago

"This change is being made along with the rest of the industry, as required by the CA/Browser Forum Baseline Requirements, which set the technical requirements that we must follow."

I dont follow. Why? Why not an hour? A ssl failure is a very effective way to shut down a site.

"you should verify that your automation is compatible with certificates that have shorter validity periods.

To ensure your ACME client renews on time, we recommend using ACME Renewal Information (ARI). ARI is a feature we’ve introduced to help clients know when they need to renew their certificates. Consult your ACME client’s documentation on how to enable ARI, as it differs from client to client. If you are a client developer, check out this integration guide."

Oh that sounds wonderful. So every small site that took the LE bait needs expensive help to stay online.

Do they track and publish the sites they take down?

charcircuit 42 minutes ago | parent | next [-]

They've been slowly moving the time lower and lower. It will go lower than 45 days in the future, but the reason why we don't go immediately to 1 hour is that it would be too much of a shock.

>So every small site that took the LE bait needs expensive help to stay online.

It's all automated. They don't need help to stay online.

jakeogh 36 minutes ago | parent | next [-]

re too much shock, how so?

TZubiri 35 minutes ago | parent | prev [-]

Nope. I renew my LE certs manually. I take my http server down, run certbot, and pull http back online

Semaphor 43 minutes ago | parent | prev [-]

LE bait. Wow.

To your actual content, unless you did something weird and special snowflake like, everything will just keep working with this.