Remix.run Logo
woodruffw 14 hours ago

I don’t think there’s a ton of benefit to the technique. If you’re worried about getting too close to your certificate expiry via automation, the solution is to renew earlier rather than complicate things with a ladder of valid certs.

bawolff 7 hours ago | parent | next [-]

There are reasons to do this, just not because of expiry.

The main reason to have multiple certs is so if your host (and cert prov key) is compromised, you can quickly switch to a backup, without first having to sort out getting a new cert issued.

miladyincontrol an hour ago | parent [-]

If getting a new cert issued is some sort of thing you need to sort out, as in a process that takes time, you've already missed the target.

kees99 14 hours ago | parent | prev [-]

Exactly. It's not like backup certificate have validity starting at a future date.

flowerlad 14 hours ago | parent [-]

Yes the backup certificate can have validity starting at a future date. You just need to wait till that future date to create it.