Remix.run Logo
jsheard 11 hours ago

For better or worse the push down to 47-day certificates is an industry-wide thing, in a few years no provider will issue certificates for longer than that.

Nobody is being forced to use 6-day certs for domains though, when the time comes Let's Encrypt will default to 47 days just like everyone else.

hungryhobbit 9 hours ago | parent | next [-]

And you don't think that years ago people would have said "of course you'll be able to keep your security cert for more than two months"?

The people who innovate in security are failing to actually create new ways to verify things, so all that everyone else in the security industry can do to make things more secure is shorten the cert expiration. It's only logical that they'll keep doing it.

themafia an hour ago | parent [-]

ALPN per transaction certificates. Why take the chance?

singpolyma3 11 hours ago | parent | prev [-]

> Nobody is being forced to use 6-day certs for domains though

Yet

einsteinx2 9 hours ago | parent [-]

Nobody is being forced to use Let’s Encrypt either.

singpolyma3 6 hours ago | parent [-]

It doesn't matter. Google makes sure every CA has the same rules.