Sujet : Re: 6-day TLS certificates from Let's Encrypt
De : ldo (at) *nospam* nz.invalid (Lawrence D'Oliveiro)
Groupes : comp.miscDate : 12. Dec 2024, 07:07:53
Autres entêtes
Organisation : A noiseless patient Spider
Message-ID : <vjdujp$20g9u$2@dont-email.me>
References : 1 2 3 4
User-Agent : Pan/0.161 (Chasiv Yar; )
On Thu, 12 Dec 2024 01:05:24 +0000, Broseki wrote:
I have been running 2-day TTL certs for some services I run. It is not
bad at all with ACME since things just renew in the background; and it
really helps cut down on the possbile impact of a compromised cert.
Without ACME though, no way it would be possible XD
If the Let’s Encrypt folks have no trouble with the server load, then I
guess I have no objection either.
When I started using Let’s Encrypt, I found the default setting for Debian
was to check for renewals twice a day. That shocked me a bit, but I assume
they knew what they were doing.