Certbot 4.0: Long Live Short-Lived Certs!

1 month 4 weeks ago

When Let’s Encrypt, a free certificate authority, started issuing 90 day TLS certificates for websites, it was considered a bold move that helped push the ecosystem towards shorter certificate life times. Beforehand, certificate authorities normally issued certificate lifetimes lasting a year or more. With 4.0, Certbot is now supporting Let’s Encrypt’s new capability for six day certificates through ACME profiles and dynamic renewal at:

  • 1/3rd of lifetime left
  • 1/2 of lifetime left, if the lifetime is shorter than 10 days

There’s a few, significant reasons why shorter lifetimes are better:

  • If a certificate's private key is compromised, that compromise can't last as long.
  • With shorter life spans for the certificates, automation is encouraged. Which facilitates robust security of web servers.
  • Certificate revocation is historically flaky. Lifetimes 10 days and under prevent the need to invoke the revocation process and deal with continued usage of a compromised key.

There is debate on how short these lifetimes should be, but with ACME profiles you can have the default or “classic” Let’s Encrypt experience (90 days) or start actively using other profile types through Certbot with the --preferred-profile and --required-profile flags. For six day certificates, you can choose the “shortlived” profile.

These new options are just the beginning of the modern features the ecosystem can support and we are glad to have dynamic renewal times to start leveraging a more agile web that facilitates better security and flexible options for everyone. Thank you to the community and the Certbot team for making this happen!

UPDATE (05/02/2025): To clear up any confusion, Certbot offers support for these profiles but Let's Encrypt plans to have this feature fully available by the end of this year.

Love ♥️ Certbot as much as us? Donate today to support this work.

Alexis Hancock

【焦点】トランプ課税で世界はキナ臭さが漂う=橋詰雅博

1 month 4 weeks ago
 「投資の神様」と称される著名投資家、米国のウォーレン・バフェット氏(94)は最近のCBSニュースのインタビューで関税は「ある程度の戦争行為」「すぐに血を流すことはないかもしれないが、間違いなく報復を招く侵略行為だ」と語った。 その代表例として共和党のフーヴァー大統領の下で1930年に法制化されたスムートホーリー関税法を上げた。高関税によって国内産業を保護して高賃金を維持することで世界恐慌を克服しようとした。 しかし米国が保護貿易主義に転じたことに対し、英国、フランス、オラン..
JCJ