Let's Encrypt: 64-Day Certificate Lifetimes By Default Coming Feb 2027
letsencrypt.org
[5 comments hidden]
Sure, re-issuance usually works. But when you only do it every 42 days it does break from time-to-time without you noticing.
I would love if we still renew with 30d remaining. I really don't care if they reduce certificate lifetime to 31 days as long as I am allowed to renew daily. But lowering the gap between expiry and when you are allowed to renew is very annoying.
[4 comments hidden]
Now that they have a dominant position they do Google style and Google influenced move.
You are at their will fit whatever retarded dictatorial decision they want.
[3 comments hidden]
[hidden]
[hidden]
But they said: it is ok now, because you can get a certificate for free with let's encrypt. So suppose, you have a local device not connected to internet or your own private network server/services, with 3 month validity, it was short but you were able to generate the certificate in some way, manually, and deploy it manually also.
You could also easily manual renew and deploy the certificates.
Now, with a very short period, especially the 7 days that is their end goal, your devices needs to be constantly connected to internet, constantly receiving "things" from LE that are automatically downloaded and "installed". And it becomes impossible, to manually manage the certificate renewal, so you are force to let automatic scripts/agent do that work. And most probably also let the script/agent auto-update itself because of "breaking changes" like it happened with certbot.
And all of that being, with a short lifetime, you are now constantly at will of Let's Encrypt, and in the end the US state and government where all of this is located. You depend of the https for a lot of things, now at the US gov will you can be cut off, eventually be monitored or be targeted, in a very short timeframe of "days" instead of months.
You can also more easily have your certificates impersonated in a hard to catch way as certificates will be constantly renewed.
And even in a non evil plot, if anything happens to let's encrypt, down time or anything, you could have your service broken with dead certificate in a so short time that you would not even have the time to look for a solution. Today you have at least months to figure out.
1970-01-01[hidden]