This is not true. Authorization lifetimes are only going to get shorter and shorter [1], and have already been reduced to 90 days.
[1] https://community.letsencrypt.org/t/upcoming-api-changes/179...
This is not true. Authorization lifetimes are only going to get shorter and shorter [1], and have already been reduced to 90 days.
[1] https://community.letsencrypt.org/t/upcoming-api-changes/179...
You still state in your updated post that: "The surprising aspect is that Authz has a validity of 300 days (which is likely to be increased)" [emphasis mine]. This would appear to be incorrect based on the source cited above , where it is stated at "Eventually, we'd like to make authorization objects much shorter than certificate lifetimes, probably 7 days."
Perhaps it's worth updating the post again in light of this?
https://community.letsencrypt.org/t/dns-authorization-lifeti...
It is from 14 June 2016 (a few months back), @pfg states "The CA/B Forum is currently developing new rules for domain validation and is probably going to settle on a validation period that is significantly longer than the 300 days currently in use ..."
Is there an authority to say which way it will go?
[1]: https://community.letsencrypt.org/t/upcoming-api-changes/179...
Token issues are something we solved about a decade ago. As to why LetsEncrypt has yet to learn these lessons, I leave that as an exercise to the readers and those familiar with security issues to discover for themselves.
Let's Encrypt is slowly learning the lessons one should have learned a decade ago regarding tokens.
That does not give me hope for their future.
I've had over 20 years (way longer if you count BBS systems which had the exact same problems then as we have now) to play with this. I retired on this very concept.