goes to make Caddy and CertMagic ACME clients even more complicated
goes to make Caddy and CertMagic ACME clients even more complicated
> ARI can be used to set subscribers up for success in terms of ideal renewal times in the event that Let’s Encrypt offers even shorter-lived certificates in the future.
Much of Let’s Encrypts engineering time has been spent on revocation infrastructure, and I don’t like it. I’d much rather issue 2.5 day certs than 2.5 day OCSP responses we need to serve with high availability.
I’m hoping in the near future we see a CA/B ballot and and associated root program changes allowing us to not run OCSP infrastructure for short-lived certs.
That’s the kick needed to support short-lived certs. Of course Caddy is one of the best implementations of TLS and certificate handling and is already ready for that world, but many other systems are going to have a much worse time. That’s a big concern, and it’ll take everyone a while to switch to Caddy to fix their busted manual processes :)
(I’m an employee of Let’s Encrypt but these opinions are my own)
I'll see about adding ARI to Caddy in the hopes that it will accelerate the transition to shorter-lived certs.