Most of them have either completely forgotten about it and how to do it, or there's been a change of employees and the new ones didn't get the memo, so to speak.
So it falls on us to remind them and guide them through the process.
How I wish the gov't moved to a 3 month setup like Let's Encrypt.
(That said, three months is better than any longer period. The shorter the rotation, the lower the risk -- but, more importantly, the stronger the impetus to build strong automation around the process.)
If we lowered the expiration time to say 3 days, with automatic renewal after 2 days, then any breakage on your side or downtime on let's encrypt's side would quickly escalate into https errors. That in turn would train users that those just happen, and make them ignore the big red scary page even when it's an actual attack. That sounds much worse than the small risk from a 30 day certificate.
That's already happened. I'm encountering LE errors on random websites so much that I don't care and automatically click through warnings. This is especially troublesome because my government keeps MITM me and I don't like it.
the lower the risk of compromised certs / keys. certainly not a lower risk of issues, or surprises.
hopefully -- emphasis on hope -- this regular action becomes routine and easy enough to that it is a low risk behavior.
I once met a person at a client org who was generally opposed to automation due to risks of forgetting how things work and not always knowing what the internals behind those abstractions are. It was an interesting take.
At the same time, something like Ansible and other methods of automation can be pretty useful and actually aid in documenting things.
It's especially good if you can spare 10% of your time to put some notes down in Markdown files in a Git repo, or source/deploy most of your automation scripts from there as well.
In a world of containerized and immutable cattle servers its not a good solution. Especially not when you technically only need it for something that is internally accessible.
Currently my homelab setup is based on running certbot locally in a docker and a calender entry - maybe I get annoyed enough and switch to my own cert at some point, but those are also a big pita.
my blog and personal website are down for this reason, I simply can't spend half-a-day at this point in my life figuring out how to do this on OpenBSD. So I'd rather just leave it dead at this point.
Guess I could just buy an SSL certificate still, maybe I do that tonight.
And buying an SSL cert only gives you 368 days in Chrome / Apple browsers: https://support.apple.com/en-us/102028
For me it’s like;
blog.jharasym.com - namecheap
blog.jharasym.dev - gandi
blog.dijit.sh - self hosted with BIND