We Issued Our First Six Day Cert
letsencrypt.org
letsencrypt.org
Next thing you know, they'll find a way to require that your web server link their dynamic shared object.
Then another year later you'll need a let's encrypt kernel module too.
"We really want to make sure you have automation, so certificate lifetimes have been reduced to 36 seconds; accounting for RTT and, in our generosity, time for a single timeout/retry" /s
Let it be my problem, please. I'll even use certbot or whatever is in fashion, just find another knob to turn [or don't].
I am concerned at how the cert transparency logs will handle this. That’s going to be a lot of certs getting logged globally if everyone switches to shorter lifetimes.