5 ms·
> A good defense is to limit the renewals for important domains by registering them for as long as possible (10 years) This is an interesting take. I prefer th
by cialowicz 8y ago
> A good defense is to limit the renewals for important domains by registering them for as long as possible (10 years)
This is an interesting take. I prefer the opposite approach: choose the shortest possible registration window (1 year), and have a very clearly defined, properly-documented renewal process that multiple people at the company understand. It's unlikely that all of those people leave the company in a 1-year window, so the knowledge gets passed on reliably.
If a renewal happens only once every 10 years, then it seems very likely that the person responsible for it has moved on, knowledge around the process is lost, and at best the documentation is very out-of-date (but more likely it's missing).
My process is to have a shared calendar for these high-risk renewals. Top company officers should be on this calendar (CEO, CTO, and some engineering VPs). The calendar contains recurring events for domain and SSL cert renewals. These calendar events are set up for about 1-month before the actual renewal, and fire reminder emails at several intervals beforehand (in case people are away or on PTO).
- hinkley 8y agoWe had this same argument about certificate expiration on a code signing project I worked on. I maintained that having to remember to renew a cert every September was more likely to stick with someone than 18 months or two years. It also keeps your blacklist smaller because dead ones age off faster. I don’t recall how it ended up but we added automated reminders every 30 days starting three months before expiry.
- deleted 8y ago[deleted]
- abraham 8y agoYou could do both. Register it out ten years and each your register an additional one.
- kijin 8y ago10 years sounds a bit inflexible for me. Things can get a little weird if you switch registrars but you have more than 9 years left on your domain so you can't get a full additional year. I do try to maintain a margin of at least 3 years on important personal and business domains, though. Less than 37 months left = immediate attention required.
- user5994461 8y agoI personally found a period of 1-2 year to be the absolute worst. On the next cycle the man is gone because it's past the average tenure. The emails about it were lost or auto deleted. Any documentation or process is useless because the company or the supplier has changed. To have a process be remembered, make it monthly or quarterly.
- mkopinsky 8y agoHow can you make domain renewals be monthly or quarterly?
- gpm 8y agoIf you have multiple domains you could renew them at seperate times. Has the advantage that a failure might not be so disastrous either.
- eli 8y agoOnly if you had the foresight to register them at different times, right?
- jethro_tell 8y agoNot necessarily, most registrars will let you renew for a full year or more at any time. Buy both on the same day, set a reminder or open a ticket to renew only one domain in 3/6 mo. Also, get a registrar with an API and use a script to figure out how long a domain is valid. Alarm through your monitoring system when you hit the too close for comfort time frame. You can scrape whois as well but that seems fragile.
- dspillett 8y agoThe monthly process isn't necessarily to renew domains - it is to assess the situation to see if there are any that need renewing soon. Many months nothing will need doing, a couple of months per year something will need action. Even as a small company we have a number of regular infrastructure reviews. Most of the time we just go through the review, find nothing has changed unexpectedly and no new ideas need bringing to the table, we sign off to say all looks well, and the prices takes very little time. Some of this is automated: scripts collate and report information for signoff and we humans verify the result and take actions as needed (in some cases the action needed is to update the script(s)). This may seem wasteful, but a couple of people spending a couple of hours total per month on such checks can save some nasty surprises in future. Domain status checks is one of the things that gets reviewed.
- Alex3917 8y ago> choose the shortest possible registration window (1 year) Registering domains for only a year at a time will negatively impact your email reputation.
- jsjohnst 8y agoWhy not renew for ten years, then every year extend it by one more year. Best of both worlds and if something screws up, you have 9 more years to fix it.
- ubershmekel 8y agoCeremonies that aren't critical have a higher likelihood of being skipped, forgotten or ignored...
- tajen 8y agoLetsEncrypt chose 3 months. Maybe that’s a hint for us that frequent renewals are better.
- jonatanheyman 8y agoNo, for SSL certificates there's value in having a short expiry. For example if the private keys leak. There's no value in having a domain name (that you want to keep) expire.
- tinus_hn 8y agoThe value is in forcing you to keep it in mind. You don’t forget about things you have to do every 3 months as easily as something you have to do every 10 years.