4 ms·
I don't think a percentage is the best way to think about it. There is a lot of variability in lifetimes and the time it takes to resolve issues is not related
by jaas 7y ago
I don't think a percentage is the best way to think about it. There is a lot of variability in lifetimes and the time it takes to resolve issues is not related to the lifetime of the cert.
Just pick a discrete number of days before expiration such that you have a comfortable amount of time to deal with issues.
We (Let's Encrypt) recommend renewing with 30 days left, so every 60 days. If your system is automated like we recommend that shouldn't be burdensome, no reason to do it less often than that.
- gerdesj 7y agoAlso, Nagios/Icinga has a handy certificate checker in check_http. If that is a bit too much then logwatch the log and notify on the box itself.
- mmalone 7y agoFor what it’s worth, I’ve run into some issues with this guidance from you guys as I’ve been building out a private CA with ACME support. A lot of ACME clients have hard coded renewal at 30 days prior to expiration, which makes them pretty worthless for managing short-lived private certificates. Using a percentage might not encode a fixed SLA very well, but as a default it does accommodate various lifetimes well. I can see pros/cons either way, just thought you might be interested in this feedback.