3 ms·
Have a certificate updater system which will respect an expired certificate for the sole purpose of fetching the latest certificates. What difference is there b
by SilverRed 5y ago
Have a certificate updater system which will respect an expired certificate for the sole purpose of fetching the latest certificates. What difference is there between having a cert that lasts 15 years or one that lasts a single year but can fetch a new list even if expired.
Everything else can still be confined to the regular expiry rules, just the certificate renewal job is exempt.
- dsr_ 5y agoGood idea, let's change that slightly. Require a new cert to be available at a standard path, not less than 10 days before the previous expiration date for ordinary websites, and not less than 1 year before the previous expiration date for long-lived certs. Then part of the standard utilities in any SSL library should be the autoupdater, which recognizes that a cert should have an update available and takes care of that, emitting loud warnings if the replacement is not available in the appropriate window.