But I don't like centralization where failure in a centralized service may render millions of websites inaccessible
Clients are encouraged to renew their certificates a couple of days prior to expiration, precisely to make sure that in the case of a disruption there is still some buffer in time to prevent expired certs being served.
Comments
Clients are encouraged to renew their certificates a couple of days prior to expiration, precisely to make sure that in the case of a disruption there is still some buffer in time to prevent expired certs being served.
Standard practice is to renew 30 days before expiry. This gives you plenty of time to deal with issues.