Comment on Let’s Encrypt: Stopping Issuance for Potential Incident – ResolvedparentComments−nottorp4mono plan to make them the default at this timeAt this time! Boil the frog slowly...−Dylan168074moIs the frog the guy that still won't automate their certificates?−nottorp4moMine are automated. Somehow it reminds me of prayer wheels though...−Dylan168074moForcing certificates to expire in less than a year means people don't forget how to update them, which is a big benefit.And once people automate, short-lived certificates are a workable plan B for how to revoke certificates and have the revocation actually work.These are both reasonable goals.−nottorp4mopeople don't forget how to update themSeriously? I don't even remember how the letsencrypt auto renew service is called. No idea how I did the initial setup either.−Dylan168074moYes, seriously. Forgetting how to set up the automation is a different and significantly smaller issue.
Comments
At this time! Boil the frog slowly...
Is the frog the guy that still won't automate their certificates?
Mine are automated. Somehow it reminds me of prayer wheels though...
Forcing certificates to expire in less than a year means people don't forget how to update them, which is a big benefit.
And once people automate, short-lived certificates are a workable plan B for how to revoke certificates and have the revocation actually work.
These are both reasonable goals.
Seriously? I don't even remember how the letsencrypt auto renew service is called. No idea how I did the initial setup either.
Yes, seriously. Forgetting how to set up the automation is a different and significantly smaller issue.