Comment on Let’s Encrypt: Stopping Issuance for Potential Incident – ResolvedparentComments−Dylan168074moIs the frog the guy that still won't automate their certificates?−nottorp4moMine are automated. Somehow it reminds me of prayer wheels though...−Dylan168074moForcing certificates to expire in less than a year means people don't forget how to update them, which is a big benefit.And once people automate, short-lived certificates are a workable plan B for how to revoke certificates and have the revocation actually work.These are both reasonable goals.−nottorp4mopeople don't forget how to update themSeriously? I don't even remember how the letsencrypt auto renew service is called. No idea how I did the initial setup either.−Dylan168074moYes, seriously. Forgetting how to set up the automation is a different and significantly smaller issue.
Comments
Is the frog the guy that still won't automate their certificates?
Mine are automated. Somehow it reminds me of prayer wheels though...
Forcing certificates to expire in less than a year means people don't forget how to update them, which is a big benefit.
And once people automate, short-lived certificates are a workable plan B for how to revoke certificates and have the revocation actually work.
These are both reasonable goals.
Seriously? I don't even remember how the letsencrypt auto renew service is called. No idea how I did the initial setup either.
Yes, seriously. Forgetting how to set up the automation is a different and significantly smaller issue.