Let's Encrypt short-lived certificates for domains and IPs

Short-lived certificates and IP address certificates are now generally available from Let's Encrypt. These certificates will be valid for 160 hours, a little over six days.

To obtain a short-lived certificate, subscribers simply need to select the “shortlived” certificate profile in the ACME client.

See more articles from iGuRu.gr when you search for news on Google.

Short-lived certificates improve security by requiring more frequent validation and reducing reliance on unreliable revocation mechanisms. If a certificate's private key is exposed or compromised, revocation has historically been the way to mitigate the damage before the certificate expires. Unfortunately, it's an unreliable system. So far, many people have been vulnerable until the certificate expires, a period of up to 90 days. With short-lived certificates, this window is significantly reduced.

Shortlived certificates are optional and Let's Encrypt has no plans to make them the default at this time.

Subscribers who have fully automated their renewal process will be able to easily switch to shortlived certificates if they wish. At this time, not everyone is comfortable with this significantly shorter lifespan.

Let's Encrypt hopes, however, that over time everyone will switch to automated solutions and that it will be able to prove that shortlived certificates work just fine.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).