Since the beginning of this year, Let’s Encrypt rolled out a new shortlived profile for certificates that make them valid for only 160 hours. The intention, as they say, is to encourage automation and reduce the window of certificate compromise (because revocation is somewhat a flakey thing).

Yet, I haven’t seen a lot of news about it since then. Hence the question: is this shorter cert thingy something you considered and deployed for your homelab?

As for me I’ve set up lego-acme with profile: "shortlived" on my rig. Lego runs on a bihourly cronjob, but only renews when a cert has >=3 days to expiry. It’s been pretty much a set-and-forget experience, although some more monitoring would be nice.

  • Ooops@feddit.org
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    1 day ago

    Certbot came with a systemd timer running twice a day (0, 12 +12h random) that only renews –iirc– when the certificate has 30 days or less to live. Also I looked it up and my (version 6.7) Certbot neither mentions the option with the --help option, nor in the manual (where there is just one instance of “profiles exist, no other details given”).

    So they probably need another way than a random blog post when they want users to use (or even just know about) that option…

    It’s been pretty much a set-and-forget experience

    Yeah, that’s what it always has been. So no need to change anything unless they make it the new standard on their side with an update…

    • pdl@social.tchncs.de
      link
      fedilink
      arrow-up
      0
      ·
      14 hours ago

      @Ooops @stratself Certbot renews a certificate when the remaining lifetime is lower than 30 %. If you change the profile from tlsserver (90 days) to shortlived (6 days), you do not need to adjust the renewal interval manually, because it is relative to the cert livetime.
      I think it is not Letsencrypt’s part to document how to use the different profiles with certbot. It should be explained in the documentation of the ACME client (certbot and others).

      • Ooops@feddit.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        8 hours ago

        I know that I could easily change my config. My point is that a) they are failing to advertise this and b) I don’t see any reason to do it. I understand the arguments about security benefits of shorter certificates on their side and iirc they are already planning to change it from 3 months to 1.5 months in the future. But in what scenario do I benefit from a short-term certificate as long as the regular ones are still available anyway?