Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's mostly to limit the damage in case of compromise and to encourage automation.

Let's Encrypt explains their choice for 90day certificates here: https://letsencrypt.org/2015/11/09/why-90-days.html

edit: With 3 year certificates there is also a greater risk for certificates expiring unexpectedly because the renewal process happens so infrequently. The person with the knowledge on the renewal process might not be at the company anymore by the time the certificate expires.



And in the case of letsencrypt to encourage the automation of the renewal process.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: