Ok. But 1 year means I have less than a year, then less than a year again, then less than a year again. Can’t even do one month and just do the first of every month. These expiration times make no sense, or they make sense for machines but not humans.
You don't have to revoke a key as soon as it is rotated. If you rotate every week you can have a job that runs every week, offset by one day, to revoke.
Right, but there’s no way to do that on the same day every year, or even the “first Tuesday of every June” because that may or may not always fall within a year.
Also, these tokens have to be rotated by a human. So weekly is way too often.
> Right, but there’s no way to do that on the same day every year, or even the “first Tuesday of every June” because that may or may not always fall within a year.