|
|
|
|
|
by wiktor-k
352 days ago
|
|
> ² With S/MIME you need to keep your old certificates around to decrypt old mails, so having a new one frequently is not practical You don't need to change your decryption key - the new certificate can use the same decryption keys as the old one (certbot even has a flag: --reuse-key). Whether this is a good idea or not is a separate question. I think the biggest benefit would be ACME-like automatic certificate issuance. Currently getting a new certificate is just too much friction. |
|