Hacker News new | ask | show | jobs
by charcircuit 203 days ago
They've been slowly moving the time lower and lower. It will go lower than 45 days in the future, but the reason why we don't go immediately to 1 hour is that it would be too much of a shock.

>So every small site that took the LE bait needs expensive help to stay online.

It's all automated. They don't need help to stay online.

2 comments

re too much shock, how so?
I'd say two big reasons: 1) A lot of people/enterprises/companies/systems are not ready. They're simply not automated or even close to it.

2) Clock skew.

Nope. I renew my LE certs manually. I take my http server down, run certbot, and pull http back online