| I have now implemented a 2 week renewal interval to test the change to the 45 days, and now they come with a 6-day certificate? This is no criticism, I like what they do, but how am I supposed to do renewals? If something goes wrong, like the pipeline triggering certbot goes wrong, I won't have time to fix this. So I'd be at a two day renewal with a 4 day "debugging" window. I'm certain there are some who need this, but it's not me. Also the rationale is a bit odd: > IP address certificates must be short-lived certificates, a decision we made because IP addresses are more transient than domain names, so validating more frequently is important. Are IP addresses more transient than a domain within a 45 day window? The static IPs you get when you rent a vps, they're not transient. |
6 days actually seems like a long time for this situation!