Ask HN: How are you preparing for upcoming short-lived SSL renewals?
No synthesized answer yet. Check the discussion below.
As of March 15, 2027, the maximum lifetime for a TLS certificate will be 100 days.
As of March 15, 2029, the maximum lifetime for a TLS certificate will be 47 days.
As of March 15, 2026, the maximum period during which domain validation information may be reused is 200 days.
As of March 15, 2027, the maximum period during which domain validation information may be reused is 100 days.
As of March 15, 2029, the maximum period during which domain validation information may be reused is 10 days.
https://groups.google.com/a/groups.cabforum.org/g/servercert...
A surprising number of Ops colleagues have almost zero exposure to IaC and the short-lived certificates on the horizon has been the necessary catalyst to change this.
Only now are their roles morphing to include programming and, understandably, it's occasionally a daunting steep learning curve for them.
Automation isn't enough: qualys.com (famous for SSLLabs.com) is currently serving an expired certificate (expired 8 days ago). They know their job very well, but without a tool to thoroughly and systematically inventory your certificates, you'll miss it.