Skip to content

Shorter-lived certs #8

Description

@konklone

Is it possible, with the upstream APIs you've integrated with, to get 1 year of authorized reissuances from SSLMate, but to have each certificate be valid for a subset of that time, from the date of reissuance?

For example, I'd love to start using shorter-lived certs, with an initial goal of 3 months, Google-style. This makes a compromised key/cert less useful to an attacker, and forces us to get an automated apparatus in place for managing them. Maybe someday, we can get to certs that last 1-2 days (which may have some performance benefits in the future).

It's not an urgent feature request. But I'd love to know if SSLMate can make this possible.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions