Skip to content

make renewals compatible with short-lived certificates #5483

@ismxilxrif

Description

@ismxilxrif

according to this, the ACME client now has the ability to request certain profiles: https://letsencrypt.org/docs/profiles/

i tried the short lived profile by setting letsencrpyt.ini with profiles = shortlived

but i noticed the certs after renewal, it keeps getting renewed until we've been rate limited, it seems the check was to renew certs that are less than 30 days

it would be nice to have some checks that renew the certs when let's say, it is less than 1/3 of it's lifetime, or let certbot decide when to renew instead of force renewing the certs.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions