[Qa-debsources] upcoming SSL cert expiry and letsencrypt

Matthieu Caneill matt at brokenwa.re
Thu Nov 26 12:56:30 UTC 2015


On Thu, Nov 26, 2015 at 11:35:04AM +0100, Stefano Zacchiroli wrote:
> That's correct. And thanks to you too. Sounds like you and Orestis are a
> well-formed team for handling this :)

Yep, only blocker could be read/write rights on some /etc/apache2
files.
> 
> > Zack: do you know for how long the Let's Encrypt certificates will be
> > valid? 1 year?
> 
> 3 months, the rationale is here (and I agree with it):
> 
>   https://letsencrypt.org/2015/11/09/why-90-days.html
> 
> So in addition to one-off certificate, what it will need doing is
> actually automating the renewal process, so that we have to worry only
> once about the setup.

Indeed 90 days make sense with automation :)

Thanks!

--
Matthieu



More information about the Qa-debsources mailing list