Skip to content

Documentation about certificate lifetimes and rationale - #1993

Closed
bdaehlie wants to merge 247 commits into
mainfrom
doc-cert-lifetimes
Closed

bdaehlie wants to merge 247 commits into
mainfrom
doc-cert-lifetimes

Conversation

@bdaehlie

@bdaehlie bdaehlie commented Aug 3, 2025

Copy link
Copy Markdown
Contributor

Resolves #1214

@bdaehlie

bdaehlie commented Aug 3, 2025

Copy link
Copy Markdown
Contributor Author

Asking for content review first, once we're happy with that I'll commit all the other language files for this. That'll keep the diff UI here cleaner during content review.

@bdaehlie
bdaehlie requested review from aarongable and jsha August 3, 2025 04:53
@bdaehlie
bdaehlie marked this pull request as ready for review August 3, 2025 04:53

@aarongable aarongable left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Content generally LGTM, especially the justifications around why we offer the lifetimes that we do. Some of the more factual information seems redundant with what's already explained on the Profiles page (https://letsencrypt.org/docs/profiles/), so we should at the very least link to that, if not replace some of this language with just a link to that to prevent duplication.

@schoen

schoen commented Aug 7, 2025

Copy link
Copy Markdown
Collaborator

Another benefit is that shorter lifetimes limit the damage from properly-issued certificates whose contents become incorrect during their lifetimes. For DV, that's largely the case of "control of the underlying subject identifier changed". For other forms of certificates that Let's Encrypt doesn't issue it could be that some other detail about the subject changed.

A real-world offline example for me is that I had an internship in college and was issued an employee ID with no expiration date. As a result, I used my (unexpired!) employee ID a couple of times after my internship had ended to visit the employer's campus again and enjoy the nice view there. The ID document was no longer accurate, in the sense that the employee relationship it described no longer existed. I didn't do anything harmful or malicious to my former employer or its premises, but their security policy would probably have preferred that former interns be more readily distinguished from current interns!

@bdaehlie

Copy link
Copy Markdown
Contributor Author

Note to self: Add a header on the 90 days blog post from 2015 pointing to this documentation.

bdaehlie and others added 22 commits July 22, 2026 02:10
This PR is a follow-up on #1983, which was reverted.
With this PR in place, the link in the main main menu to the
[blog](https://deploy-preview-1994--letsencrypt.netlify.app/blog/) is
now preserved.
This is basically just a combination of PRs #1996 and #1999 from
@deining.

---------

Co-authored-by: Andreas Deininger <andreas@deininger.net>
# Latest from Crowdin

- Updates in Czech, Danish, Hebrew, Chinese (China)
# Latest from Crowdin

- Updates in Chinese (China)
* Improve wording
* Add reference to CertSage (@GriffinSoftware)
This updates the stale subscriber agreement redirects, which exist as a
convenience for anyone who clicks a link that includes a trailing
period.

This adds new redirects from "https://cp-test.letsencrypt.org/" and
"https://cps-test.letsencrypt.org/" to the current version of the CPS.
Once we validate this works properly, we can stop using a standalone
webserver that hosts those URLs, and update this to use the real
domains.

DNS entries will be required for these to work, which will be handled
independently.
Ensure they take priority over page content
# Latest from Crowdin

- Updates in Danish, Chinese (China)
… used (#2016)

The type: page parameter is needed to use the custom template. I believe
this was not required by prior Hugo versions so this was caused by the
recent update to the newest hugo version.

Fixes #2015
November 30 is shortly after we expect our new Sunlight logs to be
Usable.
February 28 is 90 days later.
> [!NOTE]
> Also need to update the isrg-hierarchy.png photo.

> [!WARNING]
> Don't merge until August 20, after intermediates have been rotated

---------

Co-authored-by: Aaron Gable <aaron@letsencrypt.org>
ludekjanda and others added 26 commits July 22, 2026 02:13
# Latest from Crowdin

- Updates in Hebrew, Chinese (China)
Leave a reference here for anyone who may be searching for it, which we
can remove in the future.
On the certificates page, move the Gen X intermediates to the "retired"
section. Create a new "expired" section to hold the very oldest Gen X
intermediates, to prevent the "retired" expando from getting unwieldy.
Update the diagram to match.

On the profiles page, remove the tlsclient profile and all mentions of
the TLS Client Auth EKU. Wordsmith the description of the tlsserver
profile somewhat, to paper over the removal and better reflect reality.
There have been at least two posts in the forum from people who expected
their short-lived certificates to contain no revocation information.
# Latest from Crowdin

- Updates in Chinese (China)
# Latest from Crowdin

- Updates in Danish, German, Hebrew, Chinese (China)
## Summary

- Adds [Chill SSL](https://www.chillssl.com/) to the monitoring options
list on `/docs/monitoring-options/`
- Updates `lastmod` in `content/en/docs/monitoring-options.md`

Note: I'm the founder/owner of Chill SSL. Chill SSL helps users track
SSL certificate expiration dates and receive timely notifications.

This follows up on #1926, which was merged and then reverted pending
team review. I've been advised the listing can be resubmitted.

## Test plan

- [x] Verified locally with `hugo server -F` at
`/docs/monitoring-options/`
- [x] Link format matches existing entries on the page
- [x] `lastmod` updated per repo guidelines


Made with [Cursor](https://cursor.com)

Co-authored-by: Cursor <cursoragent@cursor.com>
Preparing 2026 Donation Campaign page
The docs currently says that authorization reuse is limited to 398 days
which is no longer correct.
# Latest from Crowdin

- Updates in Czech, Chinese (Taiwan)
# Latest from Crowdin

- Updates in Czech, Danish, German, Chinese (China), Chinese (Taiwan)
# Latest from Crowdin

- Updates in Czech, Danish
# Latest from Crowdin

- Updates in Czech, Hebrew, Japanese
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion)
from 1.1.12 to 1.1.16.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/juliangruber/brace-expansion/releases">brace-expansion's
releases</a>.</em></p>
<blockquote>
<h2>v1.1.15</h2>
<ul>
<li>Backport v5.0.6 change to v1 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)
0b09384</li>
</ul>
<hr />
<p><a
href="https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15">https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97"><code>447763a</code></a>
1.1.16</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95"><code>d74e630</code></a>
fix: v1 backport for CVE-2026-13149 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/122">#122</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24"><code>2203f4f</code></a>
1.1.15</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd"><code>0b09384</code></a>
Backport v5.0.6 change to v1 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3"><code>10c05fc</code></a>
1.1.14</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/1afa1b22ead12f6a7a02f25bf0f7d64c2439b007"><code>1afa1b2</code></a>
Add opt-in { max } mitigation to v1 legacy line (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/103">#103</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/2fbb6a2aa0f984bb2fb5f60252ca6cba3e1368ec"><code>2fbb6a2</code></a>
Revert &quot;Backport fix for GHSA-7h2j-956f-4vf2 to v1 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/101">#101</a>)&quot;
(<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/102">#102</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/0d7652e3093d3273151729812f9b0b79a17ecba6"><code>0d7652e</code></a>
Backport fix for GHSA-7h2j-956f-4vf2 to v1 (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/101">#101</a>)</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/6c353caf23beb9644f858eb3fe38d43a68b82898"><code>6c353ca</code></a>
1.1.13</li>
<li><a
href="https://github.com/juliangruber/brace-expansion/commit/7fd684f89fdde3549563d0a6522226a9189472a2"><code>7fd684f</code></a>
Backport fix for GHSA-f886-m6hf-6m8v (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/95">#95</a>)</li>
<li>See full diff in <a
href="https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.16">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=brace-expansion&package-manager=npm_and_yarn&previous-version=1.1.12&new-version=1.1.16)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/letsencrypt/website/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Removed [breard-r/acmed](https://github.com/breard-r/acmed) and
[icing/mod_md](https://github.com/icing/mod_md) entries from
clients.json (repos archived by their owners on Feb 22, 2026 and Jun 9,
2026 respectively)
Several years ago we [changed from the plural Certification Practices
Statement to the singular Certification Practice
Statement](letsencrypt/cp-cps#174). This PR
makes us consistent with _that_. I've only updated the keyword in the
translation files, not the actual translated text. That will need
further review but I'm not sure of the process because there's no
lastmod date in those files.

For posterity:
```
grep -rl Practices | xargs sed -i 's/Practices /Practice /g'
grep -rl practices | xargs sed -i 's/practices_s/practice_s/g
```
update the zappa url in `clients.json` since its moved.

Co-authored-by: Josh Aas <jaas@kflag.net>
@bdaehlie

Copy link
Copy Markdown
Contributor Author

Doing this work in #2276 instead since I messed up this PR.

@bdaehlie bdaehlie closed this Jul 22, 2026
bdaehlie added a commit that referenced this pull request Jul 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add documentation about certificate lifetime choices and future plans