• 1 Post
  • 211 Comments
Joined 2 years ago
cake
Cake day: February 27th, 2024

help-circle

  • our org forbids plain http

    is redirecting http to https also out of the question? because let’s encrypt HTTP-01 accepts http -> https redirects:

    Our implementation of the HTTP-01 challenge follows redirects, up to 10 redirects deep. It only accepts redirects to “http:” or “https:”, and only to ports 80 or 443. It does not accept redirects to IP addresses. When redirected to an HTTPS URL, it does not validate certificates.




  • Well it should be as short as possible while still being practical. LE doesn’t have infinite server compute, renewal also takes some amount of time, plus if they make the validity too short people might stop using them (pretty evident judging from sentiment here) and move to other CAs and make what they do pointless.

    45 days are still plenty of time yet people are already complaining. Does make me worry.