7
6-day and IP Address Certificates are Generally Available
letsencrypt.orgShort-lived and IP address certificates are now generally available from Let’s Encrypt. These certificates are valid for 160 hours, just over six days. In order to get a short-lived certificate subscribers simply need to select the ‘shortlived’ certificate profile in their ACME client.
Short-lived certificates improve security by requiring more frequent validation and reducing reliance on unreliable revocation mechanisms. If a certificate’s private key is exposed or compromised, revocation has historically been the way to mitigate damage prior to the certificate’s expiration. Unfortunately, revocation is an unreliable system so many relying parties continue to be vulnerable until the certificate expires, a period as long as 90 days. With short-lived certificates that vulnerability window is greatly reduced.


When I first saw this, I thought it was super awesome. And then upon further reflection, I was like, yay, let me open up port 80 so someone can come in and check and verify shit.
“oh yeah, fleem is running blah blah on 10.200.16.55”
the vaulTLS looks cool though