sofialund
Member
OP
homelab heatstroke
- Joined:
- Jul 2024
- Posts:
- 140
- From:
- Buenos Aires, Argentina
¡News reaction: Let's Encrypt shortens cert lifetime to 47 days!
The certificate new is crazy no? ¡47 days only!
Before was 90 days, already the automation necessary was... now is the automation double necessary!
I run the server small for the clients 12, and the script bash I have... ¡will break for sure! The renewals every month and half... ¡caramba!
The ACME clients all will update? Or we need the migration to new tool? I am using the certbot old, version the 1.12...
¡tell me your plans friends!
hot air, steady hand, magic smoke
PetraSuper
Member
network boot believer
- Joined:
- Jun 2024
- Posts:
- 127
- From:
- Bratislava, Slovakia
Hej, no, this is big problem...
On server I have 34 certificates... into config many are the virtualhost old...
Malý script I wrote will not work... no, need rewrite...
certbot has the plugin for renewal, hej? But I am not trusting... no...
Better to test on malý VPS first... no, before touching production...
What ACME client you use? I am hearing good things about the client small written in go... no, name I forget...
boot anything, anywhere, anytime
hankels
Member
52 VPS and counting
- Joined:
- Jun 2024
- Posts:
- 301
- From:
- Phoenix, US
I run 52 boxes so this hits different
Math time:
- 52 certs × 7.7 renewals/year = 400 renewals
- was 208 at 90 days
- my automation failure rate: ~2%
- that's 8 broken certs/year vs 4 before
Cost comparison by headache:
- manual fix: 2 hrs × $75 = $150 per incident
- new automation tool: $0 + 6 hrs setup
- switching CA: Vultr offers 60 days still, $0 — https://www.vultr.com/pricing/
Currently on certbot 2.x across fleet, mixed results. Thinking of standardizing on acme.sh or that rust client everyone's talking about.
Anyone benchmarked RAM usage? My smallest box has 512MB, 12 containers fighting for it
seedbox, NAS, tape, and three offsite
rustyrack_grag
Member
- Joined:
- Jun 2024
- Posts:
- 68
- From:
- Tallinn, Estonia
Bullet points for clarity:
- current situation: Let's Encrypt 47-day proposal, not yet enforced
- effective date: anticipated 2027 per their timeline
- preparation window: approximately 18 months remain
Personal mitigation:
- inventory all certificates by expiry automation status
- test renewal frequency under 47-day simulation
- evaluate alternative CAs: Vultr, HostHatch CA, self-hosted step-ca
Professional obligation:
- from memory Contabo's ToS has something about requiring notice for infrastructure changes affecting client services, I think it's 30 days
- I have initiated compliance review
R.R.
if it ain't broke, rust it
larryjeong
Member
- Joined:
- Jun 2024
- Posts:
- 179
- From:
- Texas, US
Certbot 1.12 is ancient my friend, you need to upgrade that thing before 47 days hits. I was on 1.10 til last year and half my renewals failed random, not worth the headache.
$3/year. 128MB RAM. Pure happiness.