mozilla/server-side-tls

Certificate lifespan is one day short

uwe-schwarz opened this issue · 4 comments

In the json-file the maximum_certificate_lifespan is set to 730 days, which is one day short of the 2 years mentioned on the webpage. With 2020 being a leap year there are 731 days.

I think changing the web page to say "730 days" is a better approach

If we're updating the time period, it might be good to at least decide if the new 398-day limit for Apple products that goes into effect in September is what should be recommended for compatibility.

Maybe we could settle on 366 days.

april commented

This is now fixed in version 5.5, which has 90/90, 90/366, and 90/366 as its recommended and maximum certificate lifespans for the various configurations. :)