dehydrated-io / dehydrated-io/dehydrated

Dynamic renewal timing

Open
#985 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
6.2k
Forks
724
PR merge metrics
No merged PRs in 30d

Description

Hello,
We are using several CAs with different profiles. As a result, the validity periods of the certificates vary (6–365 days), meaning that a general configuration in days is not sufficient. In addition, the validity periods of the certificates will be shortened in the near future, meaning that a configuration in days that is suitable today will no longer be suitable tomorrow – and so the configuration would have to be adjusted despite automation.
Let's Encrypt recommends renewing certificates after about 2/3 of their term. This works for both 6-day and 365-day terms today, and it will also work if the terms are adjusted automatically.
Would it be possible to include such a configuration option?
Thank you!
Best regards
tw-

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue mentions no files, tests, or entry points. Start by locating the renewal timing configuration and the code that determines certificate validity or renewal eligibility; done means supporting a validity-period-based renewal threshold that works across the requested certificate lifetimes.

Written by the indexing model from the issue text.

Assessment

Tech stack
shell
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.