Re: [Acme] Long-lived certificates, but frequently renewed certificates

Jacob Hoffman-Andrews <jsha@letsencrypt.org> Fri, 19 March 2021 00:25 UTC

Return-Path: <jsha@letsencrypt.org>
X-Original-To: acme@ietfa.amsl.com
Delivered-To: acme@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BAADD3A1031 for <acme@ietfa.amsl.com>; Thu, 18 Mar 2021 17:25:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.346
X-Spam-Level:
X-Spam-Status: No, score=-2.346 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.248, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=letsencrypt.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id s6woNh85wsx4 for <acme@ietfa.amsl.com>; Thu, 18 Mar 2021 17:25:46 -0700 (PDT)
Received: from mail-qv1-xf2e.google.com (mail-qv1-xf2e.google.com [IPv6:2607:f8b0:4864:20::f2e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7B3433A102E for <acme@ietf.org>; Thu, 18 Mar 2021 17:25:46 -0700 (PDT)
Received: by mail-qv1-xf2e.google.com with SMTP id d10so4197705qve.7 for <acme@ietf.org>; Thu, 18 Mar 2021 17:25:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=letsencrypt.org; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=FLXUwsl5yl2K/+rXTnev2mDJz3s5LnNnm2/kTPFUY2o=; b=DT9qb2dBByHAjamzd1gw0J2mH4460usrCsibyqWASD1jEUj7fOyqAqhJny3K5+4SBZ 3HFLYwl9OKQl4l3HQ9+CtbhUE5unuj7HIh8G4SkbK0wWkzg5rn4iHOBB14zaynUH+FCz bGddLjHM8ne4cKpp3Z/vQgS9pS0LxlMzqcDhg=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=FLXUwsl5yl2K/+rXTnev2mDJz3s5LnNnm2/kTPFUY2o=; b=gqJTXys93obduAUTTfM9fZg+NBndmnjn7MhDDQQ+OzTUhHsLwCiRGP9llmxZX4V65E IhTeTAU0jru7wHdTpQfK2/fKonmCsut8ZsPCEtTaVkWgLEu/mucLrFA3KhbzA9GG3zm+ FSBzH1T5K5zJMAATP6c6zqNGYmw7WV/0x6bHNGKUtIMvK3Vpueb3XFUxKKvuQ6cKB5JH EdJYIsTjQyU7ZnmlV06IEe9ESDSj73zblCRCrYjKFJvqNEpqVJjyGjDOOkEx+poeVAtQ 80IEzzRhNX3PxoBn4OM92TSt+nZNQKAWQtv/qi0qNnfhQLlbZGiumTYqhfNlq1cy5S6z upOg==
X-Gm-Message-State: AOAM5325wR9cdnhpS7xi5B20KVq4lZchjS7K2SUAccACbUUIEk6FSXvQ ATLOLHBVEfzItFWIrGs3asY8Sq7Z9Vt4Qtdotfpggee16evIFNd0
X-Google-Smtp-Source: ABdhPJyVjdeBKOU/VlpA4cqTugNwoPrHuB/vcB27fbJdEp6w96YJPfFuympenPUbnYdOjtZ4tCZMG1Qt5WKvYWO6KAI=
X-Received: by 2002:a05:6214:c8a:: with SMTP id r10mr7169886qvr.13.1616113544755; Thu, 18 Mar 2021 17:25:44 -0700 (PDT)
MIME-Version: 1.0
References: <20210318130241.A6B44389A8@tuna.sandelman.ca> <22886.1616091336@localhost>
In-Reply-To: <22886.1616091336@localhost>
From: Jacob Hoffman-Andrews <jsha@letsencrypt.org>
Date: Thu, 18 Mar 2021 17:25:18 -0700
Message-ID: <CAN3x4QmmAiA+L9fqj8_or8z0o1Uu9VHb8RFua6x_BAF41Z2A2Q@mail.gmail.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>
Cc: spasm@ietf.org, acme@ietf.org, anima@ietf.org
Content-Type: multipart/alternative; boundary="000000000000c0958105bdd8c1dd"
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/JkxfKIRJ6KxARCppjDdKe-KEyOQ>
Subject: Re: [Acme] Long-lived certificates, but frequently renewed certificates
X-BeenThere: acme@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Automated Certificate Management Environment <acme.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/acme>, <mailto:acme-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme/>
List-Post: <mailto:acme@ietf.org>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/acme>, <mailto:acme-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 19 Mar 2021 00:25:48 -0000

Roland Shoemaker sent a proposal a while back for ACME Renewal Info (ARI)
with the goal of solving both "impending revocation" and "expressing
suggested renewal times."
https://mailarchive.ietf.org/arch/msg/acme/b-RddSX8TdGYvO3f9c7Lzg6I2I4/. We
at Let's Encrypt hope to develop this idea further and implement it soon.