Really not looking forward to the upcoming certificate renewal apocalypse. From 350+ days to now 200 days and soon to be 47 days renewal time for WebPKI TLS certificates.
Google Chrome (And later FireFox) removed support for DANE TLS certificates, but now they are forcing the planet to move to 47 days. So frustrating.
Sure, requesting certs are pretty easy, but the tooling to install and test requires previously isolated systems need to be able to talk out.
The LD50 on 47 days is about 23.5 days, and like with the very recent situation where LetsEncrypt stopped issuing certs while they did some debug work, you need to factor in some safety margin.. so maybe every 40 days you renew? LD20?
Sure Google and Amazon issue their own certs, doesnβt bother them. But all the SMB who self hols will be pushed to more central services as the difficulty to host continues to increase.
</rant>




