• 0 Posts
  • 1 Comment
Joined 1 year ago
cake
Cake day: September 20th, 2025

help-circle
  • At work, I used ssh-signed certificates for Linux server access - those certs are only valid for about 15 minutes.

    The whole idea of shorter lifetime certificates is to address if a certificate is compromised. (Especially for client certificates which, iirc, Let’s Encrypt no longer offers).

    For a home lab? With no externally accessible services? Short-lived certs aren’t really a big deal. Nobody is going to be hacking your homelab, stealing your private keys, poisoning your internal DNS, and pointing you to a different, malicious service.