Todo #16606
openUpdate recommended maximum server certificate lifetimes to 200 days
100%
Description
CA/Browser forum baseline requirements are calling for shorter validity periods to be phased in over the next few years and the next change is to a maximum of 200 days for server certificates issued between March 15, 2026 and March 15, 2027.
After that it changes to 100 days between 2027 and 2029, then 47 days after that. However, at this time we only need to lower the limit from 398 to 200. That said, since the future limits are published, we could add logic to adjust the value automatically.
This should be taken into account and tested in a few places, most of which properly respect the value of max_server_cert_lifetime in source:etc/inc/certs.inc#L1638 :
- The default GUI certificate lifetime
- The warnings in the GUI when the user is creating a new server certificate
- The "strict security" logic in the renewal page
Additionally the current 398 day value is hardcoded in the OpenVPN wizard and must be changed there as well.
Updated by Jim Pingle 10 days ago
- Status changed from New to Feedback
- % Done changed from 0 to 100
Applied in changeset e5fe340d96c98a617cecf5bcef0d7185e82b28ef.
Updated by Jim Pingle 2 days ago
- Plus Target Version changed from 26.03 to 25.11.1
Updated by Jim Pingle 2 days ago
- Subject changed from Update recommended maximum server certificate lifetimes to 200 days to Update recommended maximum server certificate lifetimes to 200 days