@Ooops @stratself Certbot renews a certificate when the remaining lifetime is lower than 30 %. If you change the profile from tlsserver (90 days) to shortlived (6 days), you do not need to adjust the renewal interval manually, because it is relative to the cert livetime.
I think it is not Letsencrypt’s part to document how to use the different profiles with certbot. It should be explained in the documentation of the ACME client (certbot and others).
Seit einigen Jahren wird mein Drang zum Selfhosting immer größer. Begonnen haben meine Erfahrungen Ende 2012 mit einem Raspberry Pi 1B, später ein RasPi 3, RasPi 4 mit 4 GB RAM und aktuell ein recycleter Thinkcentre 700.
Zunächst nur Nextcloud (damals noch Owncloud) mit Apache und MySQL (inzwischen MariaDB), später weitere Spielereien wie Mozilla Syncserver, und einiges per Docker: Immich, Wanderer, Dawarich, Reitti, Invidious, Libretranslate, Searxng, Snowflake, Stirlingpdf, FMD.
- 0 Posts
- 2 Comments
Joined 2 months ago
Cake day: August 3rd, 2026
You are not logged in. If you use a Fediverse account that is able to follow users, you can follow this user.



@Ooops I do not understand what you mean with “they are failing to advertise this”. Letsencrypt has announced in in their blog:
https://letsencrypt.org/2025/01/16/6-day-and-ip-certs
https://letsencrypt.org/2025/02/20/first-short-lived-cert-issued
The profiles are documented:
https://letsencrypt.org/docs/profiles/
It is your deciscion what profile to use. If you use the shortlived profile and your key is compromised, you benefit from the short lifetime. This benefit you have regardless of the availability of the 90 day certs.
https://letsencrypt.org/2025/01/16/6-day-and-ip-certs