dehydrated-io / dehydrated

letsencrypt/acme client implemented as a shell-script – just add water
https://dehydrated.io
MIT License
5.96k stars 716 forks source link

Support custom certificate lifetime #932

Open janh opened 8 months ago

janh commented 8 months ago

The ACME protocol allows to request a specific lifetime using the fields "notBefore" and "notAfter" when creating an order (see also #806).

This change allows to specify the desired lifetime using the new LIFETIME_SECS option.

The "notBefore" time is back-dated by 1 hour (Let's Encrypt and Google Trust Services also do this by default). Not sure if this should also be configurable.