Alter TLS renewal period

This commit is contained in:
Benjamin Schwartz
2026-01-21 00:38:04 -08:00
committed by GitHub
parent 63820e1d78
commit ef5d040fd6
3 changed files with 25 additions and 13 deletions
+2 -2
View File
@@ -809,8 +809,8 @@ func getCertificateRenewDurations(certificatesDuration int) (time.Duration, time
return 30 * 24 * time.Hour, 24 * time.Hour // 30 days, 1 day
case certificatesDuration >= 30*24: // >= 30 days
return 10 * 24 * time.Hour, 12 * time.Hour // 10 days, 12 hours
case certificatesDuration >= 7*24: // >= 7 days
return 24 * time.Hour, time.Hour // 1 days, 1 hour
case certificatesDuration >= 6*24: // >= 6 days
return 2 * 24 * time.Hour, 2 * time.Hour // 2 days, 2 hours
case certificatesDuration >= 24: // >= 1 days
return 6 * time.Hour, 10 * time.Minute // 6 hours, 10 minutes
default:
+15 -3
View File
@@ -612,6 +612,12 @@ func Test_getCertificateRenewDurations(t *testing.T) {
expectRenewPeriod: time.Hour * 24 * 30,
expectRenewInterval: time.Hour * 24,
},
{
desc: "45 Days certificates (Let's Encrypt 2028 standard): 10 days renew period, 12 hour renew interval",
certificatesDurations: 24 * 45,
expectRenewPeriod: time.Hour * 24 * 10,
expectRenewInterval: time.Hour * 12,
},
{
desc: "30 Days certificates: 10 days renew period, 12 hour renew interval",
certificatesDurations: 24 * 30,
@@ -619,10 +625,16 @@ func Test_getCertificateRenewDurations(t *testing.T) {
expectRenewInterval: time.Hour * 12,
},
{
desc: "7 Days certificates: 1 days renew period, 1 hour renew interval",
desc: "7 Days certificates: 2 days renew period, 2 hour renew interval",
certificatesDurations: 24 * 7,
expectRenewPeriod: time.Hour * 24,
expectRenewInterval: time.Hour,
expectRenewPeriod: time.Hour * 24 * 2,
expectRenewInterval: time.Hour * 2,
},
{
desc: "160 hour certificate (Let's Encrypt 'shortlived' profile): 2 days renew period, 2 hour renew interval",
certificatesDurations: 160,
expectRenewPeriod: time.Hour * 24 * 2,
expectRenewInterval: time.Hour * 2,
},
{
desc: "24 Hours certificates: 6 hours renew period, 10 minutes renew interval",