Skip to content

Reduce maximum allowed valid authorization lifetime#8648

Merged
jsha merged 2 commits intomainfrom
authz-lifetime
Feb 26, 2026
Merged

Reduce maximum allowed valid authorization lifetime#8648
jsha merged 2 commits intomainfrom
authz-lifetime

Conversation

@aarongable
Copy link
Contributor

Although our config loading code ensured that we could never configure Boulder to violate the Baseline Requirements (currently 398 days), it did not ensure that we could not configure Boulder to violate our own CP/CPS (90 days). Reduce the maximum allowed ValidAuthzLifetime to prevent accidental violation of our CP/CPS.

@aarongable aarongable requested a review from a team as a code owner February 25, 2026 20:54
@jsha jsha merged commit 84c9477 into main Feb 26, 2026
28 checks passed
@jsha jsha deleted the authz-lifetime branch February 26, 2026 22:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants