Sovereign Tech Agency Director of Programs Erik Möller, @eloquence, spoke to Josh Bressers, @joshbressers, on the Open Source Security Podcast about how we work, where we invest, and the importance of supporting #opensource maintainers at a time when AI is reshaping how we think about digital infrastructure.
🎧 Take a listen: https://opensourcesecurity.io/2026/2026-08-erik-sta/
Blog
- Details
- Written by: Adrian Offerman
- Category: Blog
Managing TLS certificates has become pretty crazy: Over the years validity was cut down from several years to two years to one year to half a year now. In a few years it will be only a little more than one month, with the additional requirement to basically continuously prove domain control.
Since I'm not using Let's Encrypt over here, these days I have to re-submit a CSR to my certificate provider every half a year for every domain, prove domain ownership, install the new certificate (chain), and update my DANE/TLSA records. Soon continuous domain control validation will have to be added as an additional secondary process to the domain reactivation/renewal process.
Read more: The 47-day certificate: faster treadmill, same broken foundation
Nederlands (nl-NL)
English (United Kingdom) 