Skip to content

Conversation

@kvinwang
Copy link
Collaborator

  • Change default certificate validity from 10 years to 1 hour
  • Add server_cert_not_after() helper for long-lived server certs (10 years)
  • Add client_cert_not_after() helper for short-lived client certs (10 minutes)
  • Update KMS CA, RPC and App CA certs to use 10-year validity
  • Update Gateway RPC cert to use 10-year validity
  • Update dstack-util generated certs to use 10-year validity
  • Update RA-TLS temp certs to use 10-minute validity

This is a breaking change. We should reconsider carefully.

- Change default certificate validity from 10 years to 1 hour
- Add server_cert_not_after() helper for long-lived server certs (10 years)
- Add client_cert_not_after() helper for short-lived client certs (10 minutes)
- Update KMS CA, RPC and App CA certs to use 10-year validity
- Update Gateway RPC cert to use 10-year validity
- Update dstack-util generated certs to use 10-year validity
- Update RA-TLS temp certs to use 10-minute validity
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants