# Apple drops a bomb on long-life HTTPS certificates

**URL:** https://the.fmsoup.org/t/apple-drops-a-bomb-on-long-life-https-certificates/780
**Category:** in the News
**Tags:** security
**Created:** [February 21, 2020, 1:04pm UTC](https://the.fmsoup.org/t/apple-drops-a-bomb-on-long-life-https-certificates/780 "2020-02-21T13:04:30Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![AndyHibbs](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/andyhibbs/32/3089_2.png) [@AndyHibbs](https://the.fmsoup.org/u/AndyHibbs)
#### Post date: [February 21, 2020, 1:04pm UTC](https://the.fmsoup.org/t/apple-drops-a-bomb-on-long-life-https-certificates/780/1 "2020-02-21T13:04:30Z")

</div>

Oh joy, more regular SSL certificate maintenance. Thanks Apple.

> **[Apple drops a bomb on long-life HTTPS certificates: Safari to snub new...](https://www.theregister.co.uk/2020/02/20/apple_shorter_cert_lifetime/)**
>
> Keep your crypto below 398 days after September 1 and you're all good

---

<div class="post-metadata">

### Author: ![ian](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/ian/32/544_2.png) [@ian](https://the.fmsoup.org/u/ian)
#### Post date: [February 21, 2020, 1:54pm UTC](https://the.fmsoup.org/t/apple-drops-a-bomb-on-long-life-https-certificates/780/2 "2020-02-21T13:54:47Z")

</div>

Maybe it will provide some impetus for Claris to support automation when it comes to certificate management?

---

<div class="post-metadata">

### Author: ![jormond](https://avatars.discourse-cdn.com/v4/letter/j/35a633/32.png) [@jormond](https://the.fmsoup.org/u/jormond)
#### Post date: [February 21, 2020, 2:58pm UTC](https://the.fmsoup.org/t/apple-drops-a-bomb-on-long-life-https-certificates/780/3 "2020-02-21T14:58:29Z")

</div>

Likely this will come from the community. [GitHub - dansmith65/FileMaker-LetsEncrypt-Win: A PowerShell script for fetching and renewing Let's Encrypt SSL certificates for FileMaker Server running on Windows Server.](https://github.com/dansmith65/FileMaker-LetsEncrypt-Win)

I have thoughts and feelings about some methods I've seen, but it is getting better.

---

<div class="post-metadata">

### Author: ![Markus](https://avatars.discourse-cdn.com/v4/letter/m/b782af/32.png) [@Markus](https://the.fmsoup.org/u/Markus)
#### Post date: [February 22, 2020, 9:52am UTC](https://the.fmsoup.org/t/apple-drops-a-bomb-on-long-life-https-certificates/780/4 "2020-02-22T09:52:04Z")

</div>

sounds very good - this one about let's encrypt. L'e has to be renewed much more often than other certs

---

<div class="post-metadata">

### Author: ![jwilling](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/jwilling/32/256_2.png) [@jwilling](https://the.fmsoup.org/u/jwilling)
#### Post date: [February 22, 2020, 9:58am UTC](https://the.fmsoup.org/t/apple-drops-a-bomb-on-long-life-https-certificates/780/5 "2020-02-22T09:58:39Z")

</div>

FWIW, the script that @jormond linked can be configured to renew automatically with Windows task scheduler. I use this script on 3 production servers. PS, you may need to use the version on Dan's `dev` branch rather than the `master` for new deployments.
