Ephemeral Certificates (< 48h)
Aligning with CABForum's direction to eliminate OCSP reliance, keysupport.net aggressively renews its Let's Encrypt certificates every night (--force-renewal). This ensures certificate lifetimes remain under 48 hours, neutralizing the revocation window and removing the need to check revocation status for the gateway itself.
Evidence & Transparency
To verify our daily certificate rotation and sub-48-hour lifetimes, you can view the Certificate Transparency (CT) logs for our domain: