If it auto-renews, then what's the difference? It's the same certificate, and you're automatically telling the CA to continue to recognize it. If you want to generate a new certificate every 3 months, you don't need to have a short expiration date to do that--you can just do it, create a new signing request, install the new certificate, and revoke the old one. |