globalsign / certlint

X.509 certificate linter, written in Go

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Ballot 193 defines 825 day limit for all cert types

cardonator opened this issue · comments

When merged, PR #20 should resolve this issue with the latest guidance.

Thanks, Bryan. FWIW, we ended up switching to https://github.com/zmap/zlint for cert linting since that's one of the linters crt.sh uses, Boulder CA uses, and seems to stay the most up to date with industry guidelines.

@cardonator That for the information. I've taken a look at zlint a while back and it looks really good and it's nice that it has the focus to get updated promptly with new industry guidance. I think we'll plan to use zlint in our pre-issuance process as well.