i am using certbot. added cronjob for it to run daily.
but i also make a reminder in my calendar. :wink:
all links within the page are https now, too.
maybe i should enforce https now.
weekly is often enough
IIRC it only does anything, if the cert has less than 30d lifetime left
okay.
good.
enforced. no more http now. https has easier than i expected.
i hope all my scripts still work.
it is indeed not that hard on a single one off server, it is quite tricky in a bigger org with centralized management and tiered PKI
adding HSTS headers is the next low hanging fruit for you
to whomever may concern: i've dropped support for TLSv1.1 across all of my services