<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>PKI | OKHK 👀</title><description>个人数字泔水\(⁠◔⁠‿⁠◔⁠)✨ Thinking...</description><link>https://tg.okhk.net</link><item><title>DNS-PERSIST-01：单次 DNS 记录修改即可供持久签发 TLS 证书；预计 26 年 Q2 正式发布</title><link>https://tg.okhk.net/posts/8760</link><guid isPermaLink="true">https://tg.okhk.net/posts/8760</guid><pubDate>Fri, 20 Feb 2026 03:21:31 GMT</pubDate><content:encoded>DNS-PERSIST-01：单次 DNS 记录修改即可供持久签发 TLS 证书；预计 26 年 Q2 正式发布。&lt;br /&gt;&lt;br /&gt;- 和 DNS01 的 _acme-challenge 不同，使用的是 _validation-persist 域名前缀。&lt;br /&gt;- TXT 记录包含证书签发方、ACME 账户信息、签发政策，以及授权过期时间等信息。&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://letsencrypt.org/2026/02/18/dns-persist-01.html&quot; target=&quot;_blank&quot;&gt;https://letsencrypt.org/2026/02/18/dns-persist-01.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;/search/result?q=%23PKI&quot;&gt;#PKI&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23LetsEncrypt&quot;&gt;#LetsEncrypt&lt;/a&gt;&lt;a href=&quot;https://letsencrypt.org/2026/02/18/dns-persist-01.html&quot; target=&quot;_blank&quot;&gt;
  &lt;i&gt;&lt;/i&gt;
  &lt;div&gt;letsencrypt.org&lt;/div&gt;
  
  &lt;div&gt;DNS-PERSIST-01: A New Model for DNS-based Challenge Validation&lt;/div&gt;
  &lt;div&gt;When you request a certificate from Let’s Encrypt, our servers validate that you control the hostnames in that certificate using ACME challenges. For subscribers who need wildcard certificates or who prefer not to expose infrastructure to the public Internet…&lt;/div&gt;
&lt;/a&gt;</content:encoded></item><item><title>Let&apos;s Encrypt 宣布证书有效期缩短到 45 天的计划</title><link>https://tg.okhk.net/posts/7897</link><guid isPermaLink="true">https://tg.okhk.net/posts/7897</guid><pubDate>Tue, 02 Dec 2025 10:07:26 GMT</pubDate><content:encoded>Let&apos;s Encrypt 宣布证书有效期缩短到 45 天的计划。&lt;br /&gt;&lt;br /&gt;- Let&apos;s Encrypt 用户可在 2026/5/13 起切换到签发有效期 45 天证书的 profile “tlsserver”。&lt;br /&gt;- 2027/2/10 起，Let&apos;s Encrypt 默认签发证书有效期将从 90 天降至 64 天；2028/2/16 起降至 45 天。&lt;br /&gt;- CA/B Forum 正研究 dns-persist-01 验证方式，使证书更新不再需要修改 DNS 记录；预计 2026 年可供使用。&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://letsencrypt.org/2025/12/02/from-90-to-45.html&quot; target=&quot;_blank&quot;&gt;https://letsencrypt.org/2025/12/02/from-90-to-45.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;thread: &lt;a href=&quot;https://t.me/outvivid/4701&quot; target=&quot;_blank&quot;&gt;/4701&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;/search/result?q=%23CABForum&quot;&gt;#CABForum&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23PKI&quot;&gt;#PKI&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23LetsEncrypt&quot;&gt;#LetsEncrypt&lt;/a&gt;&lt;a href=&quot;https://letsencrypt.org/2025/12/02/from-90-to-45.html&quot; target=&quot;_blank&quot;&gt;
  &lt;i&gt;&lt;/i&gt;
  &lt;div&gt;letsencrypt.org&lt;/div&gt;
  
  &lt;div&gt;Decreasing Certificate Lifetimes to 45 Days&lt;/div&gt;
  &lt;div&gt;Let’s Encrypt will be reducing the validity period of the certificates we issue. We currently issue certificates valid for 90 days, which will be cut in half to 45 days by 2028.&lt;br /&gt;This change is being made along with the rest of the industry, as required by…&lt;/div&gt;
&lt;/a&gt;</content:encoded></item></channel></rss>