diff --git a/nix/modules/hive-tls.nix b/nix/modules/hive-tls.nix index b55533d8..e2a6d791 100644 --- a/nix/modules/hive-tls.nix +++ b/nix/modules/hive-tls.nix @@ -63,22 +63,14 @@ in leafValidityDays = lib.mkOption { type = lib.types.int; - default = 30; + default = 3650; description = '' - Validity window of the gateway leaf cert in days (default 30). - Short-lived by design — ahead of the CA/Browser-Forum's move - toward ~47-day max lifetimes — which bounds the blast radius of a - leaf-key compromise. The leaf is re-signed by the (stable) CA - when it is missing or near expiry; because it shares the CA - anchor, a rotation does not disturb consumer trust. Agents and - federation peers validate against the CA, not browser CA/B-forum - limits. NOTE: at this short a window the re-sign must run more - often than the leaf lifetime. Today `hive-tls-ca` re-signs at - service activation (boot/rebuild) only — there is no periodic - re-sign timer yet — so a hive that does not reboot within the - validity window would let the leaf expire. Keep that in mind (or - add a re-sign timer) when running a hive that stays up for long - stretches without a rebuild. + Validity window of the gateway leaf cert in days (default ~10y). + The leaf is re-signed by the (stable) CA when it is missing or + within 30 days of expiry; because it shares the CA anchor, a + rotation does not disturb consumer trust. Browsers may warn on + long-lived leaves, but agents and federation peers validate + against the CA, not browser CA/B-forum limits. ''; }; };