

The real value is in the agility needed to update certs every six days.
Six days is still too long to leave a compromised key in play, but anyone who can rotate their keys every six days can probably also rotate their keys quite quickly if there’s a comprise.

I plan to operate on expired certificates for two to four years, forcing all three of my users to click past a terrible warning.
Then I will automate my six day certificate rotation with Ansible (officially), but maybe actually with a stupid bash script in CRON (unofficially).