the pki separation is good.
(This is now reversed, of course)
Reducing certificate life to ridiculous time frames, making it difficult to obtain certificates, all for very dubious, extremely tiny and minor improvements in security. It's going to cause more harm than good, and in the end, will reduce not enhance security.
For example, many SMTP servers may revert to self-signed certs now.
It's not fine to force it. There's no logic behind it. Browser and OS updates can expire certificate authorities, and that's the only real reason people claim this is to be done.
Do most SMTP server require, or even use, certs issued by a CA?
[1]: https://letsencrypt.org/2025/05/14/ending-tls-client-authent...
Which systems are these? Are they public email providers? Are they enterprises?
So once you're in the business of providing any kind of general email service you eventually have to deal with it.
Edit: Porsche corporate
londons_explore•1h ago
They don't want your insecure mail server software to put your secure web server at risk.
dandanio•40m ago
dlgeek•4m ago