DNSCrypt – how expired certificates became a thing of the past

DNSCrypt – how expired certificates became a thing of the past

A regular DNS query is used to retrieve the server’s certificates that are verified using a public key already known by the client. The reference client implementation, , accepts certificates with any expiration date, but spits out a warning “The key rotation period for this server is excessively long” if it is valid for more than 24 hours. Users get an informational warning 30 days before the expiration of a certificate required by a server they use, another message at a higher severity level 7 days before the expiration, and a critical message if the certificate has less than 24 hours left.

Source: 00f.net