Apple clients do not trust TLS certificates with long Validity Periods

It took quite some time but here is the proposed automatic renewal of the self-generated certificates in case of certificated with short-term validity:

The proposed validity range is reduced from 30 to 2 years in here, but this is not set in stone. I'd like to foster a discussion here for what you think is needed.

Note: Short lifetimes may cause some inconvenience to users. Whenever the certificate is automatically regenerated, users will again have to confirm that they want the browser to trust the new certificate:

(Chromium)


(Firefox)