Interesting. That's an (expired) Cloudflare certificate, and those are Cloudflare IP addresses I'm being sent to.<p>I wonder if Cloudflare broke this somehow (whoops) or if Thunderbird themselves screwed up here. I don't see a CAA record that would tell DigiCert they can't issue this either.
Mozilla seems to repeatedly suffer this[1]. I wonder what solution they use for expiry monitoring.<p>1: <a href="https://www.computerworld.com/article/3393446/mozilla-issues-fix-after-it-lets-cert-expire-and-firefox-add-ons-go-belly-up.html" rel="nofollow">https://www.computerworld.com/article/3393446/mozilla-issues...</a>
I know little about SSL certificates. Could someone tell me why they should expire regularly? Is it for precaution? Is it just because "good practices". What's the difference (from a security point of view) between a certificate that expires in 3 months and one that expires in 3 years?