In my understanding for public-facing certificates the shorter the lifetime the better (within reasonable limits). But what about Origin Certificates that are only used between CloudFlare and the origin server? Are there any recommendations on not using the 15 year option? Apparently one shouldn’t really be able to create certificates with an expiry longer than 2 years any way.

