Or very long ones. I often generate 10 year certs because then I don't have to worry about renewing them for the lifetime of the hardware.

In a production environment with customer data?

No for internal stuff.