The key is generated and instantly outputted over SSL. Nothing is ever stored nor would I want that liability. Would it better if I did the private key generation on the client side so that your browser generates it? The only issue with that is that it's a lot slower and browser compatibility isn't great.
i appreciate the effort to make SSL free and easy. i know the first time I attempted to use lets encrypt it took a bit of work getting setup. what's the possibility of using electron and doing the work locally?
I don't use electron so I'm not sure. This service is for people that don't have access to SSH or don't know how to use letsencrypts' official client on their hosting server. If you do have access then it's best to use the client and have an auto-renew cron, then you won't ever have to renew a certificate again as it will renew and install periodically. If you run cPanel on Cent 6/7 use this guide https://forums.cpanel.net/threads/how-to-installing-ssl-from....
Okay sorry, I looked at electron. If you want a local copy you can try https://gethttpsforfree.com/ it's completely client sided, you can save the html file and use whenever. You have to generate your own keys and CSR though
I just ran through the process, and it worked very smoothly. No hick-ups, it just worked. SSLlabs reports an A. Very awesome.
Thanks. SSL should always have been this easy. I used the let's encrypt client when it came out and it took 3 hours to install on my server requiring root access. I couldn't get a client working on windows as well so for people without root access to their server they can't even really get a certificate. I paid for my certificates before this and it takes at least 30 minutes. This literally takes seconds once you know your FTP or know how to manually do it.
Look at StartSSL's workflow.
Private keys are now generated on the client using the Web Crypto API and never transmitted now. Merry Christmas all!
Even getting your private key from the CA isn't a good idea.