Install, configure and automatically renew a free Let's Encrypt SSL certificate
vincent.composieux.fr
vincent.composieux.fr
This is a great scanner and is free: https://www.ssllabs.com/ssltest/analyze.html
> Are certificates from Let’s Encrypt trusted by my browser?
The short answer is “yes”.
The long answer is that our issuing intermediates are cross-signed by a widely trusted IdenTrust root531. This allows our certificates to be trusted while we work on propagating our own root. Most platforms that trust that root should trust Let's Encrypt certs. One notable exception is Windows XP, which currently doesn't accept our intermediate630.
Sadly at the moment not only IE, but also e.g. Chrome on WinXP: https://github.com/letsencrypt/letsencrypt/issues/1660 and https://github.com/letsencrypt/letsencrypt/issues/1942
But XP is silly anyway, it doesn't even have SNI.
It isn't really set up to handle all possible scenarios, so I only made it available as a gist as opposed to a full role available in the Ansible Galaxy. For example, it expects an Apache virtual host to be configured already instead of allowing Let's Encrypt handle it - I do this in another role specifically set up to handle Apache.
Nginx configuration needs to handle the two (or more, depending on subdomains) certificates.
Let's Encrypt is a great initiative and hope that they can support nginx auto-renewal!
That's not accurate - you can have up to n[0] domains on a single certificate
[0]: I don't remember the exact number, but it's more than 2 at least.
From their ReadMe -> https://github.com/letsencrypt/letsencrypt
Worked perfectly.
You won’t be able to use the automated letsencrypt scripts to generate a cert either - you’ll have to use something like acme-tiny (it’s on github) and edit it to upload the proof-of-site-ownership challenge files to the appropriate place on your shared hosting (unless the letsencrypt script already lets you do this? Worth a quick look.)