The fact that they have chosen to reduce certificate lifetime in order to encourage automation is a really big win for the security of the web as a whole.
The fact that they have chosen to reduce certificate lifetime in order to encourage automation is a really big win for the security of the web as a whole.
If you are trying out the client for the first time, you may want to use the --test-cert flag, and a domain name that does not receive live traffic. This will get certificates from our staging server. They won’t be valid in browsers, but otherwise the process will be the same, so you can test a variety of configuration options without hitting the rate limit.
Also linked lower down in the thread
There's a staging server issuing untrusted certificates with significantly higher rate limits for this purpose. With the reference client, it's a matter of using the --staging flag.
Without using the various hacks people have created, you can generate the certificates on linux and then move them over to windows, but doing this all the time is extremely inconvenient.
I hope that this gets addressed at some point, because encryption is important for everyone, not just linux admins.