Let's Encrypt: Active Incident, DNS errors causing service disruption
letsencrypt.status.io
letsencrypt.status.io
The bigger complaint about StartSSL should be that if you need to revoke the certificate you have to pay for it.
For a free service though I don't think their requirements are too terrible.
Hopefully there are a few other alternatives that just make their money on EV certs instead.
Many of our clients are excited about LE, and as we figure out how to support it without disrupting our infrastructure too much, it's concerning to imagine that there's substantial daily risk that 4-5 certs will fail to renew.
I suppose since it's free and automated, you just renew a month earlier than required.
[1] https://letsencrypt.org/sponsors/ [2] https://letsencrypt.org/become-a-sponsor/
There is something strange going on at the moment, though, but not sure it has to do with DNS. I actually tried set up my first cert about 10 hours ago with Let's Encrypt, and got a variety of ungraceful errors with the same configuration. Only one was related to DNS. Most were code 500 from the api servers.
April 14, 2016 12:47PM MDT
April 14, 2016 6:47PM UTC
[Investigating] We have noticed an increased number of errors. We are investigating now.
April 14, 2016 1:21PM MDT
April 14, 2016 7:21PM UTC
[Resolved] Systems have fully recovered and all services appear to be operating nominally. Cause seems to have been a transient hardware failure and further investigation is under way.
Or at least the most recent issue... they both marked it as resolved and "further investigation is under way". Should be "investigating/monitoring" instead?