1) Our software is already open source. That doesn't mean we get the development work that we need when we need it for free. We are constantly working on various features and fixes that need to be deployed weekly if not more often, and usually based on a close working relationship with our operations team. Security fixes need to be produced in hours or less, not when a volunteer contributor gets around to it. Our engineers also spend a lot of time every day digging through hundreds of GB of logs to find or verify service issues.
Keep in mind that our software is deployed by very few people other than us, because in order for our software to be useful you need to have done a massive amount of other (expensive) work to set up the legal, compliance, and technical context.
2) I'm not sure where you get 60k requests per day as a representation of our system load. Between ACME API interactions and OCSP it's many millions.
3) The CA needs to be monitored 24/7. Our infrastructure is necessarily more complicated than your average web API or application, and it's constantly being maintained and improved. Open sourcing doesn't address the issue of having highly qualified and trained staff building and monitoring secure systems.
4) There is a huge amount of tedious compliance and legal work that has to be done in order for us to continue to operate.
5) We operate in a compliance environment (WebTrust/BRs/root program rules). We have a lot of obligations, mostly for good reasons, that make what we're doing very different from "write some code, throw it on GitHub, deploy on a cloud service and be done with it."
2) I thought i saw around 60k certificate requests in statistics on your site.
But your CA server won't be able to sign any certificates that will be recognized by Mozilla, Google, Microsoft, etc. It takes time, energy, and expertise to be a CA authority that is trusted by those organizations.
I think that trying to scrimp and save is not worth the relatively small amount of money saved for something like this. We've seen over and over again that so-called "critical" open source projects cannot afford to operate that way.
It is.
> And let other people work on it and just cover 3 people managing this + architecture costs.
Um, Lets Encrypt, in the course of the last year has inadvertently become one of the largest issuers, and has become critical infrastructure for many of it's users who would suddenly have to pay for certificates, assuming they configured LE certs and Strict Transport Security. If LE was only 3 "managers" + cloud infrastructure, it wouldn't be reliable.
> You don't need 2.9 mil per year to process 60k certificate requests a day with system that is practically finished. What else is there to do which open source community could not do it itself?
The service isn't "practically finished", they need to continue to improve the service to reduce costs, improve the operations capabilities of the service as it grows, From LE: Staffing is our dominant cost. We currently have eight full time employees, plus two full time staff that are employed by other entities (Mozilla and EFF). This includes five operations/sysadmin staff, three software developers, one communications and fundraising person, and an executive director.
>Thousands of companies and developers use letsencrypt, a lot of potential man power to help if you ask me. You could easily cut costs 5-6 times. Or am i missing something here?
You are missing alot... this is not an open source project that anyone other than an existing CA can consume and hit the ground running. If any other major CA decided to consume Boulder, and offer it as a service, they could eat LE for lunch, but for anyone else, they need a massive investment in the logistics of becoming a CA.
Over and above that, LE is a team run on a shoestring, and yet they are building out infrastructure that is likely to be highly targeted by a broad range of attackers. Wether it's DoS, folks trying to get mis-issued certs, or a number of other objectives, that they are running and keeping the service up with that few people and that little money is an impressive feat.