How Etsy Manages HTTPS and SSL Certificates for Custom Domains on Pattern
codeascraft.com
codeascraft.com
We at Let's Encrypt talk to a lot of large providers about large deployments and there's really nothing more helpful than being able to refer engineering teams to detailed accounts of previous efforts.
These writeups really make a difference because they accelerate other large deployments. The sooner those other large deployments happen, the sooner many more people will experience a more secure and privacy-respecting Web.
However, for a small startup (like mine), I think it's still a bit too much work to get this working. I know that there aren't any other "automated" options out there anyway. Perhaps one day. :)
Thanks
Looking forward to seeing your work. Will definitely aim to provide feedback too!
(upvoted)
How many pools are there? If you're having to restart apache every time you renew a cert, are they renewing certs in the background and then only restart apache when they have around a thousand renewed? If so, wouldn't the current running certs be revoked in that time? It seems like on-the-fly cert usage is something that could be made, if not already.
[1]: https://github.com/openresty/lua-nginx-module/#ssl_certifica...
This stuff is ancient but still works great.
Also curious to know more about their LB solution and how it scales. Encrypting everything isn't free if you're doing thousands of ECDH[E] handshakes per second to chase down that "A+" rating.
Congrats for them for supporting Let's Encrypt as an organization (it's not mentioned in the article it is in the comments here).