You no longer have to ask year after year for a new certificate. It will be renewed automatically for as long as your webserver lives. And everything is backed by good protocols, a strong community and a trustworthy organization (EFF).
You no longer have to ask year after year for a new certificate. It will be renewed automatically for as long as your webserver lives. And everything is backed by good protocols, a strong community and a trustworthy organization (EFF).
Now you have to ask every three months.
It improves security at the small cost of having to slightly improve your deployment process.
No, you have a script running that updates your certificate automatically, and you never ever have do that that manually again. Or, you don't need that script because your webserver (e.g. Caddy) does that for you.
Oh, and just in case one of the intermediate certificates of Let's Encrypt had to be revoked for some reason: The very same mechanism would provide you with a new, working certificate as soon as possible. This, again, is fully automatic without any headache on your side.
Do you know any other CA where get this level of comfort?
I have a running system with Let's Encrypt certificates for webserver (HTTPS) as well as mail server (SMTPS, IMAPS, POP3S), based on nginx, exim4 and dovecot, using certbot.
Setting up Let's Encrypt literally consists of just 3 steps:
1. In the webserver for all domains on HTTP, add alias /.well-known/acme-challenge to /var/www/letsencrypt/.well-known/acme-challenge
2. Run "certbot certonly" once for every domain
3. Add cronjob for "certbot renew" with a post-hook that restarts your webserver and mailservers.
Well, to be honest, there is one more step, but that one is specific to my own setup, and also just a one-time effort:
3a. Add a post-hook command that fixes a permission issue with Debian-exim. Note that this is only needed if you want to use the certificates for SMTPS and use exim under Debian.
If you add a new domain later on, this is just a single step, no need to touch the cronjob:
1. Run "certbot certonly" once for that domain
So yes! Once you have the setup running, setting up a new SSL/TLS domain is actually easier with Let's Encrypt than with any other CA.
(Of course, you'll also have to add the domain to your webserver configuration, but that's always needed, whether you use Let's Encrypt or not.)
StartSSL was at the perfect price point for my needs (which are a weird mixture of SMB with Large/Enterprise). It's a damn shame what happened to it.