In our prod we use https://github.com/GUI/lua-resty-auto-ssl to generate over 1k lets encrypt certs that refresh as they expire.
Hope these can help
I'm not sure how up to date https://github.com/hlandau/acme#comparison-list-of-client-im... is.
0 9 * * 0 certbot renew --renew-hook "service nginx restart"
I'm sure there are cases where restarting nginx willy-nilly won't fly, but for non-mission critical it's wonderfully simple.
Cerbot is also great for the initial setup. I just add the non-SSL entry, run `certbot --nginx` and follow the simple prompts.
I've been using this in production for more than a year now, and if you google around a bit, most guides for automating renewal on nginx[1] will use that command.
[1]: https://www.digitalocean.com/community/tutorials/how-to-secu...
How exactly do the other people need to be involved - there is no purchasing/responding to email for proof/etc required.
As for large organizations and the 90 limit, I find dealing with it at work isn't a big deal. We have so many they have to be automated anyway. Even if we only had a few, the process is much easier/faster than it used to be to have someone in the company buy a cert and figure out what files to get to us. Now we can just take care of it, no credit card required. An easy cert every 90 days or so or one that is much more work once a year? Let's Encrypt has my vote and people who want to make excuses will never run out of them.