Looking Forward to 2018
letsencrypt.org
letsencrypt.org
I sincerely hope that they don't become like Wikimedia with their ever-increasing scope and bureaucracy. And it might work because Let's Encrypt has a rather specific mission (free TLS certs for everyone), whereas Wikimedia has a rather broad mission (free knowledge/data for everyone).
It's an extension of their offering rather than a new product.
This also affects systems like Sandstorm, which use randomly generated, unguessable subdomains per user session per "grain" (document), which may have (small) privacy concerns in some cases. Certificate Transparency would publicly publish every subdomain generated, even if the rate limits weren't a thing.
In the long run it might actually save them money by cutting down on the total number of certs their system has to verify and sign.
Don't forget the past :)
No no no... That's a gain of 50% (give or take) or 21 percentage points; not a gain of 21%.
It may be similar to people not feeling the difference between causation and correlation.
It clearly doesn't talk about the gain of a percent of a percentage.
shouldn't it get less again? if i use ~8 certs for different servers, i could just get a wildcard for my domain and be done with it...?
If anything it will reduce the strain on their servers. Instead of authorising subdomain by subdomain there will be a single authorisation by domain.
1) Wildcards may have a net negative effect on total issuance if subscribers who were getting many non-wildcard certificates before replace them with a single wildcard. I'm not sure this will be the case, but it could be. I expect wildcards will help move many more sites to HTTPS - perhaps just with fewer actual certs.
2) Wildcard validation from Let's Encrypt will be restricted to DNS validation, and many people don't have the ability to automate modifications to their DNS records. That being the case, it will be a bit more difficult to validate for wildcard certificates than for non-wildcards.
enableACME = true;
This automatically does the ACME thing and sets up systemd units to renew the certificate. Have been using it a while for my (sub)domains and it's worked really well.[1]: https://nixos.org/
[2]: https://nixos.org/nixos/options.html#%3Cname%3E.enableacme
https://github.com/mholt/caddy
(I'm not affiliated, just a happy user)
They fixed that so that it has three weeks grace. Now only if you switch off the server wait until the cert has almost expired (say five days left) then switch it on, Caddy will go "eek, time to renew" and if Let's Encrypt is down it'll give up and the server doesn't start.
This means either Let's Encrypt was down for longer than a decent summer vacation or you switched off your own web site for weeks. Neither of those is a good idea.
So think that qualifies as a good integration.
https://letsencrypt.org reports Identrust.
However it seems that https://community.letsencrypt.org/ which would seem a good place to get help is actually using one of their certificates so maybe it's just historical. The certificate dates back to 2015 and expires in next February, maybe they'll replace it by one of their own then.
I understand though, code signing will be much harder to automate and maybe not so fit for purpose...
So if you wanted to sign a windows executable, you'd need to have a microsoft account, and that microsoft account would need a place that you could publicly post a string of text.
Then it's up to the Lets Encrypt service to validate that and cut the certificate
This allows a competitor (even a commercial) one to fill in the gap left by letsencrypt if they stop issuing certs.
Still, it's worth it. I have some private sites that now have TLS thanks to let's encrypt, which were plain HTTP before.
I still wish for a second free, automated CA. Just to have redundancy.
They're never gonna run of of founds - their backers (Mozilla, Akamai, OVH, Cisco, Google, EFF,++++) would never let them.
There's also the possibility of their competitors pushing an agenda with standards bodies that pushes up the cost of PKI to try to freeze them out.
If they charged a token amount I don't think it would be so bad (except for the whole getting it through the bean counters problem), but it would be more lucrative for them to charge people money for raising the rate limits in their system.
Certain people like Akamai are charging exorbitant amounts to manage large numbers of SSL certificates. Just look at their quarterly revenue, it's insane. Other providers could partner with LetsEncrypt and undercut them substantially enough that they could steal customers, but it might mean LetsEncrypt has to scale up their operational limits to do so.