Only free if you value your time at $0.
Only free if you value your time at $0.
And if you're using Apache or Nginx, Certbot[1] can configure Let's Encrypt support for them automatically. It's not the "one-click install" you'd get with some other software, but it's pretty close.
Update: I got it working. I still maintain that it was largely pointless, not zero-effort, and puts the difficulty of running a webserver further into the domain of stuff that's only likely to be undertaken by professional / commercial entities, and that that's a bit of a pity.
Update2: Shit, I broke some other stuff :-(
But even if it was just security, it would be irresponsible to offer something (a blog) and knowingly compromise security for anyone who is interested.
ISPs have been known to inject ads for example.
Like people saying that changing SSH port on your VPS is not security. Setup one Linux VPS and see how many bots are trying to brute force your password. Just change the port so they stop trying.
Only if you value your (and your users/readers) privacy at $0
Haven't had to change a CC number, or trip over any of the usual selection of billing and renewal gotchas.
Fits my definition of free, even after valuing my time as non-zero!
(btw I've used LE both in my day jobs and for some personal stuff, and I very much appreciate its existence).
If you consider constant warnings from most browsers that annoy your users and coming up with new excuses as to why you haven't moved to HTTPS as not being a cost…
Also, sometimes doing a bit of server work is rewarding on its own.
Your attitude is irresponsible. HTTPS is not a luxury, it is a requirement.
1. The Let's Encrypt service from ISRG, which is a charity and so obviously if the donations dried up and somehow we didn't fix that then eventually (maybe a year or more) it would go away. This is also true for Wikipedia and the EFF in the most obvious direct sense, but it's true for all commercial services you rely on too, Youtube, Facebook, Hacker News, all could go away if their owners decide there isn't enough money any more.
2. ACME and other certificate automation. These are protocols, in ACME's case IETF Standards Track protocols, for how we can validate control over a name and issue certificates to an applicant. These don't vanish if ISRG goes away. For example loads of cPanel users already don't use Let's Encrypt, they have a single button "Yes, I want free certificates" feature, and Comodo (the root CA behind that) is taking a slice out of the cPanel license fees.
Why not use LetsEncrypt until it’s no longer available?
Not really. With Let's Encrypt available, the browser makers are now talking about penalising all HTTP sites. Next year, or the year after that, they could decommission Let's Encrypt (or start charging), and suddenly we'd all see what had been lost: it'd no longer be possible to set up an unpenalised site for free.
Personally, I believe that an IP cert should be issued along with one's IP address, and a hostname cert should be issued along with one's domain name.
My small business page's cert got messed up (by Plesk, or the hosting provider I suspect) and the page went offline.
If your site being essentially unavailable to customers isn't a major consequence I don't know what is.