Lets encrypt is one obvious thing to mention here, besides removing the cost barrier to entry it really is quite simple to set up.
Lets encrypt is one obvious thing to mention here, besides removing the cost barrier to entry it really is quite simple to set up.
I haven’t tried but I think it’s only simple is you’re willing to manually renew every 90 days. I’m not willing to.
Automatic renewals are only simple for popular environments like LAMP, my web server runs Windows server with IIS and old school asp.net. I can run arbitrary native code on that server, but I don’t have GUI access to that machine.
But even if it would be super-easy and automated for 100% web servers, that’s still introducing a dependency to a third-party service, for no value for audience of my web site. Just shutting up a web browser that I don’t even use myself is not a good reason, IMO.
That's the opposite of the design goals - Let's Encrypt is designed to be automatable.
They set the expiry to 90 days precisely because they want you to automate the renewal.