> I don't mind if the protocol if FUBAR. It works for me and it works for an awful lot of people. And it encrypts the web.
To me, it feels like most stuff becomes much more troublesome once you peel back the curtain and drop down to the internals. For most folks (myself included), using a web server that handles most of this for you will be enough. There's Traefik, there's Caddy and plenty of other options.
Even Apache has support for ACME with mod_md, about which I wrote on my blog last year: https://blog.kronis.dev/tutorials/how-and-why-to-use-apache-...
It's not perfect (you still need a restart/reload for the new cert to be actually used), but the configuration side of things is simple enough and most of the issues are known: https://httpd.apache.org/docs/2.4/mod/mod_md.html
> Before that, it was manually re-creating a cert, faffing with chains (converting formats and dealing with bad documentation) and update the production servers manually. It was a royal PITFA.
This has always been a pain to me, for example, the OpenSSL CLI is a bit like tar in how unintuitive it is, vs something like the Docker CLI which walks you through a tree of commands with all of their parameters that you might be interested in. Curiously, I've had most success with using graphical software for manually working with certificates, like Keystore Explorer: https://blog.kronis.dev/tutorials/lets-run-our-own-ca
The linked article is a bit barebones (I didn't feel like Googling for the OpenSSL equivalents for the actions to demonstrate the difference in UX), but I want to express the importance and usefulness of your software (CLI, TUI, GUI, API, whatever) telling you what options are available to you, which makes a world of difference.
In my eyes, there's no reason why a junior dev or someone who hasn't worked with OpenSSL (or an equivalent piece of software) in the past should have their first time doing so be miserable. Then again, needing to think about bunches of different formats and what technology accepts what is probably always going to be at least moderately painful or annoying: https://serverfault.com/a/9717
> Don't forget to set a calendar reminder for the next year's renewal.
Thankfully, this is pretty easy to deal with! Even if you use ACME, you'll still want this in place, in case automatic cert renewal fails, or if the cert just isn't swapped over to by the web server.
For example, for the self-hosting crowd, something like Uptime Kuma allows you to have all sorts of reminders, including certificate expiry: https://github.com/louislam/uptime-kuma (note: Uptime Kuma does not batch those notifications, I got about 30 messages in Slack at the same time because a bunch of sites had the same wildcard certificate that was going to expire)
Basically, it's nice to see that as a end user of software you can have a decent experience, for the most part. Definitely a bit better in some regards than what you might have been dealing with 10 years ago or so. Not that all of the problems or nitpicks are solved, or will be for the foreseeable future.
Personal worries: what if Let's Encrypt becomes a non-viable option for whatever reason? There aren't that many ACME compatible providers out there.