Live data from Hacker News

Public Beta: December 3, 2015

letsencrypt.org

11–20 of 70 posts

Re: Public Beta: December 3, 2015

#11
post #8

I am beginning to wonder how much effect Let's Encrypt will really have on wide TLS deployment. A very large portion of the web is stuck at shared hosting services, such as Go Daddy, Lunarpages, et al. These services generally charge for TLS hosting, and due to the 90-day issuance on Let's Encrypt certificates it seems somewhat infeasible to use their certificates on shared hosts which offer very limited (if any) she…

A VPS costs 5 bucks on DO and I've seen (can't remember where) a 3 USD/month offering. So it's rather cheap to move away from shared hosting nowadays. For me Let's Encrypt came out at the right time. They said they will automate the 90-day renewal process.

Side question, does anyone actually enjoy running a VPS? Between managing the sites on it, you have to maintain the VPS, keep it up to date, its prone to security bugs and flaws, etc. Am I missing something here? I remember setting up multiple VPSes on Linode / DO and it was always a painful process of installing the OS, installing the whole stack, configuring everything, setting up users / roles, firewalls, etc.

On top of that, whereas on a shared host i click a button and host a second domain, with a VPS I have to SSH in and manually edit server files.

But everyone always recommends running a VPS so I can't help but imagine I've either missed some magical tool that makes running a VPS a snap or it's just not a realistic solution for most people.

Re: Public Beta: December 3, 2015

#12
post #2

So a slight delay then, previously they announced general availability for November 16th: https://letsencrypt.org/2015/08/07/updated-lets-encrypt-laun...

Given the scope of what they are trying to accomplish and the fact that I've never worked on a project which was delivered on time and with all features complete, I'm pretty happy that the delay isn't longer! :)

Re: Public Beta: December 3, 2015

#13
post #11
post #8

Earlier quoted context omitted.

A VPS costs 5 bucks on DO and I've seen (can't remember where) a 3 USD/month offering. So it's rather cheap to move away from shared hosting nowadays. For me Let's Encrypt came out at the right time. They said they will automate the 90-day renewal process.

Side question, does anyone actually enjoy running a VPS? Between managing the sites on it, you have to maintain the VPS, keep it up to date, its prone to security bugs and flaws, etc. Am I missing something here? I remember setting up multiple VPSes on Linode / DO and it was always a painful process of installing the OS, installing the whole stack, configuring everything, setting up users / roles, firewalls, etc. On…

I don't think it's a question of "enjoy" versus "need". If you just doing some static hosting with perhaps PHP, sure, go with shared hosting. The second you need to run your own Java server, Go server, etc. you're in VPS territory.

Re: Public Beta: December 3, 2015

#14
post #11
post #8

Earlier quoted context omitted.

A VPS costs 5 bucks on DO and I've seen (can't remember where) a 3 USD/month offering. So it's rather cheap to move away from shared hosting nowadays. For me Let's Encrypt came out at the right time. They said they will automate the 90-day renewal process.

Side question, does anyone actually enjoy running a VPS? Between managing the sites on it, you have to maintain the VPS, keep it up to date, its prone to security bugs and flaws, etc. Am I missing something here? I remember setting up multiple VPSes on Linode / DO and it was always a painful process of installing the OS, installing the whole stack, configuring everything, setting up users / roles, firewalls, etc. On…

> installing the OS, installing the whole stack, configuring everything, setting up users / roles, firewalls, etc.

> SSH in and manually edit server files.

Docker solves almost all those problems. Comes with its own complexities, though.

Re: Public Beta: December 3, 2015

#15
post #8

I am beginning to wonder how much effect Let's Encrypt will really have on wide TLS deployment. A very large portion of the web is stuck at shared hosting services, such as Go Daddy, Lunarpages, et al. These services generally charge for TLS hosting, and due to the 90-day issuance on Let's Encrypt certificates it seems somewhat infeasible to use their certificates on shared hosts which offer very limited (if any) she…

A VPS costs 5 bucks on DO and I've seen (can't remember where) a 3 USD/month offering. So it's rather cheap to move away from shared hosting nowadays. For me Let's Encrypt came out at the right time. They said they will automate the 90-day renewal process.

I don't think cost is what's keeping people on shared hosting versus VPS. It's that there is a whole wide world of people just doing a little static hosting. They don't want, need, or know how to use a VPS.

Re: Public Beta: December 3, 2015

#16

Is there finally a way to renew the certificate without taking down the web server listening on :443? This was the major thing missing from being able to deploy it in production.

There's no downtime when using the webroot method, see here for details: https://community.letsencrypt.org/t/using-the-webroot-domain...

Re: Public Beta: December 3, 2015

#17
post #8

I am beginning to wonder how much effect Let's Encrypt will really have on wide TLS deployment. A very large portion of the web is stuck at shared hosting services, such as Go Daddy, Lunarpages, et al. These services generally charge for TLS hosting, and due to the 90-day issuance on Let's Encrypt certificates it seems somewhat infeasible to use their certificates on shared hosts which offer very limited (if any) she…

A VPS costs 5 bucks on DO and I've seen (can't remember where) a 3 USD/month offering. So it's rather cheap to move away from shared hosting nowadays. For me Let's Encrypt came out at the right time. They said they will automate the 90-day renewal process.

There are reasonable offerings for between 10 and 20 USD/year (from companies that are even likely to be around long enough for you to use the full year - there are cheaper still from the other sort of company) some with enough CPU+memory+disk space to be useful for more than static hosting too. Look at places like lowendtalk.com for such offers when they turn up.

Re: Public Beta: December 3, 2015

#18

I'm really pleased to see this initiative and I've used the private beta with letsencrypt-nosudo[0] to issue a certificate, but after successfully getting a certificate my site failed the SSL Labs test[1] with an 'unknown CA' error, even though I used the newer one that should have been trusted. It was probably down to user error and the additional complexity of denying sudo privileges for the set up script, but it t…

I actually love the idea of 90 day (or less) certificates! Once you automate the process of replacing your certificate (which let's encrypt will greatly help with), it won't matter how short the period is. Also, if a key gets compromised, it'll be valid for a shorter time. Give https://letsencrypt.org/2015/11/09/why-90-days.html a read! If you want to get more in-depth about certificate revocation, http://news.netcraft.com/archives/2013/05/13/how-certificate... is also a great/depressing read.

Re: Public Beta: December 3, 2015

#19

I'm really pleased to see this initiative and I've used the private beta with letsencrypt-nosudo[0] to issue a certificate, but after successfully getting a certificate my site failed the SSL Labs test[1] with an 'unknown CA' error, even though I used the newer one that should have been trusted. It was probably down to user error and the additional complexity of denying sudo privileges for the set up script, but it t…

I think you really have to understand that at its heart, Let's Encrypt is not about free certs as much as it is about automatic certs. If you just want a cert, definitely use an established provider. But a year from know, LE will be making this a "set and forget" thing, which is how it should be. LE is NOT a painless way to get certs for legacy infrastructure. I found this out by using it for an elastic beanstalk hosted site. I just wrote about it at https://go-to-hellman.blogspot.com/2015/11/using-lets-encryp...

Re: Public Beta: December 3, 2015

#20

I'm really pleased to see this initiative and I've used the private beta with letsencrypt-nosudo[0] to issue a certificate, but after successfully getting a certificate my site failed the SSL Labs test[1] with an 'unknown CA' error, even though I used the newer one that should have been trusted. It was probably down to user error and the additional complexity of denying sudo privileges for the set up script, but it t…

There's definitely some rough edges on the tooling that will make this less painful. You likely used it with development endpoints, which only give certificates signed by untrusted CA (happy hacker fake CA or something like that). However, the point[1] of short lifetime of the certificates is to incentivize automating it. I'm highly hopeful that in a short while, having an HTTPS certificate is a matter of apt-get install.

[1]: https://letsencrypt.org/2015/11/09/why-90-days.html

Post reply on HN