I've used them a bunch. We host a lot of internal-facing utilities that are low-profile, but occasionally hosting sensitive data. In the past I couldn't convince managers to spend money on certs even if the cost of someone stumbling on these sites could be very high and certs are cheap. Now I don't even have to ask.
Keep in mind that Let's Encrypt publishes a searchable list of all domains issued. https://crt.sh/?Identity=%25&iCAID=7395
Early Impacts of Let's Encrypt
11–20 of 98 posts
Re: Early Impacts of Let's Encrypt
#12Re: Early Impacts of Let's Encrypt
#13Wow. Public beta for 2.5 months and already 700,000 certificates issued, more than a third of the largest competitor's number, about 10% of the entire secure Web. There certainly seems to have been pent-up demand.
Re: Early Impacts of Let's Encrypt
#14For anyone struggling with creating Let's Encrypt certificates (or just as lazy as I am), try out https://gethttpsforfree.com/ .
Re: Early Impacts of Let's Encrypt
#15So, Let's Encrypt became 4-th in the world by amount of certs? Am i right?
CT logs are populated by CAs sending their certificates to log servers. Only a few CAs (including Let's Encrypt) do this consistently at the moment, since it's only mandatory for EV certs (for now), and CAs generally move rather slowly. Certificates encountered by Googlebot during web crawling also get pushed to their log servers. Censys probably does something similar.
It's possible that there's a large number of certificates issued only for internal systems that would not end up on CT log servers and that are not accessible by public crawlers, so the numbers are probably not painting a full picture. It is, however, as close as you can get to the full picture unless every CA is willing to release their internal numbers.
Re: Early Impacts of Let's Encrypt
#16Wow. Public beta for 2.5 months and already 700,000 certificates issued, more than a third of the largest competitor's number, about 10% of the entire secure Web. There certainly seems to have been pent-up demand.
There is always pent-up demand for a previously-expensive service to become free.
Re: Early Impacts of Let's Encrypt
#17Does anyone know where one can get a free wildcard certificate? Need it for development and foo/bar/baz/biff.example.com change names regularly (they include the hash of the code commit) so I would like to get a *.dev.example.com wildcard cert. (one that won't give warnings that scare the business types who are testing the code, and won't understand what self-signed means.)
Re: Early Impacts of Let's Encrypt
#18Earlier quoted context omitted.
There is always pent-up demand for a previously-expensive service to become free.
There were free options. I think the biggest benefits to Let's Encrypt are the EFF's clout and the simplicity.
LE made SSL free, trusted and long-term. You could have made it twice as hard to do the initial setup and people would have jumped at the opportunity regardless.
Re: Early Impacts of Let's Encrypt
#19Earlier quoted context omitted.
There is always pent-up demand for a previously-expensive service to become free.
There were free options. I think the biggest benefits to Let's Encrypt are the EFF's clout and the simplicity.
Incidentally, does anyone have a good way to integrate LE with EC2's load balancers?
Re: Early Impacts of Let's Encrypt
#20Does anyone know where one can get a free wildcard certificate? Need it for development and foo/bar/baz/biff.example.com change names regularly (they include the hash of the code commit) so I would like to get a *.dev.example.com wildcard cert. (one that won't give warnings that scare the business types who are testing the code, and won't understand what self-signed means.)
As an alternative you could incorporate provisioning of a Let's Encrypt certificate for the new subdomain into your deployment process since the process is designed to be automated.