Does it support wildcard?
Announcing Free and Automated SSL Certs
31–40 of 79 posts
Re: Announcing Free and Automated SSL Certs
#32Sweet, this is basically want Lets Encrypt wanted, make the market go towards this free SSL model.
Companies who aren't in the business of selling TLS [0] certs themselves have little excuse to not offer free TLS via Let's Encrypt. It's an advantage over any competitors who haven't set that process up. If your company does hosting - your company should provide TLS certs via Let's Encrypt automatically . [0] Can we start dropping the SSL part now? Generally SSL v2/v3 is disabled so it is all over TLS anyway.
Re: Announcing Free and Automated SSL Certs
#33Does it support wildcard?
Re: Announcing Free and Automated SSL Certs
#34Earlier quoted context omitted.
Implementing support for LetsEncrypt SSL does have a cost associated with it, particularly at scale. I think restricting the feature to paid users is totally reasonable, particularly since it's still vastly cheaper than getting a traditional SSL certificate.
And what exactly would that cost be? Can it even be quantified? We're speaking of a 4x yearly ACME request of a few kilobytes going to and from the LE servers. It certainly isn't bandwidth. The engineering work was already done, and doesn't change based on the number of instances that are making the cert request. It certainly isn't labor. It certainly isn't storage. Certs are 2-4 kilobytes. Even if we assume Heroku h…
And what pays for that engineering work? The money you make from having the feature.
Re: Announcing Free and Automated SSL Certs
#35Earlier quoted context omitted.
Implementing support for LetsEncrypt SSL does have a cost associated with it, particularly at scale. I think restricting the feature to paid users is totally reasonable, particularly since it's still vastly cheaper than getting a traditional SSL certificate.
And what exactly would that cost be? Can it even be quantified? We're speaking of a 4x yearly ACME request of a few kilobytes going to and from the LE servers. It certainly isn't bandwidth. The engineering work was already done, and doesn't change based on the number of instances that are making the cert request. It certainly isn't labor. It certainly isn't storage. Certs are 2-4 kilobytes. Even if we assume Heroku h…
- You have to build enough of a retry algorithm so that you start renewing well in advance of the expiration date.
- You then have to build the mechanism for warning customers that there was an issue renewing for one of a variety of reasons
- You then have to deal with situations where LE has issues, which happens fairly often
- There's a queueing system, where you have to handle not sending too many certs at once
- You will end up in scenarios where users will migrate off of you, not tell you, attempt to issue another LE cert with another service, and fail, and then blame you
- Similarly, you will have users who connect and disconnect domains, and your system has to be smart enough to properly revoke certificates without locking out a domain from too many retries
- and then what happens when you can't renew a cert for whatever reason? Do you break the user's site? Do you fall back to http?
I'm not saying it's millions of dollars, but at scale, it's complicated. Here's a blog post about how Squarespace did this (disclosure, I work there):
https://engineering.squarespace.com/blog/2016/implementing-s...
Saying it's "just" a 4x acme request annually demonstrates a real lack of understanding of supporting this kind of system at scale.
Re: Announcing Free and Automated SSL Certs
#36Earlier quoted context omitted.
Implementing support for LetsEncrypt SSL does have a cost associated with it, particularly at scale. I think restricting the feature to paid users is totally reasonable, particularly since it's still vastly cheaper than getting a traditional SSL certificate.
And what exactly would that cost be? Can it even be quantified? We're speaking of a 4x yearly ACME request of a few kilobytes going to and from the LE servers. It certainly isn't bandwidth. The engineering work was already done, and doesn't change based on the number of instances that are making the cert request. It certainly isn't labor. It certainly isn't storage. Certs are 2-4 kilobytes. Even if we assume Heroku h…
Re: Announcing Free and Automated SSL Certs
#37Not free. Included with purchase.
Re: Announcing Free and Automated SSL Certs
#38Sweet, this is basically want Lets Encrypt wanted, make the market go towards this free SSL model.
Companies who aren't in the business of selling TLS [0] certs themselves have little excuse to not offer free TLS via Let's Encrypt. It's an advantage over any competitors who haven't set that process up. If your company does hosting - your company should provide TLS certs via Let's Encrypt automatically . [0] Can we start dropping the SSL part now? Generally SSL v2/v3 is disabled so it is all over TLS anyway.
Correction: As part of the paid plan.
Why give for free sometimes you can charge money for.
Re: Announcing Free and Automated SSL Certs
#39Earlier quoted context omitted.
Companies who aren't in the business of selling TLS [0] certs themselves have little excuse to not offer free TLS via Let's Encrypt. It's an advantage over any competitors who haven't set that process up. If your company does hosting - your company should provide TLS certs via Let's Encrypt automatically . [0] Can we start dropping the SSL part now? Generally SSL v2/v3 is disabled so it is all over TLS anyway.
> If your company does hosting - your company should provide TLS certs via Let's Encrypt automatically. Correction: As part of the paid plan. Why give for free sometimes you can charge money for.
Re: Announcing Free and Automated SSL Certs
#40Earlier quoted context omitted.
> If your company does hosting - your company should provide TLS certs via Let's Encrypt automatically. Correction: As part of the paid plan. Why give for free sometimes you can charge money for.
If you have a free plan at all, then the only reason TLS should not be a paid feature would be if you intentionally want to position the free plan as "don't take this seriously because you can't build anything production-quality on it".