can someone please share how they deploy/distribute Let's encrypt certificates with auto renewal on load balanced multiple EC2 servers for the same dns name. I had tried this a while but had to give up and just bought SSL certs which I then include in my EC2 image.
Let's Encrypt makes certs for 30% of web domains
11–20 of 147 posts
Re: Let's Encrypt makes certs for 30% of web domains
#12Re: Let's Encrypt makes certs for 30% of web domains
#13Re: Let's Encrypt makes certs for 30% of web domains
#14can someone please share how they deploy/distribute Let's encrypt certificates with auto renewal on load balanced multiple EC2 servers for the same dns name. I had tried this a while but had to give up and just bought SSL certs which I then include in my EC2 image.
Re: Let's Encrypt makes certs for 30% of web domains
#15The GCP self-serving platform for certs is very welcome, but still kinda janky. You end up waiting hours for their batch jobs to run at unknown cycles. Let's encrypt is awesome because it's instantaneous! You'd think Google would understand that aspect. Edit: GCP people: Please give us a an explicit "retry" button to press when we've set up the DNS records. (I'm talking about the Google Cloud Balancing Service here.…
Better hope you don't get your account automatically banned because one of your employees does sketchy things on their own personal account
Re: Let's Encrypt makes certs for 30% of web domains
#16This kind of centralization is not good. Even thought let's encrypt is non profit and has a very good service record. We desperately need more like it spread around the globe.
Re: Let's Encrypt makes certs for 30% of web domains
#17A few of these things, while not necessarily wrong, should be put into context. E.g. "Hundreds of thousands of domains' certs expire after 2099". Yeah, but no publicly trusted certs. They're capped at a bit more than 2 years and there's a discussion to cap them even more. The certs they're seeing are almost certainly mostly: "let's create a test selfsigned cert for this host. how long should it last? let's type in a…
Historically there were some certs that kept getting grandfathered in after lifetimes were restricted because they'd been issued before there were any rules - maybe ten years to expire or even more? I think the last of those probably went away because of the Symantec distrust (not that they were issued by Symantec, but they were issued by a CA which was bought by a CA which in turn was bought by Symantec before it was distrusted) and also of course they'd have either MD5 or SHA-1 signatures, which are not accepted today anyway.
There were still certs issued right up until the end of March 2018 with the old 39 month lifetime maximum. You can see them most easily in the annualised CT logs for 2021. A while back CT log operators realised that logs just get longer (of course) and so they would need to periodically make new ones and archive the old ones. Very quickly they struck upon the idea of annualising them, instead of running FooBar Log, run FooBar Log 2019, FooBar Log 2020 and FooBar Log 2021, and then require any submissions to use the log matching the year of expiry of the certificate they were logging. This way you can archive FooBar Log 2019 when people get back from holidays after celebrating New Year 2020, all the certs in that log are expired anyway now.
I guess that today the last of those 39 month certs will actually expire before a brand new 825 day cert, but they are still out there, so don't write software that assumes leaf certs can't last more than 825 days just yet.
Re: Let's Encrypt makes certs for 30% of web domains
#18This kind of centralization is not good. Even thought let's encrypt is non profit and has a very good service record. We desperately need more like it spread around the globe.
What problems would decentralization solve here?
Re: Let's Encrypt makes certs for 30% of web domains
#19This kind of centralization is not good. Even thought let's encrypt is non profit and has a very good service record. We desperately need more like it spread around the globe.
What problems would decentralization solve here?