I can't believe that they not only decided not to implement ACME (the protocol behind Let's Encrypt), but also not to at least reuse large portions of ACME, like the way HTTP ownership validation was implemented. It's simply mind-boggling how they would discard a protocol that has received a lot of attention from various security experts. What's more, this design could not have been reviewed by anyone familiar with h…
FWIW I got in contact with their R&D team earlier last week and they told me: no StartEncrypt API now, later it will support IETF ACME, maybe open source.
Re: StartEncrypt considered harmful today
#41Neat. Maybe they can even put license compliance on their roadmap (they statically linked in OpenSSL).