4 ms·
> Let's Encrypt only issue certificates that are valid for 90 days[0] because they want you to automate renewal by having your server automatically run their sc
by iamsohungry 11y ago
> Let's Encrypt only issue certificates that are valid for 90 days[0] because they want you to automate renewal by having your server automatically run their script which needs root privileges
The provided script:
1. Is FOSS. You can audit it before running.
2. Is an example, not required. You can write your own script from scratch if you want, or even do it by hand (although this would be admittedly tedious to do every 90 days).
> and they use Google as the gatekeeper of who is allowed a certificate[1].
That's a drastic oversimplification. The Google Safe Browsing API lists phishing and malware sites. I can see some concern that Google might mark sites as phishing or malware for political reasons or something, but so far I know of no cases of that happening. In fact, high-profile sites that do contain a lot of malware have been left unmarked: see Pirate Bay, Kickass Torrents, MegaUploads. I definitely have concerns about censorship, but so far I see no evidence that's happening. If you have such evidence, I'd be very receptive to seeing it.
> We are still short an option that issues certificates that are valid for 1+ years
That's not something I want, or something that's good for the security of the internet.
> can be used for any purpose and doesn't pass every request to a corporation for approval.
As long as the limitation continues to be on malware, I'm fine with it, and I'm not sure why you aren't.
P.S. To be clear, I know very little about StartCom and am not defending or attacking them.