13 ms·
Get HTTPS for free
- godzillabrennus 11y agoThis is definitely a step in the right direction. It's bugged me that vendors are leveraging a commercial and proprietary system to secure sites. If we are going to move forward with this as the baseline of security for public facing sites then it's good to see a free and transparent solution pop up to help lower costs for students and the developing world.
- Smudge 11y ago> This website is static, so it can be saved and loaded locally. Just right-click and "Save Page As.."! This strikes me as particularly neat. I wish more SPA's were able to work like this.
- dham 11y agoIt would be somewhat hard. You couldn't do things like CSRF tokens or any kind of data that comes from the server and rendered on the page. Also the assets couldn't be named with hashes to be cached indefinitely. But the concept is interesting.
- mintplant 11y ago> Also the assets couldn't be named with hashes to be cached indefinitely. I don't see why not.
- diafygi 11y agoThis is my project, happy to answer questions or receive feedback. The goal was to let people experiment with getting a Let's Encrypt cert before the had to install anything on their server. The static/unhosted property is to strengthen trust that nothing shady is going on here.
- seivan 11y agoSo if you use the Keychain Assistant on OS X to generate a CSR, that should be enough? Or am I missing something here? Thanks for the service!
- diafygi 11y agoIf they generate x509 compliant CSRs, then this should work. If not, please file an issue with the CSR, and I'll take a look to see why it's not parsing correctly.
- seivan 11y agoYup, though not sure I am doing it right. Printed the public key and that worked fine. Went to step 2 and pasted in my CSR, and that also worked fine. Basically Start Keychain -> "Request a Certificate from a Certificate Authority" -> Save to disk. Though weirdly enough, my public key generated from keygen didn't quite work, I actually had to use "openssl rsa -in myPrivateKey -pubout" for it to accept it. Why is that?
- doughj3 11y agoThanks, diafygi! I used this a few weeks ago for a new domain and it was incredibly easy to get set up. Definitely appreciate you providing both Nginx and Apache isntructions as well. Great tool here!
- pytrin 11y agoDoes this support wildcard subdomains? If not, would you be willing to add such support?
- deleted 11y ago[deleted]
- toupeira 11y agoThis uses LetsEncrypt which doesn't support wildcard certificates yet: > Will Let’s Encrypt issue wildcard certificates? > We currently have no plans to do so, but it is a possibility in the future. Hopefully wildcards aren’t necessary for the vast majority of our potential subscribers because it should be easy to get and manage certificates for all subdomains. From https://community.letsencrypt.org/t/frequently-asked-questions-faq/26 https://community.letsencrypt.org/t/frequently-asked-questio...
- dasmoth 11y agoThanks for making such a great little tool. Are you still intending to add a renew page at some point?
- diafygi 11y agoMaybe, swamped at my startup (we're hiring!). Pull requests welcome!
- theviajerock 11y agoWhere can I see the open positions???
- overcast 11y agohttps://angel.co/utilityapi/jobs https://angel.co/utilityapi/jobs
- deleted 11y ago[deleted]
- DrScump 11y agoAre you getting Smartmeter data direct from the utilities, or do you sniff it direct from consumers via wireless?
- LCDninja 11y agoThis is fantastic! Thank you very much for creating this!
- nulltype 11y agoThe Let's Encrypt certificates seem to expire after 90 days. I wrote up some example code in Go so you can automate the process of issuing these certs here: http://goroutines.com/ssl http://goroutines.com/ssl It does not require CSRs, but uses your DNS provider to complete the challenge. You do not need to run anything on your production servers.
- imron 11y agoYes, the intent is to have short expiry times to encourage people to completely automate the process.
- tomjen3 11y agoUnfortunately that makes it more complicated too, which means fewer people will use it (a classic example of a trivial inconvinience http://lesswrong.com/lw/f1/beware_trivial_inconveniences/ http://lesswrong.com/lw/f1/beware_trivial_inconveniences/).
- nulltype 11y agoHonestly renewing certs is a huge pain and should be automated even in the 1 year case. I usually have forgotten after a year how I obtained and installed the cert last time. The Lets Encrypt flow with DNS is way less complicated than obtaining a cert through many commercial services, so it probably works out about even.
- nitrix 11y agoWhat is the intermediate certificate hardcoded in the source?
- diafygi 11y agoThe Let's Encrypt cross signed intermediate.
- deleted 11y ago[deleted]
- robmclarty 11y agoFor those that are interested, I posted an article[1] a little while ago on how to automate the renewal process for Letsencrypt using Daniel's acme-tiny[2] script. It's a lot nicer to let cron handle it than doing it manually ;) [1] http://robmclarty.com/blog/how-to-secure-your-web-app-using-https-with-letsencrypt http://robmclarty.com/blog/how-to-secure-your-web-app-using-... [2] https://github.com/diafygi/acme-tiny https://github.com/diafygi/acme-tiny
- c0l0 11y agoVery nice, I quite like it! I recently hacked together a completely web-based, client-side CSR generator for PKCS#10; you can take a look at it at https://johannes.truschnigg.info/csr/ https://johannes.truschnigg.info/csr/ With something like that fused into your project, users wouldn't even have to execute `openssl` to generate their key material and CSR, they'd just need a modern browser with support for the W3 Web Cryptography API.
- nailer 11y agoWe also use webcrypto on https://certsimple.com https://certsimple.com If people prefer, we also dynamically generate a full OpenSSL or powershell command,so they can make keypairs on their own server with a single paste - no terminal Q and A. We're awesome, but there's nothing stopping you from using the tools wherever you want. :^)
- AndyKelley 11y agoSadly Let's Encrypt still doesn't work if your ISP blocks port 80 and 443.
- jrochkind1 11y agoI don't get it. If your ISP blocks port 80 and 443 incoming, how would you possibly deploy a website anyway? What do you need an ssl cert for if you can't deploy a website anyway?
- xxpor 11y agoIt's entirely possible to deploy websites on ports other than 80 and 443.
- rakoo 11y ago> What do you need an ssl cert for if you can't deploy a website anyway? SSL certs are used to secure TLS connections, not just websites connections. So you can host a mail server, a mumble server, an XMPP server, or really anything that speaks TLS. Let's encrypt has been explicitely created for websites, but that doesn't mean its certs must be used for websites only.
- AndyKelley 11y agoI run a music server[1] on my home server so I can listen to music anywhere. I serve it on a port other than 80 and 443 since my ISP blocks those ports. If I access the web interface over HTTP, the admin password is sent in clear text, which means someone on the network I connect to could get my password and delete my music, or god forbid, secretly mistag some of it. * [1]: http://groovebasin.com/ http://groovebasin.com/
- ceejayoz 11y agoSince it's for personal use, you can fire up something like an EC2 server, point the domain there for a few minutes, and provision a LE certificate. Copy down the generated key/cert files and you're in good shape for three months.
- oliv__ 11y agoSlightly off topic: I know everyone here is all about naked websites but I couldn't help but add these three lines of CSS to the body: max-width: 630px; margin: 0 auto; padding: 0 15px; Makes the whole thing much more pleasant to read! (And even looks good on mobile) Here's a screenshot: http://imgur.com/UFHJp8a http://imgur.com/UFHJp8a
- sccxy 11y agohttp://bettermotherfuckingwebsite.com http://bettermotherfuckingwebsite.com
- teekert 11y agoI always wondered about this one, you hear it a lot: "A little less contrast Black on white? How often do you see that kind of contrast in real life? Tone it down a bit, asshole. I would've even made this site's background a nice #EEEEEE if I wasn't so focused on keeping declarations to a lean 7 fucking lines." But my monitor is not perfect, nobodies is so why make stuff less well readable, I don't understand it. It annoys me to no end when I have to copy paste stuff into a text editor just to get a white background because someone decide a background should never be white and people seem to agree. If I want less contrast I'll tone down the background lighting of my screen.
- effie 11y agoThere are lots of people who are annoyed to no end that the background of most websites is white and their browser does not offer simple way to change that. Plugins like stylish help to both groups. Just set the background color to what you want in custom css style, cope with the broken graphics and enjoy the web.
- teekert 11y agoSo, when your background is too bright... why not reduce monitor brightness? The letters will stay as black as they are (hey its 2016), your background gets less bright. This has other advantages too. Why must a website creator choose how much (maximum) light my screen emits around the letters?
- rogerbinns 11y agoWhat is the HTTPS/security solution for devices on a home/office LAN? They aren't externally accessible, don't have a globally unique name, but do have access to valuable content (think your router, baby camera, lighting controller, NAS, media device). Having to teach users that you always see the padlock when accessing your valuable information over the Internet, but do not see it when accessing your even more valuable information on the LAN doesn't seem good.
- pfg 11y agoOffice setups: Deploy an internal root CA (possibly with appropriate name constraints, to limit the damage to internal domains if your CA key is compromised). Active Directory makes it relatively easy to do this. Tooling will hopefully get better now that browsers are pretty much set on going HTTPS-only. Some consumer devices could probably implement something similar to what Plex did to deploy TLS [1]. I do agree that the industry isn't where it should be yet, but hopefully everyone's feeling the pressure now. :) [1]: https://blog.filippo.io/how-plex-is-doing-https-for-all-its-users/ https://blog.filippo.io/how-plex-is-doing-https-for-all-its-...
- rogerbinns 11y agoYour office setup only works for the larger ones. And then for Windows machines that are actively managed. It doesn't for example address a BYOD iPhone. The Plex solution looks good. I wonder if lets encrypt could provide a similar solution that works for everyone, rather than products having to reimplement what Plex already did.
- jetskindo 11y agoLet's encrypt looks so cool with its very few steps. But then you install and you get all sorts of errors not me toned on the page. I spent a good 5 hours debugging yesterday. When it finally works I see that the certificate expires in 2 months.
- irons 11y agoFor good reasons: https://letsencrypt.org/2015/11/09/why-90-days.html https://letsencrypt.org/2015/11/09/why-90-days.html
- schoen 11y agoIf you'd be willing to describe the problems you encountered in issues on https://github.com/letsencrypt/letsencrypt/issues https://github.com/letsencrypt/letsencrypt/issues (if they're clearly problems with the client software) or in a forum post at https://community.letsencrypt.org/ https://community.letsencrypt.org/ (if you're not sure), you can help other people have a better experience in the future. Not everyone is having five hours' worth of problems -- many people are getting it to work right immediately -- but there are clearly also people who are running into difficulties which it would be great to figure out how to address.
- satbyy 11y agoI had been using free Startcom SSL certs, but their UI and overall experience was not as great as this simple website. I just generated mine in about 10 minutes. The last I remember was that StartSSL required something to be stored on my local browser, but I reinstalled my browser, so lost some certificate, etc. If was free, but painful. I know I should automate every 3 months, but even when I miss it, I know I can use this website and manually generate a cert in 10 min. Thanks to OP, diafygi and Lets Encrypt !
- rogerbinns 11y agoStartcom insist that you have your own personal certificate first, before they will issue the website certificate. They could have allowed just a username and password, but I guess certificate authorities believe there is no such thing as too many certificates, and don't realise just how inconvenient they are for most people. (It was their personal certificate they issued to you that had to be in the browser.)
- simoncion 11y ago> Startcom insist that you have your own personal certificate first ... [t]hey could have allowed just a username and password... I assume that this was for TLS client authentication. Username+password sucks as a method of authentication. The only thing it has going for it is that you can -theoretically- remember your password and key it in on a machine you've never used before. [0] Client certs are effectively unguessable and typically stored in the most secure place that the OS can provide. What's more, there's -IIRC- absolutely no reason for the remote side to remember anything about the certificate that they issued you after they generate it, so there's no risk of a server-side DB breach revealing any significant information about a client's credentials. Frankly, I wish more sites would eschew username/password authentication for username/cert (or at least offer the option of username/cert). Then the UI for certificate operations would certainly get easier to use. :) [0] Though, in today's environment, it seems... highly unlikely that any non-mutant will be able to remember all of the passwords for all of the sites that they use.
- 11y ago
- nickkenens 11y agoThese are the things we need for the web.
- arihant 11y agoI plead ignorance here. I'm sort of out of touch with recent developments, with typically just buying a cert when I need it. So I have a question -- where will Let's Encrypt certificates not work? I see Mozilla and Chrome as sponsors, so I'm guessing it's added as authority in at least those browsers? This would be great, apart from apparent insurance regular certificates bring, which I still don't know how to claim.
- ceejayoz 11y ago> So I have a question -- where will Let's Encrypt certificates not work? They're very well supported. Won't work in Windows XP and Android versions lower than 2.3.6. https://community.letsencrypt.org/t/which-browsers-and-operating-systems-support-lets-encrypt/4394 https://community.letsencrypt.org/t/which-browsers-and-opera... > This would be great, apart from apparent insurance regular certificates bring, which I still don't know how to claim. To my knowledge, that insurance has never been paid out, from any SSL vendor. It's a marketing gimmick.
- src 11y agoFree is great. My only issue with LetsEncrypt is that the certificates are only valid for 3 months. It's a hassle to keep updating the certs... I just switched to AWS Cert Manager last month from StartSSL, which is free if you're an AWS customer.
- ymse 11y ago3 months expiry time was a deliberate choice to force users to automate the process. Ideally you would have a central store with a letsencrypt client, and all your actual web servers periodically fetch their certs from there.
- src 11y agoThat's great except the web server (except apache/nginx) needs to be restarted to load new certs, which isn't ideal for production. Many cloud hosting providers don't have an automated way to update certs, which makes it more tedious.
- pfg 11y agoBoth apache and nginx support graceful reloads which will reload the certificates without any downtime.
- ausjke 11y agoThis is awesome, just replaced my self-signed ssl with it. Great Thanks!! so the cert will expire in 90 days, how to deal with that? come to the same site every 3 months and regenerate a new SSL cert? Why not at least valid for a year?
- desireco42 11y agoIf you find out, I would like to know as well.
- mappu 11y agoLet's Encrypt is designed to encourage setting up an automated renewal system. If you follow the links, you won't have to renew within 90 days - or ever again.
- Tushon 11y agoOne of their goals is to not have people use this interface and instead automate the workflow completely (using a client and your own renewal script[0], full docs [1]). There are reasons for this, laid out here[2]. [0]:https://letsencrypt.org/howitworks/ https://letsencrypt.org/howitworks/ [1]:https://letsencrypt.readthedocs.org/en/latest/intro.html https://letsencrypt.readthedocs.org/en/latest/intro.html [2]:https://community.letsencrypt.org/t/pros-and-cons-of-90-day-certificate-lifetimes/4621 https://community.letsencrypt.org/t/pros-and-cons-of-90-day-...
- spiffytech 11y agoThis is a manual version of what's meant to be an automated process. I believe the idea is that certificate revocation is a big mess right now, with Chrome not using the main revocation registry, and other browsers not being great at checking / enforcing revocations. So the EFF decided that since automated certificate regeneration makes how often a cert expires irrelevant, they should use short-lived certificates so compromised certs can only be used maliciously for a short window, regardless of how well any given browser honors revocation registries. I can't speak to whether this manual version of Let's Encrypt has flexibility in choosing certificate lifespans.
- blandes 11y agoOr we could Amazon Web Services for their wildcard certificates?
- blandes 11y agoOr you could use Amazon Web Services for their certificate manager? They offer wild card certificates for free?
- danielhlockard 11y agoYou double posted, but FYI you can't export certs from AWS cert manager
- cornholio 11y agoSince it's free, could this be included into the installation or configuration scripts of major packages that provide web services ? As long as I have the DNS set up, it would be great if I can run "dpkg-reconfigure exim4-config" and have working STARTTLS with real certificates.
- mixnovich 11y agoThank you. If ever we meet. I will buy you a Westvleteren