3 ms·
The Let's Encrypt certificates seem to expire after 90 days. I wrote up some example code in Go so you can automate the process of issuing these certs here: ht
by nulltype 11y ago
The Let's Encrypt certificates seem to expire after 90 days. I wrote up some example code in Go so you can automate the process of issuing these certs here: http://goroutines.com/ssl http://goroutines.com/ssl
It does not require CSRs, but uses your DNS provider to complete the challenge. You do not need to run anything on your production servers.
- imron 11y agoYes, the intent is to have short expiry times to encourage people to completely automate the process.
- tomjen3 11y agoUnfortunately that makes it more complicated too, which means fewer people will use it (a classic example of a trivial inconvinience http://lesswrong.com/lw/f1/beware_trivial_inconveniences/ http://lesswrong.com/lw/f1/beware_trivial_inconveniences/).
- nulltype 11y agoHonestly renewing certs is a huge pain and should be automated even in the 1 year case. I usually have forgotten after a year how I obtained and installed the cert last time. The Lets Encrypt flow with DNS is way less complicated than obtaining a cert through many commercial services, so it probably works out about even.