3 ms·
The cost of the certificate is a very small part of the overall cost of a proper SSL/TLS implementation. If you don't want to exclude older browsers, you need
by DanielDent 11y ago
The cost of the certificate is a very small part of the overall cost of a proper SSL/TLS implementation.
If you don't want to exclude older browsers, you need a dedicated IP address, or you need a system to manage putting multiple names on one certificate. Let's Encrypt is a great option for multi-SAN certificates, as long as you don't care about Windows XP users.
If you have any kind of redundancy, doing perfect forward secrecy gets much harder. The open source approaches to scaling TLS along with PFS are bleeding edge, poorly documented, and may involve writing some code.
I agree, TLS everywhere is a worthy goal. But I think it's easy to underestimate how complicated it can get, especially at scale.
- deleted 11y ago[deleted]
- tshtf 11y ago> If you don't want to exclude older browsers, you need a dedicated IP address, or you need a system to manage putting multiple names on one certificate. Let's Encrypt is a great option for multi-SAN certificates, as long as you don't care about Windows XP users. This is a website for AppImage. I doubt they're targeting XP users. > If you have any kind of redundancy, doing perfect forward secrecy gets much harder. The open source approaches to scaling TLS along with PFS are bleeding edge, poorly documented, and may involve writing some code. This is simply a brochure website, so this does not apply. For more complex applications or websites, there is a certain degree of engineering required to support HTTPS-by-default. But in today's world it is a necessity.
- michaelmrose 11y agoWindows XP users ought to be shown a fullscreen banner ad warning them to upgrade.