3 ms·
Zendesk, for example, has a Let's Encrypt-based system for all those <account>.zendesk.com pages. While it wouldn't be trivial to set it up, it is free and the
by Tushon 10y ago
Zendesk, for example, has a Let's Encrypt-based system for all those <account>.zendesk.com pages. While it wouldn't be trivial to set it up, it is free and the information is out there if the admins of those sites want to make it possible.
- kuschku 10y agoNot everyone can get whitelisted from the domain creation limits of LE.
- Ajedi32 10y agoUnless you're creating [more than 20 new subdomains a week][1], you're not gonna hit that limit anyway. You can increase that figure to around 2,000 new subdomains a week if you're willing to include multiple subdomains per certificate; that should be more than enough for all but the largest of sites. And even if you do need more: > If you are a large hosting provider or organization working on a Let’s Encrypt integration, we have a rate limiting form that can be used to request a higher rate limit. [1]: https://letsencrypt.org/docs/rate-limits/ https://letsencrypt.org/docs/rate-limits/
- kuschku 10y agoIf you want to have a signup process that takes less than 9 hours, you have a max of 20 new subdomains a week. 20 users signing up a week - likely with a retention of a few percent - is not a "large hosting provider". You might have a few hundred users max, and already will be far over the rate limits.
- Ajedi32 10y agoJust start them off with HTTP and transparently upgrade to HTTPS after 9 hours. And if you're only retaining a small percentage of users who sign up, you can stretch that limit even further by only upgrading the users who you retain.
- Sephr 10y agoThis isn't possible in a properly deployed HTTPS site, since it would already have an HSTS header with includeSubdomains.