4 ms·
It may take way more than 5 minutes. My experience with let's encrypt so far: - the name of their tool was changed form "letsencrypt" to "certbot", breaking m
by barnacs 10y ago
It may take way more than 5 minutes.
My experience with let's encrypt so far:
- the name of their tool was changed form "letsencrypt" to "certbot", breaking my cronjob
- for daemons that try to access the cert/key as non-privileged users, additional fiddling with permissions is necessary, which may even be overwritten on cert update if done incorrectly
- when the certs are renewed, daemons need to reload them. This means that ideally, you need to detect when a renewal actually happens (as opposed to an attempt), keep an up-to-date list of all daemons that use the certs and possibly completely restart them, dropping all existing connections (some daemons just don't support a live reload)
I'm not saying these problems are unsolvable, but may take way more than 5 minutes and I, for one, opted to renew my startcom certificate for another 3 years instead.
- stanleydrew 10y ago> I, for one, opted to renew my startcom certificate for another 3 years instead. Wait really? When did you do this? I thought all certs signed by their root after sometime in October or November are all considered invalid due to their shenanigans with WoSign. Not so? https://news.ycombinator.com/item?id=12787029 https://news.ycombinator.com/item?id=12787029
- barnacs 10y ago10/18/2016 > Distrust certificates with a notBefore date after October 21, 2016 Just in time!
- nkkollaw 10y agoI just followed the instructions on their website, and it took me less than 5 minutes, including setting up the cronjob. The cronjob correctly renewed the certificate at least once on multiple servers, with no issues whatsoever. I was also warned that the certificates were expiring via email, which I thought was awesome. Your mileage might vary.