5 ms·
There are still a few other reasons of using non-LE certs: extended validation TLS certs (the ones with greenbar + company/entity name), SAN TLS certs, etc.
by devy 9y ago
There are still a few other reasons of using non-LE certs: extended validation TLS certs (the ones with greenbar + company/entity name), SAN TLS certs, etc.
- pfg 9y agoLet's Encrypt has supported SAN certificates with up to 100 hostnames ever since they launched.
- devy 9y agoYou are right on the SAN cert, my bad.
- byuu 9y agoFor me the last big one is longer-lasting certificates. I'd like a three-year cert like letsencrypt.org uses for their site, instead of the 90-day ones they offer. I much prefer the CA industry practice of, put a meta tag on your frontpage, or add a string to a DNS TXT record, and then download a certificate, then you're done for three years. I understand their security claims (which apparently don't apply to letsencrypt.org), but all CAs offer 2-3 year certs, so it's a feature they have that LE lacks. certbot raises complexities if you're using a managed hosting solution that doesn't have shell access, or the owner of your machine doesn't want you running code on their box, or you have a weird custom web server setup or something. But all the same, I'm not sure that avoiding certbot is worth continuing to pay $40 a year for my wildcard certificate from AlphaSSL. I may switch when mine expires. What I'm even more hopeful for is that prices of wildcard certs from other vendors will drop now that there's a free alternative. I'm super excited that LE are finally offering these for free!
- devy 9y agoI agree that free LE certs disrupt the TLS certificate market pricing and a lot of CAs are probably going to be out of business for that matter.
- snakeanus 9y agoAnd this is a great thing.
- ivanr 9y agoActually, it's not necessarily a great thing. Issuing certificates cost money and has to be paid one way or another. Having one very dominant CA -- even if it's free -- is not healthy long term. We need competition in this space.
- DaiPlusPlus 9y agoThe cost of issuing domain-validated certificates is negligible - there's no reason they couldn't be done for free and paid through advertising or other long-tail revenue sources (or in LetsEncrypt's case: donations and endowment).
- snakeanus 9y agoI believe that it would be better if all CAs disappeared and a new system such as public-keys-as-urls/hashes-as-urls (like tor/i2p/gnunet/etc) or a web-of-trust based solution was adopted. > Issuing certificates cost money Making a post on HN probably costs more money than issuing certificates.
- Karunamon 9y agoEven if you're not using a proper PKI, you still have to trust someone at the end of the day to not be lying to you. That's ostensibly the point behind CAs and auditing and trust roots. LE's probably the best we're going to get for a long time. Mozilla's one of the few groups I'd go so far as to say is completely benevolent, and LE is being operated as a public service.
- Kadin 9y ago> Issuing certificates cost money and has to be paid one way or another. It's not clear that the prices being charged by commercial CAs are anywhere close or even related to the underlying costs. I think LE is beginning to demonstrate that the costs of operating a CA are not actually that high, at the same time that the lax behavior by certain commercial CAs has demonstrated that the "validation" they provide is of very little value.
- kiallmacinnes 9y agoI assume letsencrypt don't use their own certs to avoid a chicken and egg problem if there's ever an issue. e.g. a software as a service database provider most likely does not use their own software for their database.
- snakeanus 9y agoIf you want to avoid certbot you can just self-sign.
- JoshTriplett 9y agoI don't recommend using certbot directly; I use and recommend acme-tiny (https://github.com/diafygi/acme-tiny https://github.com/diafygi/acme-tiny), which is quite simple, and doesn't require as many permissions. I keep it isolated under its own user, run it to renew a certificate, and don't give it access to my TLS private key (just my LE account key and a directory mapped to .well-known/acme-challenge in my web server). If you have a host that doesn't have shell access, it wouldn't be that hard to modify a script like that to copy files up to .well-known/acme-challenge, and copy the TLS key in place when done.
- imron 9y ago> I'd like a three-year cert like letsencrypt.org uses for their site, instead of the 90-day ones they offer. Why? The whole point of LE is to be able to automate renewals and if you automate it then the length of validity makes zero difference.
- qwerty666 9y agoWhy would anyone install what is basically alpha quality software on their server and allow access to critical functions? That is world-class malpractice.
- CJefferson 9y agoThen why doesn't letsencrypt.org eat their own dogfood, rather than have a 3 year certificate?
- imron 9y agoAt a guess, I'd say the reason is because Let's Encrypt (the service) didn't exist when they got their certificate. From Wikipedia: > Let's Encrypt is a certificate authority that launched on April 12, 2016 From Let's Encrypt's certificate > Period of Validity > Begins On: 2015/2/4 I agree they should eat their own dogfood, but in the meantime, I'm eating their dogfood and it tastes pretty good.
- deleted 9y ago[deleted]
- AnssiH 9y agoJust in case you are not aware, Let's Encrypt does support the DNS TXT method as well. I use the acme.sh client (https://github.com/Neilpang/acme.sh https://github.com/Neilpang/acme.sh) for updating certs for a site on a managed platform, using the DNS verification method.
- sandGorgon 9y ago+1 on this. An until nginx gets LE baked into it, building docker images is kind of tricky since there is a circular dependency. I'm actually willing to pay letsencrypt 60$ for a wildcard 3 year certificate.
- XorNot 9y agoThere is a Lua module which will do LetsEncrypt automatically for any domain in an nginx instance.
- pixl97 9y ago>For me the last big one is longer-lasting certificates. I'd like a three-year cert like Long term I would be concerned that browsers, such as Chrome, may stop supporting certs that last too long. We are already seeing this behavior with Symantec after some security issues with issuing certs. I expect in the long run certs that last over a year will be done away with.