8 ms·
How We Deliver Global SSL with Let's Encrypt
- tialaramex 9y agoWould greatly benefit from explaining why they couldn't do dns-01 challenges successfully. This an issue all the way from individuals with crappy or misconfigured DNS locally to whole TLDs (fortunately no really major ones) with non-working DNS. But it's often a teachable moment, something others can learn from.
- thaumaturgy 9y agoI'd like to see that too, especially since I've been doing fully-automated Let's Encrypt with dns verification for hosted domains for well over a year now. I might be able to offer a solution to whatever issue they've had.
- cagenut 9y agowould you consider writing up your system somewhere?
- mrkurt 9y agoDNS challenges weren't broken, they technically worked just fine. But they added an additional step to our setup process, and we were losing customers during signup because of it. We can still do the DNS challenge it's just not how we guide people through our setup. Basically with the DNS challenge, we had to send people away to make DNS changes, have them come back and confirm they were approved, and then we sent them away _again_ to make another DNS change. It was kind of brutal. (edit: we also tweaked the article to not imply "broken"!)
- infogulch 9y agoSo typical user engagement/onboarding complexity funnel issues not something inherent to the DNS/LE/Fly.
- zAy0LfpBZLC8mAC 9y agoWhy would you need to send them away twice for DNS changes?!
- matahwoosh 9y agoI'm assuming mrkurt meant that you send your users once to create a dns record (in case you haven't already) - you can add any hostname you want on Fly, it doesn't have to exist, yet. Then you go and create a DNS challenge for Let's Encrypt. Obviously, these 2 steps are orthogonal, but this is the reality of user onboarding.
- zAy0LfpBZLC8mAC 9y agoBut why would that need to be in two steps?
- mrkurt 9y agoWell, it's two DNS entries. You could do them both at the same time, but people were getting that TXT record wrong pretty frequently, which would have meant https connections getting an invalid certificate had they changed their actual hostname at the same time. Since we control the http response once DNS changes, we don't have that problem. And it's simpler for people to create CNAME/ALIAS records.
- zAy0LfpBZLC8mAC 9y agoErm ... you had people create TXT records? Why would you do that? Wouldn't people then have to manually update the TXT record on each certificate renew?! Why not have them create a DNAME, a delegation, or just two CNAMEs?
- mrkurt 9y agotxt records are the only way to do the dns-01 challenge with certbot/Let's Encrypt. The http-01 challenge is simpler, we can get people setup with one CNAME/A-record. Once we're serving traffic, we can do all renewals with an http challenge and they don't need to change DNS ever again.
- cm2187 9y agoAlso my experience with DNS validation and let's encrypt is that propagation times can be variable. You do not know from where in the world the let's encrypt servers will contact your DNS, so you may see the new entries in your DNS, but it may not have been propagated yet to where let's encrypt query them. And then the validation failed and you need to start again from scratch. So you need to introduce some large delays to be safe. Having DNS validation as an option is very useful, as not all certificates are used for http servers (think smtp) but not trivial to implement. Also wildcard certs will require DNS validation.
- k__ 9y agoLE is awesome. Clients want an SSL server and it lets me set it up in 10 minutes without additional costs.
- stevenwoo 9y agoYes this is a delight compared to the old way of having to hand over $10 or whatever to someone for a certificate that one had to remember to renew in a timely fashion versus just using a cron job now with LE.
- mrkurt 9y agoRight?! "Sure I won't think about this for a year, then I'll remember it 30 days before I need to have it fixed, it'll be great".
- apple4ever 9y agoOr "I won't have to think about this for three years, and everything will keep working during that time, and I don't have to worry about a cron job failing" I don't mind offering 90 day certificates, but requiring it goes against the offered reason of LE to expand HTTPS.
- mschuster91 9y agoWhy use a cron job? I have certbot running in one Docker container, the .well-known route directing to the one dedicated Docker host running certbot, and whenever certbot renews the certificate, it writes the cert to the NAS share that is only mounted on the LBs and then triggers a SIGKILL to the haproxy docker containers (which causes haproxy to re-read the cert file and configuration). Fully automated, no cronjobs to fail. In addition, I have a monitoring on all LBs that verifies the expiration time - it has never hit so far. That cronjob/monitoring is something everyone should have anyway because a well working monitoring system can alert you to so many other possible failure states...
- toomuchtodo 9y ago
- geetfun 9y agoInteresting product - fly.io It’s essentially a reverse proxy as a service. Sort of like Cloudflare but with what looks like a nicer API, and custom domain name SSL eg. for multi tenant apps. It was a bit pricy when I plugged in how many requests we get per month on our servers, easily in 5-figure per month. Having said that, internally we built most of their selling points already.
- adrinavarro 9y agoI agree with the pricy bit. I've made a calculation, and it would cost me 1200$ a month to run what Cloudflare does for free. Now, I get that free is not an option. 50/100$ a month is probably OK. But that's beyond reasonable. And prices change depending on where people visit you from (!?)
- mrkurt 9y agoI'm not sure what kind of app you're running, but our product/pricing are targeted almost entirely at SaaS apps that need multiple hostnames — which is $2500/mo min on CF: https://fly.io/mix/custom-hostnames https://fly.io/mix/custom-hostnames It's really expensive to do that on top of CloudFlare, and most apps like that aren't using a tremendous amount of bandwidth. We're not _yet_ a great option as a general purpose CDN replacement (both pricing and featureset) but we're getting there, and are pushing prices down continuously. It's more expensive to buy bandwidth and power in certain cities, too, hence the different pricing per region. If you're willing, I'd love to know what your traffic breakdown is and how you got to that $1200/mo number. You can email me if you'd like! (kurt.mackey@fly.io)
- geetfun 9y agoAgree it is not a trivial task to build out the infrastructure for custom SSL. We’ve done it ourselves and it’s just now another service component we have to manage. ie. more time sink for something that isn’t our business core feature For others who are reading this, the whole process involves reading and storing private keys using asymmetric ciphers and all that. Definitely more stuff than we’d like to be responsible for. Will definitely keep an eye on fly.io for new features! Thanks
- hw 9y agoClearalias.com is another service that provides SSL multi-tenant apps and SaaSes that want to provide secured custom domains for their customers. There's only one step required by the customer which is to point their DNS to Clearalias, no API calls or extra set up by the app or the customers.
- matahwoosh 9y agoOhai! Yeah, you can do the same thing with Fly (which is what most of our customers do - just point DNS at Fly). I cannot stress enough how nice it is being able to build on top of Let's Encrypt! bows The API is mainly for people who'd like to automate the process, because they want to provide custom domains for their customers (so more for B2B use-cases) ;)
- eo3x0 9y agoThe grandparent post means that the customer hostnsmes also work without any API calls if configured properly.
- nodesocket 9y agoSorry a little off topic, but any idea when Let's Encrypt will (if ever) support wildcard SSL certs? We provision (https://commando.io https://commando.io) a subdomain for each of our accounts (thus thousands of subdomains) using a wildcard DNS A record. Willing to pay, as long as it is less than the $99 a year currently paying through NameCheap.
- matahwoosh 9y agoLE still says Jan '18 - https://letsencrypt.org/upcoming-features/ https://letsencrypt.org/upcoming-features/
- matahwoosh 9y agofor the time being, you could try to issue SAN certs with LE (from their website): "If you have a lot of subdomains, you may want to combine them into a single certificate, up to a limit of 100 Names per Certificate. Combined with the above limit, that means you can issue certificates containing up to 2,000 unique subdomains per week."
- deleted 9y ago[deleted]
- mrkurt 9y agoWe can handle wildcards now, we just issue new certs when we see new subdomains (we have a 2500/wk rate limit from LE and will implement SANs if you need them). Feel free to email I'd you want to set it up. :)
- nodejscloud 9y agoInteresting, and you support DNS A record wildcard? Currently have around 6,300 subdomains.
- matahwoosh 9y ago
- moulidorai 9y agoOn a side-note, ManageEngine Key Manager Plus can automate certificate management (request, acquire, deploy, track and renew) for public facing websites. Video link: https://www.youtube.com/watch?v=oYelZided-E https://www.youtube.com/watch?v=oYelZided-E https://www.manageengine.com/key-manager/ https://www.manageengine.com/key-manager/ Disclaimer: *I work for ManageEngine
- thiagocsf 9y agoIt’s a x.509 certificate, not ssl. Also, the ssl protocol has been deprecated in favour of tls. I’ll let tls certificate slide but ssl certificate just triggers me too much.
- vog 9y agoWhat's the point of this nitpicking? The title is perfectly fine for its purpose. First, thanks to the terminology used by almost all commercial CAs, "SSL Certificates" is still the most commonly known term for that. Like it or not, but if you want to reach a wide audience, you need to say SSL in addition to TLS. Second, even fewer people know the term X.509, insisting on that is like insisting on saying RFC-7540 instead of HTTP/2. Third, in the very first sentence the article sets everything straight: > We've been hard at work making Let's Encrypt TLS certificates as simple and safe as possible for developers and creators of all kinds So ... is this an instance of commenting before actually having had just a tiny look at the article?
- parasubvert 9y agoBecause it is important that everyone understand that SSL is dead and TLS is the replacement. SSL/TLS is forgivable, saying SSL is sort of like writing a headline “How this company uses VHS” when you actually meant Betamax. It’s misleading.
- anubhavmishra 9y agoCompletely unrelated, what is the blog framework / cms you are using the the fly.io blog? It is amazing!
- matahwoosh 9y agoThanks! We're using ghost.org and of course all our illustrations are done by Annie (https://twitter.com/annieruygt https://twitter.com/annieruygt) :)
- matahwoosh 9y agoOh, and we use the basic Ghost theme, Casper, with some design tweaks.
- anubhavmishra 9y agoThanks for the insight! Really appreciate it!