5 ms·
Author here - I plan on switching to Let’s Encrypt once they support ECC certificates.
by perlgod 9y ago
Author here - I plan on switching to Let’s Encrypt once they support ECC certificates.
- zuck9 9y agoWhy do you need ECC certificates?
- perlgod 9y agoI don't need them, I just prefer them. They are arguably more secure and require much lower CPU usage.
- c0l0 9y agoAny reasonably modern x86_64 CPU can do more than 1000 RSA2048 signs (~ TLS handshakes) a second, per core. Performance considerations really aren't a good reason to not use RSA for TLS KEX.
- nirv 9y agoWhile I share your ECC preference, for today I see no reason to refuse free, reasonably secure LE support by default. ECDSA signing with LE's RSA intermediates is supported from Feb 2016, and full ECDSA cert chain will be added on July 2018[1]. [1] https://letsencrypt.org/upcoming-features/ https://letsencrypt.org/upcoming-features/
- wtetzner 9y agoI think they do support ECC certificates: https://cromwell-intl.com/open-source/google-freebsd-tls/tls-certificate.html https://cromwell-intl.com/open-source/google-freebsd-tls/tls...