4 ms·
Unless I'm misunderstanding they did that by partnering with a CA. Becoming a semi-trusted CA themselves. This is not an option for most organizations.
by tokenizerrr 9y ago
Unless I'm misunderstanding they did that by partnering with a CA. Becoming a semi-trusted CA themselves. This is not an option for most organizations.
- Ajedi32 9y agoThat was only necessary because, at the time, there was no other way to get a large number of wildcard certs issued for their domain in an automated fashion. With ACME that will no longer be the case. Let's Encrypt will allow you to do basically the same thing for free with ~20 devices a week[1] starting on February 27[2], for example. In the future, commercial CAs may choose to offer similar services with more relaxed rate limits. [1]: https://letsencrypt.org/docs/rate-limits/ https://letsencrypt.org/docs/rate-limits/ [2]: https://letsencrypt.org/2017/07/06/wildcard-certificates-coming-jan-2018.html https://letsencrypt.org/2017/07/06/wildcard-certificates-com...
- tokenizerrr 9y agoYeah, would be nice if ACME with DNS validation was widespread. But right now it's still not viable due to Let's Encrypt's rate limits.
- pfg 9y agoIt's fairly trivial to request a rate limit adjustment from Let's Encrypt[1]. [1]: https://docs.google.com/forms/d/e/1FAIpQLSetFLqcyPrnnrom2Kw802ZjukDVex67dOM2g4O8jEbfWFs3dA/viewform https://docs.google.com/forms/d/e/1FAIpQLSetFLqcyPrnnrom2Kw8...
- deleted 9y ago[deleted]