6 ms·
I don't get it. With Lets Encrypt, it's like one or two lines to get everything set up. I'm guessing people aren't as lucky as I am to be running on newer mach
by veb 7y ago
I don't get it. With Lets Encrypt, it's like one or two lines to get everything set up.
I'm guessing people aren't as lucky as I am to be running on newer machines and such.
I mean it even edits your nginx files to redirect http to https if you agree. It's not hard.
- onion-soup 7y agoNope, it is not straight-forward and still a confusing process.
- chungy 7y agoInstructions are here: https://certbot.eff.org/ https://certbot.eff.org/ I don't know how it could possibly be any simpler.
- onion-soup 7y agoWhile I appreciate the efforts of certbot to make it as user-friendly as possible I still find this state of things unforgivable. I don't know where it went wrong so that today a developer must spend time learning and tweaking a low-level encryption tools. I'm just saying https will never be 100% unless it becomes a baked-in feature of any hosting.
- cm2187 7y agoStarting with baking ACMEv2 in the major webservers (apache, IIS, etc).
- deleted 7y ago[deleted]
- Jaruzel 7y agoIf Microsoft baked in Auto-cert-install in to IIS that allowed you to cherry pick a provider, and/or just select their own free CA, that'd really solve the problem for Windows based web servers. In my experience CertBot/ACME type renewal doesn't work reliably for Windows/IIS.
- regecks 7y agoCertbot, and most other standalone ACME clients, are just stop-gaps. The end game is first-party support for automatic HTTPS in all web (and other) servers. It is happening (e.g. mod_md), it's just going to take time. For example, to get it packaged for all distributions. For shared hosting, if you ignore the few providers at the top who are either CAs (e.g. GoDaddy) or are in contracts with CAs (e.g. Namecheap), the overwhelming majority of them are already providing free and automatic SSL for all hosted domains.
- majewsky 7y ago> The end game is first-party support for automatic HTTPS in all web (and other) servers. There's still a need for certbot et al when you have multiple services (e.g. web and mail and XMPP) running on a single domain name. In fact, I actively avoid servers that insist on doing ACME themselves because it breaks my unified ACME process.
- jbverschoor 7y agoIt’s for ops. Not dev
- thenewnewguy 7y agoDevelopers don't need to, unless they're the ones hosting your website. In which case, yes, I expect them to be able to configure web hosting software.
- hrktb 7y agoThis is sadly not the case yet in many not so edge cases. For instance Heroku still doesn't provide straightforward support for wildcard domains under SSL: https://devcenter.heroku.com/articles/understanding-ssl-on-heroku https://devcenter.heroku.com/articles/understanding-ssl-on-h... There is myriad of other cases, basically every time you diverge a bit from the 80% path, you're in for a treat and will deal with all the intricacies of SSL management.
- AnIdiotOnTheNet 7y agoWhat is the value in HTTPS being 100%? That seems silly to me. Many many things do not have any need for encryption.
- tialaramex 7y agoMost things would benefit from encryption. Even if you don't need integrity protection, and you don't have any need of privacy, and you don't care about authenticating your peers you still want encryption because otherwise middleboxes ossify everything. If the middlebox can't see inside your flow because it's encrypted it can't object to whatever new thing it's scared of this time whether that's HD video or a new HTML tag.
- AnIdiotOnTheNet 7y agoNot a significant issue in practice as far as I can tell. I deliver text over the internet, and sometimes binaries over the internet, and it happens very fast because there is no useless cruft in the process to satisfy some security twonk's paranoid delusions.
- kbr2000 7y agoA management fad called dev-ops is what went wrong, before you could count on your sysadmin to take care of that :) Apart from that, not everything always makes sense to use in production without a good level of understanding --- and might otherwise lead to, for example, a false sense of security.
- elcomet 7y agoIt is simple for a one-server website. When you're on Alexa 1M, you certainly have a load balancer, multiple servers for redundancy, etc. It makes things not straightforward, and you certainly don't want to use the default certbot which overwrites your config.
- MrStonedOne 7y agoI am on alexa 1m (50k even). I do not have a load balancer, I do not have multiple servers for redundancy. This isn't even a static site, most of our page views are the wiki, the server running all of this has 8 cores and 4 are constantly maxxed out by a non-website related process. Most websites now and days are over engineered.
- uasm 7y ago> "I am on alexa 1m (50k even). I do not have a load balancer, I do not have multiple servers for redundancy. This isn't even a static site, most of our page views are the wiki, the server running all of this has 8 cores and 4 are constantly maxxed out by a non-website related process. Most websites now and days are over engineered." That's awesome! Mind sharing some more details? (hosting plan/CDN/etc). Or even the URL?
- MrStonedOne 7y agoRented dedicated server running a 9900k. Windows hypervisor runs vms. database vm, website vm, and 3 game server vms running on this machine. each game server vm is running 2 instances of the game server, but only 1 ever has high pop. https://tgstation13.org https://tgstation13.org Most of our traffic goes to our wiki: we are the most active open source video game on github. Most ss13 servers run their own codebase, forked from ours, but will still frequently point their players to our wiki rather then set one up on their own. A Cloudflare caching layer was added back in march when we got a 4x spike in web traffic from a youtuber talking about the game.
- owl57 7y agoChecked my old site's rank. ~250000. One VPS, €4/month. Mostly static, but a decent part is served with a not so light Perl CGI script (!). I'm sure I wouldn't get away with that in top 1k websites, but 1m?
- contravariant 7y agoI'd appreciate it if the instructions explained why they need sudo, rather than explain what sudo is...
- maple3142 7y agoMaybe not everyone host website on a platform where you can easily install these things. For example, I have a simple web app hosted on Heroku free plan, and I have to use CloudFlare SSL to get it served over https on my custom domain. But it actually is half encrypted as the connection between CloudFlare and Heroku is plain http.
- ridiculous_fish 7y agoRight. Another example is that you cannot use https with subdomains on GitHub Pages. https://github.community/t5/GitHub-Pages/Does-GitHub-Pages-Support-HTTPS-for-www-and-subdomains/m-p/7202#M495 https://github.community/t5/GitHub-Pages/Does-GitHub-Pages-S...
- arkitaip 7y agoSo true. Even on hosting that fully supports let's encrypt thru an web based admin like cpanel or directadmin, the process can be confusing and error prone.
- EnderMB 7y agoIf we're purely talking about Let's Encrypt, it's not straightforward to set up on Azure either. It's easy to set up a standard cert through Azure, but if you want to use Let's Encrypt there's a whole dance you have to go through to get there, and for many people it's not worth the time and they'll happily pay a bit of money to make it a few-clicks thing.
- thrower123 7y agoWhen I looked at doing it, I'd have to bump up my hosting plan for my vanity blog to somewhere in the neighborhood of $100/month to apply an SSL cert for my custom domain, which is just stupid for a site that gets a couple thousand visits a month and maybe earns me $5 in referral fees.
- mattferderer 7y agoI believe it's free now - https://docs.microsoft.com/en-us/azure/app-service/configure-ssl-certificate#create-a-free-certificate-preview https://docs.microsoft.com/en-us/azure/app-service/configure... Though hopefully they simplify it for cases such as yours. Putting Cloudflare in front is also another cheap option.
- thrower123 7y agoIt looks like you have to go up to at least a B1 app service, which at $50/month doesn't make a lot of sense for me, unless I can figure how to get my MSDN credits associated with that Azure subscription instead of one of the other two accounts I don't use, but that's a whole other can of worms...
- jwr 7y agoIt is relatively straightforward if you have a single site hosted on a well-supported operating system and web server. It suddenly becomes really, really complicated if you have multiple servers, multiple domains, nginx configurations that the tool does not expect (but insists on rewriting).
- dx034 7y agoThe rewrite is optional, it's also fairly trivial to let certbot create certificates and adapt nginx afterwards.
- squiggleblaz 7y agoYes, but at that point it's not two lines with let's encrypt any more. For my part, I had to write around a thousand lines of script and alter various existing code in order to switch from manual ssl (whenever the client paid for it) to automatic ssl (everywhere), because there was no way I was going to manually buy hundreds of certificates a year when I took over this role. Nowadays we're 100% ssl but it was harder for an existing person already accustomed to the existing system than doing nothing. I'm just too lazy to check a site every week and renew many certificates manually and copy around stupid files and generally go crazy. Plus, if it's automated, I think there's less chance of the keys being copied. So in my mind it was worth the effort, but it was surely effort.
- WilliamEdward 7y agoI'm fine with people who think it's too hard... What i cannot stand is people who can do it, but refuse to out of laziness. Or because they want their content to be insecure on purpose. This applies mostly to big orgs, so indie devs can have some leeway if it's too hard to implement.
- squiggleblaz 7y agoI don't do it on my own site. I'm capable of doing it, and certainly did it for my job. But my own site... It's free with HTTP, but they charge for every level that includes HTTPS. I'm it's major user (so far) so \/\/
- onion-soup 7y agoAssuming you are talking about software developers, you can't expent people do extra work out of virtue. They will do it only if there is an economic incentive. Setting up a transport layer security is not in software developer's interest or competence.
- WilliamEdward 7y agoThis is about managers and executives who call the shots on implementing these features. It is not your responsibility as a software dev working for a big company to implement something they do not pay you for.
- saagarjha 7y agoI’m curious what your opinion is on people who don’t to make a point.
- WilliamEdward 7y agoI mean, if you don't value your users privacy of course i'm not going to think you're a very swell person. Again this really only applies to people in a comfortable position to do this and choose not to. The average developer is not my target here, it's the big guys.
- 7y ago
- rocqua 7y agoI started using lets-encrypt before it supported Nginx (using standalone mode). I recently tried the Nginx-based mode, and it wrecked my reverse proxy config pretty thoroughly. Still, the stand-alone mode is pretty dang easy. I've also considered the /.well-known mode but there was some tiny snag.
- M2Ys4U 7y ago> I don't get it. With Lets Encrypt, it's like one or two lines to get everything set up. My employer won't use Let's Encrypt because they (LE) want unlimited indemnity and that's a deal breaker for them (employer).
- blowski 7y agoTo add to your point, a lot of insurers only provide cyber insurance with a certificate from a specific range of CAs, and LetsEncrypt is not one of them. Frustratingly, Symantec is allowed.
- rkagerer 7y agoI set up Let's Encrypt for an older Exchange server a while ago. While I love the result, it was NOT a simple, one-line exercise. Up to date documentation was near-impossible to find, and the scripts that came out of the box on the recommended client needed some fixing. The whole thing took about half a day, plus some hours a few weeks later once the unforgiving anti-abuse thresholds I accidentally triggered during end-to-end testing finally expired. Definitely wasn't a pleasant experience.
- strenholme 7y agoDepends on your setup. I currently use a mini CDN (content delivery network) of three different OpenVZ servers in the cloud to host my content, so getting things to work with Let’s Encrypt took about two or three days of writing Bash and Ansible scripts which get the challenge-response from Let’s Encrypt, uploading it to all my cloud nodes, having Let’s Encrypt verify it got a good response, uploading the new cert to all of the cloud nodes, then using Ansible to log in to all the nodes, put the new cert where the web server can see it, then restarting the web server. Point being, the amount of effort needed to get things to work with Let’s Encrypt varies, and can be non-trivial.