3 ms·
I am equally perplexed. > This is about me finding a supposed alternative and going through the same process of due diligence to understand just what I'd be ge
by nulbyte 4y ago
I am equally perplexed.
> This is about me finding a supposed alternative and going through the same process of due diligence to understand just what I'd be getting into.
I don't think the author has a good understanding of Let's Encrypt. Whatever service the author found claiming to be better seems to be lying, based on the author's experience.
For the benefit of the unfamiliar who stumble upon this, getting a Let's Encrypt certificate is a fairly painful process, unless you make it painful. Many hosting providers have the process built into their offering. For those self-hosting, the certbot client is very easy to use, after setting up your site and domain, which you would need to do regardless of what service you use to obtain a certificate.
It only gets complicated if you have a complicated set-up, such as a non-public site or are perhaps using some specialized web services software, in which case I would assume you are sufficiently technically inclined to overcome the obstacles you yourself built.
In any case, I find free and automated is preferable to expensive and manual.
- justin_oaks 4y agoWhen I first got started with LetsEncrypt, I wanted to do the whole thing manually so I could understand it better. This was probably 4 years ago. I expected a web form to fill out (e.g. what domain to do you want, paste your CSR here, etc.), but such a thing didn't exist. The LetsEncrypt site didn't have much useful in the way of instructions except to say "Use Certbot". So I set up certbot, ran it in manual mode, and got my certificate. Cool. The only problem was that there was a little too much magic. What is this "account" that I'm using to renew my certificate if I never made an account (i.e. username password). What happens if I accidentally delete all the files certbot created for me? And a bunch of other questions. The documentation I found didn't give a whole lot of straightforward answers. Instead I pieced together information from blogs and forum posts. I'm hoping the documentation situation has changed, but I can understand how someone can be confused about LetsEncrypt. Many people are happy to use something without any concerns about how it works. Others want to understand and when they find that they can't, they get frustrated.
- Arnavion 4y agoWhen I decided to use LE for my website's HTTPS cert, I wrote my own ACME client from scratch based on the RFC. Never tried certbot, since from the beginning I wanted to to have the cert issuance process run in an Azure Function. The RFC (and the related RFCs for JWK and JWS) are very readable and easy to implement as long as you know how to delegate the crypto to libraries. (I actually ended up writing three different versions, one in PowerShell, then one in F#, and finally one in Rust that I still maintain.) Once I had it working, I wrote a blog post with a higher-level description of the whole cert flow, which you may find useful: https://www.arnavion.dev/blog/2019-06-01-how-does-acme-v2-work/ https://www.arnavion.dev/blog/2019-06-01-how-does-acme-v2-wo... It links to the relevant sections of the RFCs, so you can follow along while reading the post.