Skip to content

What do you use for SSL certificates nowadays?

General Discussion by adam20 27 replies 2K views
3 #1

Still paying CloudCone $89/year for a wildcard. The ticket said "renewal processed" last month and they sent me a cert with SANs for *.example and example.com but the intermediate chain was missing. Had to open another ticket.

Been hearing about Let's Encrypt forever but the 90-day thing seems annoying. What ACME clients are people actually using in production? Any reason not to just automate the whole thing and forget paid certs exist?

The ticket said my account was "flagged for manual review due to certificate volume" when I asked for three wildcards. I have three subdomains. Dry humor is how I cope.

reported. resolved. repeat.
#2

(certbot) (which is fine) (if you enjoy systemd timers (or cron (which who enjoys cron))) (but I switched to acme.sh (not the shell script version (well yes that version (but the one that doesn't require root (which most do (unfortunately))))) (anyway) (the 90-day thing is a feature (forces automation (which you want anyway (for what it's worth (not much))))) (I have not paid for a cert since 2019 (except that one time (enterprise audit (long story))))

push. done. coffee.
#3
adam20 said:
Any reason not to just automate

Kids these days want to know if free is "good enough." Twenty years in this business says the certificate is never the problem. The liability is.

Let's Encrypt won't indemnify you. When your e-commerce site goes down because their OCSP responder hiccuped, you have no one to sue. No SLA, no phone number, no ticket to escalate at 2am. Mark my words, that $89 is cheaper than one hour of lawyer time.

The enterprises I consult still pay KnownHost or Leaseweb for exactly this reason. Not for the crypto. For the paper trail when something breaks.

IPv4, IRC, and irssi — fight me
#4

In the terminal I use certbot good, very easy no?

But for server good with many domain, I use acme.sh with dns challenge, no problem. The 90 days is not issue if you automate in the terminal, no?

Before I pay very very much money for wildcard, now free. But I understand company big want support phone, no? Different need.

#5

Actually, "Let's Encrypt" has no apostrophe; it is a proper noun. Your OCSP concern is misplaced; stapling eliminates that round-trip.

I have used acme.sh, certbot, and lego. The best client is the one you audit; most don't. Semicolons separate independent clauses; your run-on sentences do not.

Viejito: "dns challenge" should be "DNS challenge". Capitalize protocols.

#6

I use certbot on hos with nginx very very easy ạ

Before I pay for ssl very very expensive now free ạ

For company big maybe need paper for insurance I understand ạ

But for personal hos and small projeck lets encrypt is very very good ạ no need think more ạ

My scrip run cron every two month no problem two year already ạ

#7

Which acme client for nginx

#8

CloudCone still charges $89 for a broken chain?

#9
van3 said:
My scrip run cron every two month no problem two year already

certbot or acme.sh? nginx or apache?

#10

acme.sh ạ nginx very easy ạ

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft