Skip to content

What do you use for SSL certificates nowadays?

General Discussion by adam20 27 replies 2K views
1 #21
Petra3 said:
The best client is the one you audit

This. I audit nothing and I admit it. I run certbot-auto from a cron job on an old CentOS 7 box in Sydney and pray. It has worked since 2018. One day it will break and I will have 14 days of panic.

The 90-day thing means my panic window is small. This is not a feature. This is an anxiety generator.

100% packet loss at hop 3
#22
pam3 said:
Anxiety generator

Then set your cron to run every 30 days instead of every 60. Problem solved. You are choosing the anxiety.

push. done. coffee.
3 #23

I learning acme.sh now in Da Nang. Very difficult for me. The dns api for my provider not in list, need use manual mode. I wait 90 day and do again? No automatic? Very sad.

Vietnam provider not support api for dns challenge. Many friend use Cloudflare but I want use local domain .vn.

7 #24

You can use http challenge if you have static IP ạ no need dns api ạ

#25

My IP dynamic ạ very sad ạ

#26

For dynamic IP you can use ddns first, no? Then http challenge work. Or change provider, many cheap VPS in Singapore, no?

5 #27

What about ZeroSSL? Also free 90 day but with dashboard and email reminder. No acme needed if you dont want.

3 #28

ZeroSSL is a Sectigo reseller. The free tier has rate limits and the dashboard is not an API. If you want automation you use ACME anyway, at which point you are back to choosing a client.

"Email reminder" is not a strategy. It is a failure mode with a delay.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft