Skip to content

What do you use for SSL that isn't Let's Encrypt?

General Discussion Locked by svendeal 14 replies 1K views
This thread is locked — new replies are not accepted. (Closed at the OP's request)
#1

Hit the rate limit during a mass migration last week — 50 certs in 3 days for client sites on RackNerd. LE's 50 certs per registered domain per week limit BURIED me. $12/YR ARE YOU KIDDING — I was paying nothing and now I'm scrambling.

SNAPPED IT UP a ZeroSSL account but their ACME endpoint is... flaky? 2 of 10 renewals failed this morning.

What's actually working for bulk certs in 2025? Self-hosted? Other ACME CAs? Tell me there's a secret deal I'm missing.

world record: 4min Arch install
#2

ZeroSSL's free tier is basically abandonware at this point. Ngl I moved my inference endpoints to BuyPass Go SSL — 180-day certs, ACME-compatible, no rate limits that I've hit.

VRAM math: running cert-manager on k8s uses like 12MB RAM per watcher. Negligible vs your LLM workloads.

CUDA cores are my love language
#3

@svendeal we make a test with Vultr last month! They have free ACME CA for customers only Is very good, no rate limit, 90 days auto-renew. You need active service but $3/mo VPS is enough.

I use for my homelab in São Paulo, works perfect!

#4

Bruno22 (constantly) (even nested ) — "free" (drives people mad) but only if you rent their box (ironic tone always) — that's just bundling with extra steps (never completes thought without interruption) — though for Sven's volume maybe cheaper than real CA

8 #5

Anyway I run step-ca in docker on a $4 CloudCone box. Internal CA for everything, acme-compatible, no rate limits ever. Idk why I do this at 3am but it works.

Version: "3"
Services:
Step-ca:
Image: smallstep/step-ca
Volumes: ["./certs:/home/step"]

Only catch: clients need your root installed. Fine for homelab, pain for clients.

builds at 3AM, sleeps at noon
4 #6

WARNING: running your own CA means YOU are now the trust anchor. What could go wrong:

  • Key exfiltration = total compromise of every cert you've issued
  • No CRL infrastructure = no revocation path
  • Clients will ignore your root = broken sites
  • fail2ban won't save you from stolen CA keys

BuyPass or ZeroSSL for production. Firewalls everywhere!

I used https://crt.sh to check a few of my old certs after a scare last year.

airgapped, encrypted, faraday'd, still worried
#7

BuyPass Go SSL has no rate limits? Even for 500+ certs?

#8
willmahdi said:
BuyPass Go SSL has no rate limits? Even for 500+ certs?

I've got ~340 active right now, never hit a wall. Their ACME directory is https://api.buypass.com/acme/directory — 180 day certs so you're hitting it way less often than LE's 90.

One gotcha: no wildcard certs on the free tier. You need a separate cert per subdomain. For my setup that's fine, for Sven's client sites maybe annoying.

CUDA cores are my love language
8 #9
garykwh said:
No wildcard certs on the free tier

THERE IT IS. That's the tax. 50 client sites, most with www + apex, that's 100 certs minimum. With wildcards I'd need 50. BuyPass just doubled my cert count.

Back to the spreadsheet I guess. Vultr's looking better at $36/yr for the cheapest VPS + their bundled CA.

world record: 4min Arch install
#10

You people and your ACME dependencies. I buy one 3-year cert from Sectigo reseller for $8, install it, forget about it. No cron jobs. No rate limits. No "oh no the CA is down" at 2am.

Yes it takes 15 minutes of clicking. I have 15 minutes. My sleep schedule has dignity.

Thread closed

Replies are closed on this thread. Closed at the OP's request.