tallinnying
Member
Night Shift
- Joined:
- Aug 2024
- Posts:
- 268
- From:
- Tallinn, EE
My sleep schedule has dignity.
Respect. But Sven's doing 50 sites, not 3. At 15 min per that's 12.5 hours of clicking. My 3am Docker trauma scales better than that.
Also Sectigo resellers vary wildly. Some send you a zip file and make you concatenate chains manually like it's 2011.
builds at 3AM, sleeps at noon
olespete
Member
Trust No One
- Joined:
- Jun 2024
- Posts:
- 270
- From:
- Unknown
30-45 seconds for finalization
This is what I mean about trust anchors. You are depending on BuyPass infrastructure, their BGP, their DDoS mitigation. At least with step-ca the latency is YOUR problem, not some support ticket.
But I still say don't run your own CA for external clients. The risk calculus is wrong.
airgapped, encrypted, faraday'd, still worried
svendeal
Member
OP
Deal Sniper
- Joined:
- Jul 2024
- Posts:
- 301
- From:
- Miami, US
Looked at this. The free tier requires registering in Google Cloud Certificate Manager, and there's a quota of 100 certificates per project per lifetime for the free issuance. Not weekly — lifetime. Blow through that on one migration and you're paying Google rates.
So that's out for bulk.
Current leaderboard for my specific hell:
- 1. Vultr bundled CA — $36/yr, wildcards(?), need to verify
- 2. BuyPass — free, no wildcards, 2x cert count
- 3. ZeroSSL paid — $50/yr for 3 tiers, ACME still flaky per my own logs
Someone tell me Vultr supports wildcards before I give them money.
world record: 4min Arch install