news.volyx.in

Another free CA as an alternative to Let's Encrypt (scotthelme.co.uk)

652 points by Jaruzel · 1861 days ago · 202 comments on HN

Article summary

The article discusses the availability of another free Certificate Authority (CA) as an alternative to Let's Encrypt, which can be used to obtain SSL certificates. The new CA, SSL.com, offers free certificates via an ACME API, making it easy to automate certificate issuance and renewal. This adds to the existing options of Buypass and ZeroSSL, providing more choices for users. The article also highlights the importance of having a backup CA in case of issues with the primary one.

Main themes

  • Certificate Authorities
  • SSL Certificates
  • Automation
  • Security
  • Certificate Expiration
  • CA Alternatives
  • DNS Management

What commenters say

  • Some commenters argue that the 3-month certificate expiration deadline is too short and can be burdensome for smaller organizations, while others see it as a necessary measure to ensure security and automation.
  • There is a discussion about the trade-offs between certificate validity period and security, with some arguing that longer validity periods can be insecure, while others see them as more convenient.
  • Some users express frustration with the automation process, citing issues with certbot and the need for more user-friendly solutions.
  • Others argue that the 3-month expiration deadline forces users to automate, which is a good thing, as it ensures that certificates are always up to date and reduces the risk of expiration-related outages.
  • A few commenters mention that some CAs, like Buypass, offer longer certificate validity periods, such as 6 months, which can be more convenient for some users.
  • There is a debate about the responsibility of Certificate Authorities to provide automation-friendly solutions, with some arguing that it is the CA's responsibility to make automation easy, while others see it as the user's responsibility to automate their certificate management.
  • Some commenters suggest that DNS providers should offer more fine-grained controls over API access tokens, to improve security and reduce the risk of certificate-related issues.