Reply to post: Well done, Google

Beware the looming Google Chrome HTTPS certificate apocalypse!

Bronek Kozicki

Well done, Google

I recently installed a new server and migrated friends website from Ubuntu 14.04. While doing so, I also installed letsencrypt certificate and it was very easy, thanks to "apt-get install letsencrypt". A bit of learning of nginx configuration was required, but learning is what I do. Setting up a timer to refresh the certificate bimonthly was trivial, too. One point of note: the certificate will store all alternative host names from -d parameter(s) passed to letsencrypt, but the first -d parameter is also set as CN= record of the certificate. So make sure you pass the right name first.

Why boasting? Just to show there is absolutely no reason to stick with dinosaur CA like Symantec. If the only thing you want to show in the certificate is the host name (rather than organization name), then you do not need expensive verification and letsencrypt is your friend. If you need verification, there is plenty of competition to choose from.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon