Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
Try EnsoVPN - Reliable VPN - 1-Day Free Trial
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Try EnsoVPN - Fast & Private VPN - 1-Day Free Trial
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

ACME Compatible SSL Certificates at Cost-Effective Price (Certera.com)

CerteraSSLCerteraSSL Member, Patron Provider
edited July 24 in Offers

The era of shorter SSL certificate validity (199-day) is here, making manual certificate renewal and installation more time-consuming than ever. Certera.com now offers ACME-compatible SSL certificates from trusted brands like Sectigo and DigiCert at cost-effective prices, helping businesses simplify certificate management and reduce the risk of unexpected certificate expiry.

With ACME automation, you can streamline SSL certificate issuance, installation, and renewal, helping prevent downtime and keeping your websites and applications continuously protected.

🔐 Secure. Automated. Cost-effective SSL Automation certificates start at just $19.99 per year:

Choose ACME-compatible SSL certificates from Certera.com and stay ahead in the era of shorter SSL validity.

Comments

  • emghemgh Member, Megathread Squad
    edited July 24

    @CerteraSSL said: The era of shorter SSL certificate validity (199-day) is here, making manual certificate renewal and installation more time-consuming than ever

    i dont know anyone who renews their ssl certificates manually, literally every free certificate can and is being automated

  • forestforest Member

    What makes this better than Let's Encrypt which is also automated with short validity, but is free?

  • rpqurpqu Member

    @forest said:
    What makes this better than Let's Encrypt which is also automated with short validity, but is free?

    And IP certs

    Thanked by 1nikio
  • LeviLevi Member

    I guess code signing certs are still relevant? Web certs are dead business since LE emerged. I remember when EV certs was a thing, a nice green badge :)

  • yoursunnyyoursunny Member, IPv6 Advocate
    edited July 24

    @forest said:
    What makes this better than Let's Encrypt which is also automated with short validity, but is free?

    Having more CAs helps avoid Internet centralization.
    Formalizing Dependence of Web Infrastructure section 7

    Thanked by 2jsg buggedout
  • forestforest Member

    @yoursunny said:

    @forest said:
    What makes this better than Let's Encrypt which is also automated with short validity, but is free?

    Having more CAs helps avoid Internet centralization.
    Formalizing Dependence of Web Infrastructure section 7

    Doesn't it also increase attack surface because each new target can sign for virtually any domain?

  • nikionikio Member

    @Levi said:
    I guess code signing certs are still relevant? Web certs are dead business since LE emerged. I remember when EV certs was a thing, a nice green badge :)

    The new hot thing on the block are Verified Mark Certificates - that's iff you want Gmail to show a blue check mark next to your emails.

    Thanked by 1buggedout
  • @forest said:

    @yoursunny said:

    @forest said:
    What makes this better than Let's Encrypt which is also automated with short validity, but is free?

    Having more CAs helps avoid Internet centralization.
    Formalizing Dependence of Web Infrastructure section 7

    Doesn't it also increase attack surface because each new target can sign for virtually any domain?

    Only thing it was supposed to solve was the plaintext issue, not that someone sends their data willing to anybody else.

  • Paying for certificates is so 2016. Especially after EV stopped being a thing, there is no
    real need when you have LE, ZeroSSL, Google, Cloudflare. Not that $19.99 per year is expensive, it just an extra thing to renew and keep track of. Feels redundant.

  • Yeah it's annoying as hell. It's just convenience for public stuff as you don't need to bother people with self signed stuff. For anything important to myself, I just self sign for long timeframes. Ain't nobody got time for their little games.

  • nikionikio Member

    @Mainfrezzer said:
    Yeah it's annoying as hell. It's just convenience for public stuff as you don't need to bother people with self signed stuff. For anything important to myself, I just self sign for long timeframes. Ain't nobody got time for their little games.

    ??????????

    I have a Let's Encrypt client that's less than 500 LOC, it supports almost all challenge types and domains and IP addresses. Fully automated. Why would I run self-signed?

  • FourplexFourplex Member, Patron Provider
    edited July 25

    Is there a reason to use paid SSLs in 2026, especially low end certs like these over Let's Encrypt?

    Maybe a high-end certificate makes sense for a big website. But the typical LET user isn't the typical AWS user.

    Back in 2014 I remember paying for SSL certificates just for self-hosted email. Now I run a profitable business on Let's Encrypt.

    EDIT: I wrote 2016 by accident instead of 2026. Oops.

    Thanked by 2forest buggedout
  • @nikio said:

    @Mainfrezzer said:
    Yeah it's annoying as hell. It's just convenience for public stuff as you don't need to bother people with self signed stuff. For anything important to myself, I just self sign for long timeframes. Ain't nobody got time for their little games.

    ??????????

    I have a Let's Encrypt client that's less than 500 LOC, it supports almost all challenge types and domains and IP addresses. Fully automated. Why would I run self-signed?

    Its very easy, privacy. You either fuck around with wildcard certs, which is a bad idea or you leak all over the place your domains through the chain. Obviously one needs to ensure the cert is the correct cert and given they keep shortening the span of max renewal its a pain in the ass to keep updating the checks. (also see the xmpp mitm attack)

  • nikionikio Member

    @Mainfrezzer said: Its very easy, privacy.

    Wildcard is more private anyway. But in any event don't use hostnames like passwordmanager.mainfrezzer.com and mypornstash.mainfrezzer.com and you're good. Nobody cares nor knows what alderaan.mainfrezzer.com resolves to, except you.

    fuck around with wildcard certs, which is a bad idea

    Why?

    or you leak all over the place your domains through the chain

    Which chain? You mean through certificate transparency logs? If so, Refer to Point #1 and use sensible hostnames as per the hostname RFC (which specifically advices divorcing hostnames from purpose descriptors).

    ensure the cert is the correct cert and given they keep shortening the span of max renewal its a pain in the ass to keep updating the checks

    This is what automation is for in the first place.

    If you hate your life set up and automate HTTP Key Pinning as part of your issuance pipeline.

  • forestforest Member

    @luckypenguin said: Especially after EV stopped being a thing, there is no
    real need when you have LE, ZeroSSL, Google, Cloudflare.

    EV still exists, it's just no longer prominently displayed by browsers so it's falling out of favor. Your point is still valid, though.

Sign In or Register to comment.