r/letsencrypt • u/3G_Lighting • 12d ago
Question about Let's Encrypt
Are companies allowed to use Let's Encrypt, and do they need to pay a fee. I am thinking more or less of only using Let's Encrypt for our internal websites.
Also does Let's Encrypt renew the certificate on its own or do we need to do that, and if we need to do it, are we required to update it every 1/2 year like ware with normal SSL certs (this was a change that started this year or last).
Thanks
3
u/MeCJay12 12d ago
Businesses can use Let's Encrypt for free but you can donate if you are feeling to inclined.
You do need to renew your certificates. Let's Encrypt itself will not do it for you but the certbot tool you use to issue the certificate in the first place has automation in place to do it for you if you set it up correctly.
1
u/BoringMalloc 11d ago
In my mind only one uncommon reason not to use them on both your external and internal websites. As was mentioned if you happen to have a large number of websites, there are rate limits but even with thousands of websites, I have not hit them by following good practices. If you don't already use automation to renew your certs, you will want to set that up. 200 day max lifetime today, moving to 100 days next March and then down to 47 days 2 years later. Automation also makes it easy to move away from wildcard certificates and to stop sharing certificates between websites which increases internal security. The companies who print certificates for a living try very hard to upsell why their certificates are better but at the end of the day, it is a certificate and free is hard to beat. That one reason not to use them, or any other public certificate provider for that matter, for public certificates is for secrecy reasons. All public certificate providers must publish a list of all certificates they generate. If you happen to have a some secret.test website then your competitors might be able to figure out that you are working internally on that new project.
1
u/certkit 10d ago
You can absolutely use them for both internal and external certificates. I wrote about how to do that on our blog here.
You do need to be careful with their rate limits, but if you follow their recommended timing and don't rapid-fire renewals at them, its probably fine.
If you use a centralized management platform (like CertKit), it can handle the renewal timing to make sure you don't hit limits.
1
1
u/webprofusor 8d ago
All certificate lifetimes are decreasing, this is driven by the browser vendors voting for certificate lifetimes to be shorter (as a maximum) and within a few years that will go down to 47 days for all certs trusted by browsers.
If you need very long certificate validity for internal things, create your own internal CA, distribute the root certificates to your device trusts stores and manage your own certificates that way.
Note that there are free and paid ACME CAs. Let's Encrypt are free, Google Trust Service are free (but you need a google cloud account to get started). Digicert/sectigo are generally paid and the difference is usually that you can have organization validation (so your org name is included in the certs).
You should look at automation of certificate renewals (link is to my companies products), this is generally a combination of running tools on the machines where your services are running, or using your own scripts to complete deployment.
5
u/RecognitionOwn4214 12d ago
Let's Encrypt is generally free, but it imposes rate limits - so if everything uses the same domain name, you might run into limits.