Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The point is to automate. If you're manually renewing them every thee months, then you're very much doing it wrong and it should be cumbersome.


But most people don't want or know how to automate. HTTPS is supposed to be used on very site but not every site is setup by a developer. That's a basic flaw that will make it problematic to have these kinds of HTTPS-only policies.


Having done both, it's far easier to set up one of Let's Encrypts automatic tools than it is to install a certificate manually.

End users won't be configuring their own servers anyway. At best they'll get a cPanel (which using AutoSSL, can then support Let's Encrypt).


If one can't handle setting up Let's Encrypt, they should host their content on a platform where others take care of things like HTTPS for them.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: