| ▲ | superkuh 6 hours ago | |
Might be a bit of each of us touching different ends of the elephant. To be clear I am talking about long timespans. Lets Encrypt hasn't even existed for a full decade yet. During that time it's dropped support entirely for the original acme protocol. During that time it's root certs have expired at least twice (only those I remember where it caused issues in older software). And that's ignoring the churn in acme/acme2 clients and specific OS/Distro cert choice issues and browser CA issues. Saying that there's no trouble with HTTPS must be coming from experiences on short timescales (ie, a few years). HTTP/3 already doesn't allow anything but CA TLS only. It won't be too long before they no longer allow you to click through CA TLS warnings. If human people want things to be on the web for long time periods those things should be served HTTP+HTTPS. | ||
| ▲ | Ferret7446 6 hours ago | parent [-] | |
If you can't keep your site's certs working, I don't have much faith you can keep your server working. Maintenance is required in the face of entropy | ||