# Add an Hourly Duplicate Certificate Rate Limit

**URL:** <https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264>\
**Category:** Feature Requests\
**Created:** [November 28, 2020, 3:35am UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264 "2020-11-28T03:35:23Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [November 28, 2020, 3:35am UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/1 "2020-11-28T03:35:23Z")

</div>

I cannot take credit for this suggestion, but I felt it to be so excellent that I just had to champion it.

> [@How I WISH Certbot Worked](https://community.letsencrypt.org/t/how-i-wish-certbot-worked/138258/5):
>
> I actually wonder if it'd be more helpful to add another rate limit, along the lines of no more than 2 duplicate certificates within a half hour (or maybe an hour). So people just doing the same thing over and over again would see an error earlier, but yet haven't used up their entire 5 for the week yet. (But I suppose this is getting off-topic.)

> [@Notification before rate-limit reached](https://community.letsencrypt.org/t/notification-before-rate-limit-reached/139255/6):
>
> I suggested this elsewhere, but I think what may make more sense is to just add a second duplicate-certificate rate limit, this limit being along the lines of no more than 2 of the same certificate in a one-hour period. That way people just repeating the same thing over and over may see that it's a problem before they've used up all 5 for a week.

Multitudes of times per week we see several common ways that certificate-seekers hit the [five-duplicate-certificates-per-week rate-limit](https://letsencrypt.org/docs/rate-limits/):

- Misguided efforts to debug certificate installations (which is a compelling reason to [segregate acquisition and installation behavior](https://community.letsencrypt.org/t/how-i-wish-certbot-worked/138258))
- Ephemeral environments (like certain Docker setups) that treat certificate issuances like tissues
- Multiple devices serving the same certificate (like when the workers behind a load-balancer terminate TLS)

Allowing only two duplicate certificates (one original and one duplicate) per hour along with an appropriate message from Boulder (like coming here to get help) would likely:

- Effectively combat the issuance of duplicate certificates
- Virtually eliminate wasteful spin-up processes of ephemeral environments
- Drastically reduce the number of sad/angry help-seekers being told to "wait a week"

This limit is intended to be in-addition-to the current five-duplicate-certificates-per-week rate-limit.

* * *

I do not feel that the following response is in the spirit of this community:

 ![RTFM](https://global.discourse-cdn.com/letsencrypt/original/3X/a/f/afa729bf29351d616861a94ff65a3c75b36915c6.jpeg)

I sentence you to a long session of RTFM and a lost week of productivity/revenue!

---

<div class="post-metadata">

**Author:** ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)\
**Post date:** [November 28, 2020, 11:14am UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/2 "2020-11-28T11:14:18Z")

</div>

A couple of concerns I see with this:

- Rate limits are complicated enough already; adding yet another one will make it that much harder for a user (who hasn't and won't RTFM--because if they had or would, the situation wouldn't arise) to figure out which one they've hit and how long they have to wait.
- As noted above, this problem affects, pretty much exclusively, people who have trouble with willingness and/or ability to read the extant documentation. Why expect that they'd do a 180 at this point?

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [November 28, 2020, 8:50pm UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/3 "2020-11-28T20:50:03Z")

</div>

> [@danb35](#):
>
> Rate limits are complicated enough already; adding yet another one will make it that much harder for a user (who hasn't and won't RTFM--because if they had or would, the situation wouldn't arise) to figure out which one they've hit and how long they have to wait.

You make a valid point. Clarifying the rate limits in the messages from Boulder would be nice. For now though, I'm thinking about just rewriting the rate limits page.

> [@danb35](#):
>
> As noted above, this problem affects, pretty much exclusively, people who have trouble with willingness and/or ability to read the extant documentation. Why expect that they'd do a 180 at this point?

They would at least have a chance. Does the "sentence" of a week of lost productivity/revenue fit the "crime" of not reading the documentation and not understanding what's wrong? Would you rather help-seekers who come here have 3 more chances within 3 hours or no more chances for a week?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [November 28, 2020, 9:00pm UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/4 "2020-11-28T21:00:48Z")

</div>

> [@griffin](#):
>
> Does the "sentence" of a week of lost productivity/revenue fit the "crime" of not reading the documentation and not understanding what's wrong?

Yes. If you can't find the loophole which is quite clearly stated in the rate limit page currently, you deserve such a "sentence" IMHO.

It's also the mindset of most people coming here with a rate limit problem. It's almost **never** a request for "I don't really understand the page, please help me understand and learn more", it's almost exclusively "Please help me get a brand new cert even if I just issued 5 previously and they magically disappeared and now some stupid error popped up, but I need MOAR CERTS, please help me I'm begging, I want HTTPS `<crying user>`".

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [November 28, 2020, 9:07pm UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/5 "2020-11-28T21:07:43Z")

</div>

That's because their business/career may be in danger.

I almost can't believe that I, of all people, who have used the term "survival of the fittest" almost continuously, am actually fighting for clemency for the less-fortunate/less-willing. What a philanthropic misanthrope I've become.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [November 28, 2020, 9:09pm UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/6 "2020-11-28T21:09:45Z")

</div>

> [@griffin](#):
>
> That's because their business/career may be in danger.

Better _do_ change your dayjob then!

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [December 21, 2020, 11:14pm UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/9 "2020-12-21T23:14:39Z")

</div>

Keeping this topic alive for further discussion.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [December 22, 2020, 4:56am UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/10 "2020-12-22T04:56:25Z")

</div>

I like this suggestion and in particular I think it's somewhat in the spirit of "random entries in the directory" thing—trying to make an issuance process fail quickly if it's based on a mistaken assumption, so that it can be changed as quickly as possible.

I think if Let's Encrypt doesn't want to make this change, it would be a useful thing for clients to implement ("WARNING! Your certificate issuance is duplicative of a very recent issuance, please ensure this doesn't happen repeatedly or you will be rate limited and unable to continue issuing certificates for 1 week"). Unfortunately in the particular case of people using ephemeral Docker containers, there's no way for the client to _notice_ this unless it checks CT logs, which will probably slow down issuance unreasonably.

My other suggestion would be an ACME extension to report the rate limit status. I know that this, too, has been proposed before and is difficult to achieve in various ways, but I wonder whether there would be a straightforward way just to report duplicate certificate count via a protocol extension, without having a fully general mechanism to check the status of all rate limits. One idea would be an HTTP header like

`Duplicate-Count: 2`

that appears when issuing a duplicate that would be within the scope of the rate limit. Then clients could gradually add mechanisms for displaying warnings as appropriate within the context of their own UI.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [December 22, 2020, 5:03am UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/11 "2020-12-22T05:03:33Z")

</div>

> [@Osiris](#):
>
> Yes. If you can't find the loophole which is quite clearly stated in the rate limit page currently, you deserve such a "sentence" IMHO.

I was just having a separate discussion with @griffin about this general topic elsewhere on the forum and now on GitHub, and I noted that a _ton_ of people don't read or review any of Let's Encrypt's own documentation before attempting their first issuance.

I find this sad and frustrating (and I do feel for Jürgen, always having to tell people to "read some basics" about Let's Encrypt!), but I want to suggest that we stay creative about both encouraging people to read (and learn) more, and mitigating some of the consequences of their not having done so.

---

<div class="post-metadata">

**Author:** ![aarongable](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarongable/32/42043_2.png) [@aarongable](https://community.letsencrypt.org/u/aarongable)\
**Post date:** [December 22, 2020, 9:01am UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/12 "2020-12-22T09:01:28Z")

</div>

I'd just like to say that I think this is an idea worth considering -- not promising to do it, but certainly worth considering -- but that we probably won't put serious thought into it until the new year, as most of us are taking various amounts of vacation. If someone wants to file a feature request issue in the Boulder repo, that would be great.

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [December 22, 2020, 9:15am UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/13 "2020-12-22T09:15:49Z")

</div>

Done and done. 😁

> <https://github.com/letsencrypt/boulder/issues/5210>
>
> Per the discussion in the Let's Encrypt Community and @aarongable's recommendation seen here:
> https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [January 21, 2021, 9:26am UTC](https://community.letsencrypt.org/t/add-an-hourly-duplicate-certificate-rate-limit/139264/14 "2021-01-21T09:26:42Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
