# I'm Completely Lost

**URL:** <https://community.letsencrypt.org/t/im-completely-lost/4104>\
**Category:** Uncategorized\
**Created:** [November 18, 2015, 4:46pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104 "2015-11-18T16:46:08Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![esopro](https://avatars.discourse-cdn.com/v4/letter/e/b4bc9f/32.png) [@esopro](https://community.letsencrypt.org/u/esopro)\
**Post date:** [November 18, 2015, 4:46pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/1 "2015-11-18T16:46:08Z")

</div>

Just had a chance to crack open the beta instructions for the first time. Sorry, but I am completely lost after just the first sentence.

I mean, I know git and linux, but I just have a WordPress site. The server is controlled by GoDaddy. There’s no way I’m running Python scripts and what-not.

I sure hope this Beta methodology is to get the underlying process tight, and that a subsequent test will be WAAAAYYYYY more automatic. There’s no way the average Joe is going to sign up for letsencrypt if they have to know git and run linux commands on their server.

Unless you have way more dumbed down, real push-button instructions for the beta test, please take me off the list and give my beta slot to someone who can use it.

---

<div class="post-metadata">

**Author:** ![mlp](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mlp/32/1781_2.png) [@mlp](https://community.letsencrypt.org/u/mlp)\
**Post date:** [November 18, 2015, 5:14pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/2 "2015-11-18T17:14:19Z")

</div>

Hello!  
You don’t necessarily need python scripts. As long as you can pass the “challenge” (= prove domain ownership), it’s all good.  
You should try some other ACME clients out here (especially this one [https://github.com/diafygi/letsencrypt-nosudo](https://github.com/diafygi/letsencrypt-nosudo))

---

<div class="post-metadata">

**Author:** ![ac000](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ac000/32/71_2.png) [@ac000](https://community.letsencrypt.org/u/ac000)\
**Post date:** [November 18, 2015, 5:15pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/3 "2015-11-18T17:15:39Z")

</div>

Save yourself some hassle and get a free cert from WoSign ([https://www.wosign.com/english/freeSSL.htm](https://www.wosign.com/english/freeSSL.htm))

Between the whole 90 day cert lifetime limit and the need to install a whole bunch of stuff and the desire to have everything automated, I gave up waiting for this and just got a couple of 1 year certs from wosign. That was pretty painless.

---

<div class="post-metadata">

**Author:** ![NOYB](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/noyb/32/247_2.png) [@NOYB](https://community.letsencrypt.org/u/NOYB)\
**Post date:** [November 18, 2015, 8:47pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/4 "2015-11-18T20:47:46Z")

</div>

Beta is really a misnomer. Current state of Let’s Encrypt client is more akin to alpha.

My first impression was one of dismay. Some of their selling points are, quick, easy, anyone, less than a minute, only two commands, fully automated, and so on. Nothing could be further from the truth. That only exists once a bunch of other stuff is in place which could take considerable effort and even then is hit and miss on most platforms.

Making automation a practicality necessity (90 day cert lifetime) is a joke.

---

<div class="post-metadata">

**Author:** ![My1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/my1/32/1013_2.png) [@My1](https://community.letsencrypt.org/u/My1)\
**Post date:** [November 19, 2015, 8:58am UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/5 "2015-11-19T08:58:30Z")

</div>

@ac000 but now wosign doesnt do any SAN (except for with and without www) without money.

and most of the time their page doesnt even load properly.

---

<div class="post-metadata">

**Author:** ![molyfra](https://avatars.discourse-cdn.com/v4/letter/m/41988e/32.png) [@molyfra](https://community.letsencrypt.org/u/molyfra)\
**Post date:** [November 19, 2015, 12:23pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/6 "2015-11-19T12:23:20Z")

</div>

I believe that the current state of Let’s Encrypt as a CA is production ready. I believe that the software to use Let’s Encrypt as a CA is in Alpha. The result is in it’s current state non-technical users cannot use the service. Technical users can use it but only if they are willing to invest the time.

The 90 day lifetime aspect has been hashed out beyond belief.

---

<div class="post-metadata">

**Author:** ![ikarydis](https://avatars.discourse-cdn.com/v4/letter/i/76d3ee/32.png) [@ikarydis](https://community.letsencrypt.org/u/ikarydis)\
**Post date:** [November 19, 2015, 4:23pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/7 "2015-11-19T16:23:08Z")

</div>

> [@esopro](#):
>
> real push-button instructions for the beta test

Careful. Don't mention push buttons or you'll get censored by the thought police!

---

<div class="post-metadata">

**Author:** ![khurtwilliams](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/khurtwilliams/32/785_2.png) [@khurtwilliams](https://community.letsencrypt.org/u/khurtwilliams)\
**Post date:** [November 19, 2015, 7:27pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/8 "2015-11-19T19:27:07Z")

</div>

I’m using [StartSSL](http://startssl.com) certs.

---

<div class="post-metadata">

**Author:** ![NOYB](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/noyb/32/247_2.png) [@NOYB](https://community.letsencrypt.org/u/NOYB)\
**Post date:** [November 20, 2015, 9:46am UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/9 "2015-11-20T09:46:45Z")

</div>

> [@molyfra](#):
>
> The 90 day lifetime aspect has been hashed out beyond belief.

That's what happens when policies are beyond belief and inflexible even though there are no hard requirements.

---

<div class="post-metadata">

**Author:** ![My1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/my1/32/1013_2.png) [@My1](https://community.letsencrypt.org/u/My1)\
**Post date:** [November 20, 2015, 10:27am UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/10 "2015-11-20T10:27:53Z")

</div>

truly. I mean if you actually can automate, you could easily serve even 7 day certs but with HSTS it would be a real pita. well when DANE comes high enough everyone can create their own CA for their domain

---

<div class="post-metadata">

**Author:** ![Sid](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sid/32/1565_2.png) [@Sid](https://community.letsencrypt.org/u/Sid)\
**Post date:** [November 20, 2015, 1:40pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/11 "2015-11-20T13:40:19Z")

</div>

This thread raises a good point. Is there a PHP ACME client?  
I think there will be a lot of people that can only run PHP on their website.

---

<div class="post-metadata">

**Author:** ![My1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/my1/32/1013_2.png) [@My1](https://community.letsencrypt.org/u/My1)\
**Post date:** [November 20, 2015, 1:49pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/12 "2015-11-20T13:49:38Z")

</div>

well you can use manual mode from a completely different computer and then you have to put a file at your webserver which obviously must be accessible from the outside.  
for example like this:

[http://my1.info/.well-known/acme-challenge/E\_alwJ4LTi1BO1KyPbzY3VwyyhGZsBljT7wRm9OGouE](http://my1.info/.well-known/acme-challenge/E_alwJ4LTi1BO1KyPbzY3VwyyhGZsBljT7wRm9OGouE)

---

<div class="post-metadata">

**Author:** ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)\
**Post date:** [November 20, 2015, 2:06pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/13 "2015-11-20T14:06:51Z")

</div>

The biggest issue with that is probably that it’s usually not PHP “doing the SSLing”, but a separate web server like apache or nginx. While a Let’s Encrypt client written in PHP would work just fine, you will need to find a way to pass those certificates to your web server and force a reload. That’s usually not something you can do with shared hosting, where, if they offer SSL with custom certificates at all, it’s usually some kind of web interface where you have to manually upload the certificate. At that point you might as well use manual mode from your own PC, and upload the challenge files by some other means.

---

<div class="post-metadata">

**Author:** ![NOYB](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/noyb/32/247_2.png) [@NOYB](https://community.letsencrypt.org/u/NOYB)\
**Post date:** [November 20, 2015, 11:56pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/14 "2015-11-20T23:56:12Z")

</div>

> [@My1](#):
>
> you can use manual mode

Which completely negates the automation goal and makes 90 day cert lifetime impractical. Yes we all know that xyz can be done manually. But that is not a practical solution due to very short cert lifetime.

---

<div class="post-metadata">

**Author:** ![My1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/my1/32/1013_2.png) [@My1](https://community.letsencrypt.org/u/My1)\
**Post date:** [November 21, 2015, 12:07am UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/15 "2015-11-21T00:07:37Z")

</div>

I know and thst’s probably a reason why LE is still in beta, because the compatibility is junk

---

<div class="post-metadata">

**Author:** ![david7364](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/david7364/32/3682_2.png) [@david7364](https://community.letsencrypt.org/u/david7364)\
**Post date:** [November 21, 2015, 2:57am UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/16 "2015-11-21T02:57:17Z")

</div>

It is true that there are several sites that offer free certificates. But they aren’t adopting any of the unique Let’s Encrypt ideas, which have the potential to bring security to the entire Internet, almost automatically. I don’t blame you for giving up the wait, but for those who can wait a little longer, automated certificate management is coming. Community software development does take some time. Note also that WoSign is based in China. This might prove problematic for you over time.

---

<div class="post-metadata">

**Author:** ![david7364](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/david7364/32/3682_2.png) [@david7364](https://community.letsencrypt.org/u/david7364)\
**Post date:** [November 21, 2015, 3:03am UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/17 "2015-11-21T03:03:26Z")

</div>

NOYB, Yes, the current state is like Alpha, very true. But short-lifetime certificates are more secure, which is why they were chosen. And don’t forget that their renewal will be automatic. They won’t act like short-term certificates.

---

<div class="post-metadata">

**Author:** ![My1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/my1/32/1013_2.png) [@My1](https://community.letsencrypt.org/u/My1)\
**Post date:** [November 21, 2015, 6:54am UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/18 "2015-11-21T06:54:50Z")

</div>

@david7364 well they plan to make it automatic, yes vut you cannot automate everything, for example in shared hosting.  
also, why not give the option that when actually using manual that clonger certs (like 1 year) are possible.

---

<div class="post-metadata">

**Author:** ![david7364](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/david7364/32/3682_2.png) [@david7364](https://community.letsencrypt.org/u/david7364)\
**Post date:** [November 21, 2015, 12:02pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/19 "2015-11-21T12:02:24Z")

</div>

My1, Yes, I do agree. There is the issue of not being able to automate on strict shared hosting. Your point needs to be addressed, probably with partial automation and longer expiration periods.

---

<div class="post-metadata">

**Author:** ![kerio](https://avatars.discourse-cdn.com/v4/letter/k/f1d935/32.png) [@kerio](https://community.letsencrypt.org/u/kerio)\
**Post date:** [November 21, 2015, 12:12pm UTC](https://community.letsencrypt.org/t/im-completely-lost/4104/20 "2015-11-21T12:12:34Z")

</div>

What were you expecting, exactly? For letsencrypt to magically install a certificate for your site? I hope for your sake that your server is secure enough that changing the configuration of the web server is something that does require elevated privileges.

[Next page](https://community.letsencrypt.org/t/im-completely-lost/4104.md?page=2)
