Is reselling LetsEncrypt Certificates legal_

Hello,

i searched your forum already but my question is not completely answered. I am wondering if invoicing us the certificate itself with a yearly cost is ok.

Our hosting provider invoices us beside the working time to create and implement the certificate as well yearly costs for the certificate itself.

All other questions into this topic was finally answered that the provider invoices the service to implement or generate the certificate, but in my case its defenetely as i described above.

Thanks for answering this question.

1 Like

There’s nothing that would prohibit a hosting provider for charging for certificates, and there are many hosting providers who do charge for this.

6 Likes

OK, thanks. For me it just feels like not ok to use this great service an charge for it.

1 Like

There are many here (I, at least in part, among them) who'd agree with you, in a moral sense. But legally, it's permissible.

4 Likes

It's legal, but yeah, it shouldn't be good for business.

A lot of hosting providers just get a certificate for you and configure your site on https by default, all included.

3 Likes

It depends on the price. Compare two hosting providers giving the same quality service, only pricing differs:

  1. 10$/year certificate + 10$/year for hosting
  2. 100$/year hosting (certificate included with no extra cost)

Which one do you select?

2 Likes

I don't know. 10 $/y is too cheap to be good.

1 Like

Let's take a more abstract example.
A cup of water is free... but it is across the street from where you are seated.
Someone offers to bring you a cup of that "free water" for a price.
[they would have to cross the street twice - without spilling your water]
Does that sound like highway robbery or payment for services rendered?

5 Likes

I mean, we once had a wordpress site on which we expected a lot of traffic, and didn't have any money to invest in the necessary infrastructure (and fuck cloudflare, too).

So, what did we do? We installed a plugin to make a static site out of the wordpress site, and we pushed the whole thing on github pages: our site is now being hosted on Microsoft's cdn, and with a proper Let's Encrypt certificate we didn't even have to ask for. Good luck abusing a static website on that hosting. :smiley:

And wordpress... It could've ran on a laptop (it was on a cheap VPS, we weren't that cheap).

1 Like

I understand the difference between the service to issue the certificate, embed it with the services we are using etc. And in our case we got an invoice for this twice with 3.5hours working time and on top with 100€ each Year for 2 certificates which are running 2 domains but on the same host. So actually its easy to just extend the first certificate by a second domain. But we got invoiced the extrem high service of 7 hours and on top yearly for 2 certificates. I dont feel thats a good trustful business they are doing. Unfortunately if there is no rule which dont allow to resell the certificates its not a point to get out of the contract our boss did with this company.

SEVEN HOURS TO INSTALL TWO CERTIFICATES?

That's either gross incompetence or gross overcharging if not fraud outright.

2 Likes

Thats for sure and now you understand why i am looking for something we could get out of this contract.

Run far away, avoid giving them a single € more.

Use what you already paid for, and then run far, far away.

3 Likes

The issue here isn't whether they should resell the certificates (they're selling the certificate provisioning, which is not the certificate itself - it's the service of getting it and installing it for you), the issue is that they charged a lot of money for the work and said it took them 7 hrs to do, which is highly unlikely and needs proof.

If you need to get out of the contract just ask them for a simple breakdown of the work required and approximate time spent for each step - perhaps there really is a reason. If they can't provide a breakdown of the work (or they do but it's inflated) then the work did not demonstrably take place as stated or was not performed to a reasonable standard - pretty easy to cancel on the ground of incompetence (non-performance) or fraudulent time keeping. Alternatively the contract will have standard terms for cancellation and that will include non-payment by you.

4 Likes