# Rate limit clarification

**URL:** <https://community.letsencrypt.org/t/rate-limit-clarification/73717>\
**Category:** Issuance Policy\
**Created:** [October 2, 2018, 12:47pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification/73717 "2018-10-02T12:47:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cbaijens](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cbaijens/32/26501_2.png) [@cbaijens](https://community.letsencrypt.org/u/cbaijens)\
**Post date:** [October 2, 2018, 12:47pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification/73717/1 "2018-10-02T12:47:50Z")

</div>

Hi, I have a large set of servers currently operating under the same ‘Registered Domain’. Each of these servers requests a Let’s Encrypt certificate for it’s own FQDN, let’s say [server1.abcd.com](http://server1.abcd.com).

Does the rate limiting mean that:

- We can add and request certs for up to 50 new servers per week without issues?

- Even if we have a few thousands of servers with previously issued certificates, they can all renew without problems? I’m not sure about this because the FAQ seems to suggest adding subdomains to the original requested certificate instead of requesting a certificate per subdomain. So the issue for [server1.abcd.com](http://server1.abcd.com), server 2, … server2500 wouldn’t be capped by the same 5 certificates per week renewal policy?

Thanks in advance for clarification.  
Kind regards,

Carlo

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [October 2, 2018, 2:02pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification/73717/2 "2018-10-02T14:02:57Z")

</div>

Hi @cbaijens

> [@cbaijens](#):
>
> We can add and request certs for up to 50 new servers per week without issues?

yes, that should work. Max. 50 new certificates with a new set of domain names. One server -\> one certificate with one new domain name -\> ok.

> [@cbaijens](#):
>
> they can all renew without problems?

Yes, that should work.

> [@cbaijens](#):
>
> because the FAQ seems to suggest adding subdomains to the original requested certificate instead of requesting a certificate per subdomain.

If you add subdomains, you have a new certificate with old and new names. Then you must share one certificate -\> different servers -\> may be more complicated -\> I wouldn't use such a setting.

SAN-Certificates (one certificate with a lot of names) are ok, if the set of domain names is unchanged.

So later you may replace 50 certificates with one name -\> one certificate with 50 names.

But if you have max. 50 new server per week, you can create 50 new certificates.

---

<div class="post-metadata">

**Author:** ![jared.m](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jared.m/32/17871_2.png) [@jared.m](https://community.letsencrypt.org/u/jared.m)\
**Post date:** [October 2, 2018, 2:31pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification/73717/3 "2018-10-02T14:31:05Z")

</div>

It’s important to note for the renewal exemption that while renewals are not _blocked_ by the rate limit, they do count against it. This is why it is recommended to schedule all new issuances to occur before renewals.

---

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [October 2, 2018, 3:02pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification/73717/4 "2018-10-02T15:02:08Z")

</div>

Hi @cbaijens,

I'll assume that we are talking about issue certificates for subdomains of your main domain, i.e. (`server1.abcd.com, server2.abcd.com, serverX.abcd.com`).

> [@cbaijens](#):
>
> We can add and request certs for up to 50 new servers per week without issues?

Yes, but, you should keep in mind that a renewal will count for that limit (there are plans to override this but in a future...). I mean, lets say you renew 50 certificates on Monday (I say Monday as an example, limits are not from Monday to Sunday but from last 7 days, it is a rolling limit), then you couldn't issue a new certificate till next Monday, even worst, you renew 50 certificates on Monday, and another 50 on Friday... then you can't issue new certificates till next Friday so if you plan to issue new certificates you should issue them before a renewal batch could hit the limits for that "week".

> [@cbaijens](#):
>
> Even if we have a few thousands of servers with previously issued certificates, they can all renew without problems?

I think so, as far as I know there is no limit on renewals, but @jsha or @cpu could clarify whether there is some high rate limit on renewals to prevent abuse.

> [@cbaijens](#):
>
> I’m not sure about this because the FAQ seems to suggest adding subdomains to the original requested certificate instead of requesting a certificate per subdomain.

The FAQ is suggesting to add several subdomains on the same certificate because if you add 100 subdomains in the same certificate, it counts as only 1 certificate but if you try to issue 1 certificate for every subdomain you will issue 100 certificates and all of them will count against the rate limit... and keep in mind that there is a limit of 50 new certificates per domain and 7 days.

> [@cbaijens](#):
>
> So the issue for [server1.abcd.com](http://server1.abcd.com), server 2, … server2500 wouldn’t be capped by the same 5 certificates per week renewal policy?

That policy is for issue/renew the same certificate (a duplicated certificate). It means that you can't issue the same certificate for the same subset of domains/subdomains more than 5 times in 7 days.

Maybe you should take a second look to the [rate limit site](https://letsencrypt.org/docs/rate-limits/) and if you think it could be useful to you, then you could apply to a rate limit exception [Let's Encrypt Rate Limit Adjustment Request Form](https://docs.google.com/forms/d/e/1FAIpQLSetFLqcyPrnnrom2Kw802ZjukDVex67dOM2g4O8jEbfWFs3dA/viewform) but before apply, read very carefully all the doc.

Cheers,  
sahsanu

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [October 2, 2018, 3:38pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification/73717/5 "2018-10-02T15:38:55Z")

</div>

> [@sahsanu](#):
>
> I think so, as far as I know there is no limit on renewals, but @jsha or @cpu could clarify whether there is some high rate limit on renewals to prevent abuse.

The applicable limit for renewals is the [Duplicate Certificate](https://letsencrypt.org/docs/rate-limits/#duplicate-certificate) limit. If you renew the same certificate five times in a week (which only really happens in misconfigurations), you'll run into that limit. But if you need to renew a thousand _different_ certificates in a week, that's fine.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [November 1, 2018, 3:38pm UTC](https://community.letsencrypt.org/t/rate-limit-clarification/73717/6 "2018-11-01T15:38:55Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
