Let’s encrypt only allows a handful per hour and I think I read a maximum of 50 per week.
We filled out the google doc to request an exception however I don’t know when we will hear back about this request, has anyone got any experience with this process? If so how long is it typically for the turnaround to get this approved so we can mass enable let’s encrypt for our clients websites!
Can you share the exact message you’re getting from your ACME client, and what type of issuance you’re doing? I.e. is it lots of unrelated domains, or many subdomains on a single domain?
Is there a reason you chose not to move the existing certs with the sites to the new server? That would've prevented the need to get new ones for all of them simultaneously.
IIS won’t allow us to export the letsencrypt SSLs only the paid ones. Previously we used solidcp.com control panel and i’m not sure how exactly this generated the SSLs but it doesn’t allow private key to export.
Plesk uses 1 Let's Encrypt registration per Plesk user.
I suspect the rate limit you are hitting is this one:
You can create a maximum of 10 Accounts per IP Address per 3 hours
So if you have 100 Plesk users, it would take a total of 30 hours (10 users per 3 hours) to register Let's Encrypt accounts for each user on the server.
Yes we are using plesk but with 573 users and 2040 domains. (including the domains already using SSL ie RapidSSL)
What we tried to do was export a list of domains then run on command line to install a SSL from letsencrypt which started failing quite quickly hence why we submitted a request to have this rate limit increased.
It takes a few weeks to process requests, so this form is not suitable if you just need to reset a rate limit faster than it resets on its own.
If you want to fix the problem immediately, you might need to manually issue the missing certificates using non-Plesk tools, and then gradually replace them with Plesk-issued certificates as the account registration limit permits (~7 days for all your 573 users).
You could also ask Plesk support whether it's possible to somehow issue the certificates from a single Let's Encrypt account.
If you get desperate, there are ways to bypass that cert store flag that prevents export of those certs. Mimikatz is probably the most well known tool that can help. But it's also flagged as a hacking tool by many AV solutions. Here's a thread with some options.
There would be an option to move the accounts from the old hosting to the new one, if available. No need to create new accounts, no chance to hit rate-limit.