>certificate revocation is a thing
Man, OCSP is so flaky. It relies on a HTTP request to the CA. So if there server goes down everyone has to default to trusting or everything grinds to a halt.
And they do go down, constantly.
LetsEncryt is entirely legit. Their root is trusted in every modern browser and OS, and that is not something that happens if they are not. Granted, most people still trust Comodo too, but it is still solid.
They only issue domain-validated certs too, so its not like they are promising the moon.
Man, OCSP is so flaky. It relies on a HTTP request to the CA. So if there server goes down everyone has to default to trusting or everything grinds to a halt.
And they do go down, constantly.
LetsEncryt is entirely legit. Their root is trusted in every modern browser and OS, and that is not something that happens if they are not. Granted, most people still trust Comodo too, but it is still solid.
They only issue domain-validated certs too, so its not like they are promising the moon.