Hacker News new | ask | show | jobs
by yjftsjthsd-h 2057 days ago
> We're gradually making ZeroSSL a default CA for Caddy.

As in, replacing LE as the default, or supplementing it? (And if the former, why?)

1 comments

Note how I mentioned that Caddy will be the first server to support redundant ACME CAs, so we'll use both ZeroSSL, and Let's Encrypt for redundancy.
Why ZeroSSL and not e.g. BuyPass?
BuyPass doesn't support wildcards, and only allows up to 5 subjects per certificate (Caddy only uses 1 SAN, but still) -- and Caddy is a ZeroSSL project. We also prefer shorter cert lifetimes.