Let's Encrypt
Free, Automated, Open
A Certificate Authority for a more secure Web
Operated by the Internet Security Research Group (ISRG)
What Is Let's Encrypt?
A free, automated, and open Certificate Authority (CA)
Launched in April 2016 by the Internet Security Research Group (ISRG)
Provides TLS/SSL certificates to enable HTTPS on websites
Trusted by all major browsers and operating systems
Has issued billions of certificates since launch
Non-profit organization backed by major sponsors
Impact:
As of 2025, Let's Encrypt secures over 400 million websites worldwide.
Let's Encrypt - Free, Automated, Open Certificate Authority
Why It Matters
Before Let's Encrypt
SSL certificates cost $50-$300+ per year
Complex manual process to obtain and install certificates
Many small websites remained on insecure HTTP
Certificate renewal was error-prone and easy to forget
After Let's Encrypt
Certificates are completely free of charge
Automated issuance and renewal via ACME protocol
HTTPS adoption jumped from ~40% to over 80% of web traffic
Lowered the barrier for everyone to encrypt the web
Let's Encrypt - Free, Automated, Open Certificate Authority
How It Works: The ACME Protocol
1. Request Client (e.g. Certbot) contacts Let's Encrypt and requests a certificate for a domain.
2. Challenge Let's Encrypt issues a challenge to prove domain ownership (HTTP-01 or DNS-01).
3. Validation Client places a token at a specific URL or DNS record; LE servers verify it.
4. Issuance Once validated, Let's Encrypt signs and issues the certificate.
5. Renewal Certificates are valid for 90 days; automated renewal runs before expiry.
Standard:
ACME (Automatic Certificate Management Environment) is an IETF standard: RFC 8555
Let's Encrypt - Free, Automated, Open Certificate Authority
Validation Methods
HTTP-01
Most common challenge type
Client places a file at [Link]
Let's Encrypt servers fetch the file to verify ownership
Requires port 80 to be open and reachable
Cannot be used for wildcard certificates
DNS-01
Client creates a TXT record: _acme-[Link]
Let's Encrypt queries DNS to verify the record
Required for wildcard certificates (*.[Link])
Can be automated with DNS provider APIs
Works even when web server is not publicly accessible
Let's Encrypt - Free, Automated, Open Certificate Authority
Certbot & ACME Clients
Certbot (Official Client)
Developed by the EFF (Electronic Frontier Foundation)
Supports Apache, Nginx, and standalone mode
Handles certificate issuance, installation, and auto-renewal
Available on most Linux distros, macOS, and Docker
Other Popular ACME Clients
[Link] Shell script, no dependencies, popular on Linux
Caddy Web server with built-in automatic HTTPS
Traefik Reverse proxy with native Let's Encrypt support
lego Go-based ACME client with many DNS providers
win-acme ACME client for Windows / IIS
Let's Encrypt - Free, Automated, Open Certificate Authority
Rate Limits & Certificate Details
Certificate Details
Validity: 90 days (encourages automation, limits damage from key compromise)
Type: Domain Validated (DV) certificates only
SAN support: Up to 100 domain names per certificate
Wildcard: Supported (*.[Link]) via DNS-01 challenge
Key types: RSA (2048/4096) and ECDSA (P-256/P-384)
Rate Limits
50 certificates per registered domain per week
5 duplicate certificates per week
300 new orders per account per 3 hours
Failed validation limit: 5 failures per hostname per hour
Staging environment available for testing (no rate limits)
Let's Encrypt - Free, Automated, Open Certificate Authority
Security & Trust
Cross-signed by IdenTrust for broad compatibility from day one
Own root certificates (ISRG Root X1, X2) now trusted by all major platforms
ISRG Root X2 is an ECDSA root for smaller, faster TLS handshakes
Certificate Transparency: all certificates logged publicly for accountability
Multi-perspective validation from multiple network vantage points
Follows CA/Browser Forum Baseline Requirements
Limitation:
Let's Encrypt does NOT issue OV (Organization Validated) or EV (Extended Validation) certificates.
Let's Encrypt - Free, Automated, Open Certificate Authority
Sponsors & Governance
Operated by the Internet Security Research Group (ISRG), a 501(c)(3) nonprofit
Founded by Mozilla, Cisco, Akamai, EFF, and IdenTrust
Major Sponsors & Partners
Mozilla | Cisco | Akamai | Google Chrome | EFF
Meta | AWS | Shopify | Automattic | Fastly
OVH | GitHub | Ford Foundation | Hewlett Foundation
Funding Model:
Let's Encrypt relies on donations and sponsorships to operate.
Anyone can contribute at [Link]/donate
Let's Encrypt - Free, Automated, Open Certificate Authority
Best Practices
Always automate renewal (cron job, systemd timer, or built-in client)
Test with the staging environment before going to production
Use DNS-01 challenges for wildcard or internal-only domains
Monitor certificate expiry with tools like cert-manager or uptimerobot
Keep ACME client software up to date
Use HSTS headers to enforce HTTPS after enabling TLS
Set up CAA DNS records to restrict which CAs can issue for your domain
Consider OCSP stapling for faster TLS handshakes
Let's Encrypt - Free, Automated, Open Certificate Authority
Key Takeaways
Let's Encrypt made HTTPS free and accessible for everyone.
The ACME protocol automates certificate issuance and renewal.
90-day certificates encourage automation and improve security.
Supported by major tech companies as a nonprofit initiative.
Certbot and many other clients make setup straightforward.
It fundamentally changed the web's security landscape.