Let’s Encrypt Enters Public Beta

3 minute read

Published:

Let’s Encrypt entered public beta on December 3, 2015, removing the invite requirement from its limited beta (started November 2015) and opening free TLS certificate issuance to any website operator. The certificate authority was founded in April 2014 by the Internet Security Research Group (ISRG), backed by the Electronic Frontier Foundation, Mozilla, Cisco, Akamai, and IdenTrust — with IdenTrust cross-signing Let’s Encrypt’s intermediate certificate, which allowed browsers to trust Let’s Encrypt-issued certificates immediately without adding a new root CA to browser trust stores (a process taking years). The ACME protocol (Automatic Certificate Management Environment, finalized as RFC 8555 in 2019) allowed a server daemon to prove control of a domain through either an HTTP-01 challenge (placing a token at a specific URL path on the domain) or a DNS-01 challenge (adding a TXT record to the domain’s DNS zone), then receive a signed 90-day DV (Domain Validation) certificate. The 90-day lifetime was deliberately shorter than the 1–3 year certificates sold by commercial CAs: short-lived certificates reduced the window of exposure from key compromise, and the automation model made renewal every 60–90 days practical. Certbot, the EFF-developed command-line client, automated the challenge-response and certificate installation process for Apache and Nginx on Linux in a single command.

Before Let’s Encrypt, the economics of HTTPS were a barrier for small sites. Domain Validation certificates from commercial CAs (Comodo, DigiCert, Symantec, GlobalSign) cost $10–$100/year with annual manual renewal. StartSSL had offered free DV certificates since 2005, but the process required manual account verification and was effectively incompatible with automated renewal. Extended Validation (EV) certificates with the green address bar required company identity verification and cost $200–$1,000/year. Web hosting control panels (cPanel, Plesk) had no standardized certificate automation — server administrators needed to generate a Certificate Signing Request manually, submit it to a CA via a web form, receive the certificate by email, and install it by editing server config files. Let’s Encrypt’s ACME-based automation eliminated every manual step: the Certbot client generated the private key, submitted the CSR, completed the HTTP-01 challenge automatically, downloaded the signed certificate, and reloaded the web server, all within seconds and completely non-interactively.

By April 2016 (general availability, when the invite requirement was formally dropped), Let’s Encrypt had issued 1 million certificates. By December 2018 it had issued 380 million certificates in total. The HTTPS adoption rate on the web crossed 50% of page loads in Firefox in January 2017 (from ~25% in January 2015), with Let’s Encrypt as the primary driver of new certificate issuance. Browser vendors accelerated the transition by changing how HTTP sites were displayed: Chrome 56 (January 2017) began marking HTTP pages with password or credit card fields as “Not Secure” in the address bar; Chrome 68 (July 2018) extended the “Not Secure” label to all HTTP pages. Firefox and Safari followed similar schedules. The combination of free automated certificates and browser security UI pressure moved HTTPS from an opt-in feature for sensitive pages to the default expectation for all public web content within roughly three years of Let’s Encrypt’s public beta.