On February 27, 2020, the free certification center Let’s Encrypt .
In a festive press release, project representatives recall that the previous milestone of 100 million certificates was celebrated At that time, the share of HTTPS traffic on the internet was 58% (64% in the USA). Over the past two and a half years, these figures have significantly increased: 'Today, 81% of web pages worldwide use HTTPS, and in the United States, we are at 91%! — the team from the project is thrilled. — An incredible achievement. This is a much higher level of privacy and security for everyone.'
Let’s Encrypt has played a very important role in making HTTPS certificates a utilitarian standard and reliable traffic encryption a common norm on the internet.
Beta testing of the innovative certification center Let’s Encrypt began in December 2015. A unique feature of the new center was that the certificate issuance process was fully automated from the start.
Automatic HTTPS setup on a server occurs in two stages. At the first stage, the agent notifies the certification center of the server administrator's rights to the domain name. For example, the verification may include creating a specific subdomain or installing an HTTP resource within the domain with a specified URI.

Let’s Encrypt identifies the web server with the running agent by its public key. The public and private keys are generated by the agent before the first connection to the certification center. During the automatic verification, the agent performs a series of tests: for instance, it signs the received one-time password with the public key and presents an HTTP resource with a specified URI. If the digital signature is correct and all tests pass — the agent is granted rights to manage certificates for the domain.

At the second stage, the agent can request, renew, and revoke certificates. The protocol used for automatic certificate issuance is a challenge-response authentication class called the Automated Certificate Management Environment (ACME). All certificate manipulations are performed without stopping the web server using the ACME client. It is easy to use, works on most operating systems, and is well-documented. There is an expert mode with an expanded set of settings. Besides Certbot, there are .
The Important Role of Let’s Encrypt
Let’s Encrypt has truly revolutionized the market, where commercial certificate authorities once reigned. Now, they have practically withdrawn from the business of issuing DV certificates (Domain Validation), although they continue to sell Organization Validation (OV) certificates and Extended Validation (EV) certificates, which Let’s Encrypt does not issue because they cannot be automated. However, this is a niche product, and the mass market is dominated by free Let’s Encrypt certificates.
Let’s Encrypt has made automatic certificate renewal standard. Despite their short lifespan (90 days), the automated process eliminates the 'human factor,' which traditionally represents the main vulnerability in security. Domain administrators often simply forget to renew certificates, causing services to go offline. The latest such incident occurred with Microsoft Teams. On February 3, 2020, this collaboration service went offline .
Automatic certificate replacement via the ACME protocol prevents such incidents.
Although the Let’s Encrypt project serves half of the internet, it is a small non-profit organization in the physical world: 'In these two and a half years, our organization has grown, but just a little! — they write. — In June 2017, we were servicing about 46 million websites with 11 full-time employees and an annual budget of $2.61 million. Today, we serve nearly 192 million websites with 13 full-time employees and an annual budget of approximately $3.35 million. This means we serve more than four times as many sites with only two additional employees and a 28% increase in budget.'
Support for the project comes through and .
As of now, HTTPS has become the de facto standard on the internet. Since last year, major browsers have been warning users about the dangers of connecting to sites that do not encrypt traffic using HTTPS. Much of this shift in the security landscape is thanks to Let’s Encrypt.
Moreover, Let’s Encrypt has literally . Now Jabber operates with reliable encryption both at the client-server and server-server levels, and the vast majority of certificates were issued by Let’s Encrypt.

"As a community, we have accomplished incredible things to protect people on the internet," said in the . "Issuing one billion certificates is a testament to all the progress we've made as a community."
Source: habr.com
