Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Those are the rate limits, as far as I understand them:

* 100 Names/Certificate (how many domain names you can include in a single certificate) * 5 Certificates per Domain per week * 500 Registrations/IP address per 3 hours * 300 Pending Authorizations/Account per week

It seems to me that WP.com could reach at least one of those... So I was curious to hear how they were doing that.

And yes, I was wondering if they would replace the *.wp.com wildcard - i guess not...




The rate limits have been changed to 20 certificates per domain per week recently.

The registrations/IP rate limits aren't really a problem - WordPress could, in theory, run their entire Let's Encrypt infrastructure using one registration (account).

Pending authorizations shouldn't be much of an issue given that all custom domains are CNAMEs pointing to their servers, so they should be able to solve all challenges.

(By the way: If you're building a large integration, Let's Encrypt can change the rate limits for you.)




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: