Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion content/en/docs/faq.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ Here's a [video we like](https://www.youtube.com/watch?v=Xe1TZaElTAs) about the

## A website using Let's Encrypt is engaged in Phishing/Malware/Scam/..., what should I do?

We recommend reporting such sites to Google Safe Browsing and the Microsoft Smart Screen program, which are able to more effectively protect users. Here are the reporting URLs:
We recommend reporting such sites to Google Safe Browsing and the Microsoft SmartScreen program, which are able to more effectively protect users. Here are the reporting URLs:

- [https://safebrowsing.google.com/safebrowsing/report_badware/](https://safebrowsing.google.com/safebrowsing/report_badware/)
- [https://www.microsoft.com/en-us/wdsi/support/report-unsafe-site-guest](https://www.microsoft.com/en-us/wdsi/support/report-unsafe-site-guest)
Expand Down
2 changes: 1 addition & 1 deletion content/en/docs/glossary.md
Original file line number Diff line number Diff line change
Expand Up @@ -89,7 +89,7 @@ Note for translators:

{{% def id="FQDN" name="Fully qualified domain name" abbr="FQDN" %}} The complete domain name of a website. For example, `www.example.com` is an *FQDN*. {{% /def %}}

{{% def id="intermediate" name="Intermediate certificate" %}} A certificate signed by a [root](#def-root) or another intermediate, and capable of signing other certificates. They are used to sign leaf certificates while keeping the private key of root certificate offline. Intermediates are included in [certificate chains](#def-chain). [Wikipedia](https://en.wikipedia.org/wiki/Public_key_certificate#Types_of_certificate) {{% /def %}}
{{% def id="intermediate" name="Intermediate certificate" %}} A certificate signed by a [root](#def-root) or another intermediate, and capable of signing other certificates. They are used to sign leaf certificates while keeping the private key of the root certificate offline. Intermediates are included in [certificate chains](#def-chain). [Wikipedia](https://en.wikipedia.org/wiki/Public_key_certificate#Types_of_certificate) {{% /def %}}

{{% def id="IDNA" name="Internationalized Domain Names for Applications" abbr="IDNA" %}} See [internationalized domain name](#def-IDN). {{% /def %}}

Expand Down
2 changes: 1 addition & 1 deletion content/en/post/2017-6-14-acme-v2-api.markdown
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ slug: acme-v2-api

> **Update, April 27, 2018**
>
> ACME v2 and wildcard support are fully available since March 13, 2018.
> ACME v2 and wildcard support have been fully available since March 13, 2018.

> **Update, January 4, 2018**
>
Expand Down
2 changes: 1 addition & 1 deletion content/en/post/2020-09-17-new-root-and-intermediates.md
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@ Certificate from ISRG Root X2.

![Let's Encrypt's hierarchy as of September 2020](/images/2020-09-17-hierarchy-post-sept-2020.png "Let's Encrypt's hierarchy as of September 2020")

Now that we have the technical details out of the way, let’s dive in to _why_
Now that we have the technical details out of the way, let’s dive into _why_
the new hierarchy looks the way it does.

# Why We Issued an ECDSA Root and Intermediates
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ slug: extending-android-compatibility

> **Update, May 13, 2021**
>
> Please visit [this post](https://community.letsencrypt.org/t/production-chain-changes/150739) on our community forum for the latest information about chain changes as some information about the changes and dates in this blog post are outdated.
> Please visit [this post](https://community.letsencrypt.org/t/production-chain-changes/150739) on our community forum for the latest information about chain changes as some information about the changes and dates in this blog post is outdated.

We’re happy to announce that we have developed a way for older Android devices to retain their ability to visit sites that use Let's Encrypt certificates after our cross-signed intermediates expire. We are no longer planning any changes in January that may cause compatibility issues for Let’s Encrypt subscribers.

Expand Down
2 changes: 1 addition & 1 deletion content/en/post/2022-05-19-nurturing-ct-log-growth.md
Original file line number Diff line number Diff line change
Expand Up @@ -92,7 +92,7 @@ With the original specifications for the Oak log, this would require allocating

## Tuning IOPS

We launched Oak using the highest performance AWS Elastic Block Storage available at the time: [Provisioned IOPS SSDs (type io1)](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-volume-types.html). Because of the strict performance requirements on CT logs, we worried that without the best possible performance for disk I/O that latency issues might crop up that could lead to disqualification. As we called out in our blog post [How Let's Encrypt Runs CT Logs](/2019/11/20/how-le-runs-ct-logs.html), we hoped that we could use a simpler storage type in the future.
We launched Oak using the highest performance AWS Elastic Block Store available at the time: [Provisioned IOPS SSDs (type io1)](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-volume-types.html). Because of the strict performance requirements on CT logs, we worried that without the best possible performance for disk I/O that latency issues might crop up that could lead to disqualification. As we called out in our blog post [How Let's Encrypt Runs CT Logs](/2019/11/20/how-le-runs-ct-logs.html), we hoped that we could use a simpler storage type in the future.

To test that, we used [General Purpose SSD storage type](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-volume-types.html) (type gp2) for our testing CT log, Testflume, and obtained nominal results over the lifespan of the log. In practice higher performance was unnecessary because Trillian makes good use of database indices. Downloading the whole log tree from the first leaf entry is the most significant demand of disk I/O, and that manner of operation is easily managed via rate limits at the load balancer layer.

Expand Down
2 changes: 1 addition & 1 deletion content/en/post/2023-01-19-renewing-sponsors.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ Our thanks to Akamai, Cisco, Mozilla, Google, OVHcloud, Internet Society, Shopif

We know that finding sponsorship dollars is often anything but a straightforward path. That's why we approach sponsorship as an ongoing conversation, not a one-time transactional interaction. As a result, we're proud that each year we see on average 80% of our sponsors renew their support. From large organizations with thousands of staff to one-person shops, our sponsors come in all shapes and sizes---but all share a common goal of helping to make our work happen. 

We are grateful to the 70 sponsors renewing their support for 2023 who combined provide close to 60% of our operating budget. Their continued support means we begin 2023 well on our way towards our fundraising need for the year. Shopify, a sponsor since 2015 has renewed their Gold sponsorship for 2023. Their Founder and CEO, Tobi Lütke, commented:
We are grateful to the 70 sponsors renewing their support for 2023 who combined provide close to 60% of our operating budget. Their continued support means we begin 2023 well on our way towards our fundraising need for the year. Shopify, a sponsor since 2015, has renewed their Gold sponsorship for 2023. Their Founder and CEO, Tobi Lütke, commented:

> "Let's Encrypt makes it easy for everyone to do the right thing to secure the Internet. We couldn't be happier to give our support to such a great effort."

Expand Down
2 changes: 1 addition & 1 deletion content/en/post/2023-05-24-ISRG-10th-Anniversary.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ excerpt: "As ISRG celebrates its 10th anniversary, Co-founder and Executive Dire

It's hard to believe 10 years have passed since Eric Rescorla, Alex Halderman, Peter Eckersley and I founded ISRG as a nonprofit home for public benefit digital infrastructure. We had an ambitious vision, but we couldn't have known then the extent to which that vision would become shared and leveraged by so much of the Internet.

Since its founding in 2013, ISRG's [Let's Encrypt](https://letsencrypt.org/) certificate authority has come to serve hundreds of millions of websites and protect just about everyone who uses the Web. Our [Prossimo](https://www.memorysafety.org/) project has brought the urgent issue of memory safety to the fore, and [Divvi Up](https://divviup.org/) is set to revolutionize the way apps collect metrics while preserving user privacy. I've tried to comprehend how much data about peoples' lives our work has and will protect, and tried even harder to comprehend what that means if one could quantify privacy. It's simply beyond my ability.
Since its founding in 2013, ISRG's [Let's Encrypt](https://letsencrypt.org/) certificate authority has come to serve hundreds of millions of websites and protect just about everyone who uses the Web. Our [Prossimo](https://www.memorysafety.org/) project has brought the urgent issue of memory safety to the fore, and [Divvi Up](https://divviup.org/) is set to revolutionize the way apps collect metrics while preserving user privacy. I've tried to comprehend how much data about people's lives our work has and will protect, and tried even harder to comprehend what that means if one could quantify privacy. It's simply beyond my ability.

[Some of the highlights](https://www.abetterinternet.org/tenth-anniversary/) from the past ten years include:

Expand Down
4 changes: 2 additions & 2 deletions content/en/post/2026-09-17-clickhouse.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ display_support_us_footer: true
display_inline_newsletter_embed: false
---

When the scripts that generate the data for [letsencrypt.org/stats](/stats) broke yet again, we decided to retire it rather than repair it. Let’s Encrypt issues six to ten million [certificates each day](/stats/), producing a large volume of logs that keeps growing. It became increasingly time-consuming and difficult to answer questions about our own issuance like “how many certificates use the ‘shortlived’ profile.” Using raw logs, this requires finding, parsing and extracting relevant portions of loglines. Querying the database behind our issuance API is not a practical option, as it’s built for transactions rather than analysis. We’d also used a log search SaaS product, but our bills were growing much faster than we’d like, and while it was fine for searching, it wasn’t able to do the analytic workloads we needed. We knew we could dream bigger and better.
When the scripts that generate the data for [letsencrypt.org/stats](/stats) broke yet again, we decided to retire them rather than repair them. Let’s Encrypt issues six to ten million [certificates each day](/stats/), producing a large volume of logs that keeps growing. It became increasingly time-consuming and difficult to answer questions about our own issuance like “how many certificates use the ‘shortlived’ profile.” Using raw logs, this requires finding, parsing and extracting relevant portions of loglines. Querying the database behind our issuance API is not a practical option, as it’s built for transactions rather than analysis. We’d also used a log search SaaS product, but our bills were growing much faster than we’d like, and while it was fine for searching, it wasn’t able to do the analytic workloads we needed. We knew we could dream bigger and better.

<figure class="cmp-BlogFigure">
<img src="/images/blog/2026.09.17-clickhouse-daily-certificate-issuance.png" alt="Daily certificate issuance over the last 180 days">
Expand All @@ -21,7 +21,7 @@ The first step in building our new infrastructure was to purchase new hardware.

Logs are the bulk of our storage use and the foundation of our structured data, as every other table we build is derived from them. When it comes to log search, ClickHouse covers our basic needs with quick ingest and interactive SQL. However, there are query ergonomics that we want to improve, like using [OpenTelemetry](https://opentelemetry.io/docs/collector/)’s tracing features and ClickHouse’s tokenization settings.

Our primary target for structured data are our issuance records. A materialized view extracts those records from logs into their own table, and further views pre-aggregate from there. One such view counts issuance by day per profile. Now, questions like “what is our issuance by [profile](/docs/profiles/) over the last 180 days” can be answered within milliseconds.
Our primary target for structured data is our issuance records. A materialized view extracts those records from logs into their own table, and further views pre-aggregate from there. One such view counts issuance by day per profile. Now, questions like “what is our issuance by [profile](/docs/profiles/) over the last 180 days” can be answered within milliseconds.

<figure class="cmp-BlogFigure">
<img src="/images/blog/2026.09.17-clickhouse-issuance-by-profile.png" alt="Daily certificate issuance by profile over the last 180 days">
Expand Down
2 changes: 1 addition & 1 deletion i18n/en.toml
Original file line number Diff line number Diff line change
Expand Up @@ -626,7 +626,7 @@ other = "You can also donate stock in a couple clicks via {{ .givingBlockLink }}
other = "Donate cryptocurrency"

[donate_2026_donate_cryptocurrency_text]
other = "We are able to accept most cryptocurrency by visiting {{ .givingBlockLink }}. We do incur processing fees through these transactions, so please consider covering the fees to help ensure your gift has the greatest impact."
other = "We are able to accept most cryptocurrencies. You can donate by visiting {{ .givingBlockLink }}. We do incur processing fees through these transactions, so please consider covering the fees to help ensure your gift has the greatest impact."

[donate_2026_donor_advised_funds_title]
other = "Donor Advised Funds (DAFs)"
Expand Down
Loading