Loading…
Let’s Encrypt x Shopify: Securing the Web 4.5 Million Domains at a Time
2023-10-18
- Source
- Shopify
- Published
- Added to Yomu
Summary
Shopify describes how its SSL team moved merchants’ stores to HTTPS and ultimately secured more than 4.5 million domains with Let’s Encrypt. The effort began against certificate providers whose APIs were not designed for fully automated provisioning: errors often arrived as human-readable messages, and imposed throttling could have stretched initial issuance to about 100 days. Shopify tested the ACME protocol, valued its standardized specification and open-source implementation, and first added Let’s Encrypt as a backup certificate authority to improve emergency key or certificate-chain rotation. The team rolled out that integration in a few hours, compared with months for earlier providers, then made Let’s Encrypt its primary authority after finding it reliable. The account presents this change as evidence that ACME can make certificate automation more responsive and allow certificate authorities to be added without redesigning Shopify’s infrastructure.
Context
Shopify needed to provision and renew certificates automatically for hundreds of thousands of domains without merchant interaction. Its initial providers imposed throttling and exposed APIs with human-readable errors, creating scalability and emergency-rotation concerns; provisioning every domain could have taken about 100 days, which was too slow for responding to a private-key or certificate-chain incident.
Approach / What changed
Shopify implemented the ACME client protocol, added Let’s Encrypt as a backup certificate authority, and later made it the primary authority. The team relied on ACME’s standardized specification and Let’s Encrypt’s open-source server implementation to debug predictable errors and integrate the service without redesigning its certificate infrastructure.
Takeaways
- Initial certificate providers’ throttling could have required about 100 days to provision every domain, making emergency certificate or private-key rotation too slow.
- Let’s Encrypt’s ACME protocol provided standardized APIs designed for automated certificate-authority interactions, while its open-source implementation made specifications and behavior directly inspectable.
- Shopify integrated Let’s Encrypt in a few hours, compared with months for its original providers, and later adopted it as the main certificate authority after finding it reliable.