Improving the SRE Experience for 10 Years as a Free, Open, and Automated Certificate Authority

Tuesday, March 25, 2025 - 9:45 am10:30 am PDT

Matthew McPherrin, Internet Security Research Group

Abstract: 

Ubiquitous HTTPS is an essential part of a secure and privacy-respecting Internet. To that end, the public benefit certificate authority Let’s Encrypt has been issuing TLS certificates free of cost in a reliable, automated, and trustworthy manner for ten years. In that time, we’ve grown to servicing over 500,000,000 websites.

In this talk we’ll dive into the history of Let’s Encrypt and share helpful context for those managing TLS certificates, as well as information about upcoming changes to Let’s Encrypt and guidance for the future. We’ll also cover how we have strived to make the working lives of SREs around the world easier, and how the SRE community has helped us in return.

Matthew is the technical lead of the Let's Encrypt site reliability engineering team, which runs the Let’s Encrypt Certificate Authority and Certificate Transparency logs. Previously Matthew worked on internal PKI and security infrastructure at Stripe and Square.

BibTeX
@conference {305505,
author = {Matthew McPherrin},
title = {Improving the {SRE} Experience for 10 Years as a Free, Open, and Automated Certificate Authority},
year = {2025},
address = {Santa Clara, CA},
publisher = {USENIX Association},
month = mar
}