Scaling the Let's Encrypt rate limits to prepare for a billion active TLS cert

12 fanf2 1 5/26/2025, 8:42:05 AM letsencrypt.org ↗

Comments (1)

altairprime · 2d ago
> Conveniently, the difference between the TAT and the current time can then be returned to the subscriber in a Retry-After header, informing their client exactly how long to wait before trying again.

I hope they know to add in a small amount of anti-synchronization randomness to the exactly-calculated “retry-after” delay.