From 08076c325b4a52040caa28b0995dd8291968ce64 Mon Sep 17 00:00:00 2001
From: Matthew Holt
- Our flagship feature. Caddy enables HTTPS by default, and automatically procures and renews certificates for all your sites.
+ Our flagship feature, powered by CertMagic. Caddy is the first and only major server that enables HTTPS by default, and automatically procures and renews certificates for all your sites.
- Fully-native, integrated auto-HTTPS is far superior to any solution that requires external tooling or cron jobs. Caddy's certificate maintenance is the best in the industry because it is more robust, reliable, and scalable than any other solution.
+ Fully-native, integrated auto-HTTPS is far superior to any solution that requires external tooling or cron jobs. Caddy's certificate maintenance is the best in the industry because it is more robust, reliable, and scalable than any other solution. Caddy simplifies your infrastructure instead of complexifying it.
- You can try deploying 100,000 sites with Certbot and a cron job—but if that doesn't fall over by itself, the web server will. Only Caddy is designed to massively scale TLS certificates both horizontally and vertically.
+ Sure, you can try deploying 100,000 sites with Certbot and a cron job—but if that doesn't fall over by itself, the web server will. Only Caddy is designed to massively scale TLS certificates both horizontally and vertically.
Never manually generate a CSR again. Never click a link in an email to download a certificate. Never (mis)configure your web server to use them. Never miss reminders to renew your certificates, one-by-one, every few months before they expire. You won't even have to think about certificates or TLS.
@@ -461,7 +461,7 @@
Most ACME clients assume 90-day certificates, or don't expect certificates shorter than 7 days. Caddy can successfully manage certificates with lifetimes on the order of hours and minutes. Instead of hard-coding a certain age before renewing, Caddy computes the age relative to the lifespan of each certificate, called a Renewal Window Ratio. By default, Caddy renews certificates after 2/3 of their usable lifetime. This ratio works for most validity periods, but can be adjusted.Runtime dependencies
Compliance
On-Demand TLS
+ Certificate issuers
+
+
+ Certificate managers
+
+
+ Cluster coordination
+
+
+ Redirect HTTP to HTTPS
+ OCSP
+ Must-Staple
+ Session ticket hardening
+ Key types
+
+
+ Certificate lifetimes
+ Built-in throttling
+ ACME
+
+