Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, GCP has had arguably a superior TLS story for years.

For example they do managed TLS for their workloads like AWS but they operate their own CA rather than outsourcing to Digicert for certificate issuance which gives them a better SLA.

They have a global load balancer offering that enables TLS to terminate everywhere GCP is without having to manage a bunch of discrete load balancers, this also supports managed TLS.

They now support a very large number of certificates in the global load balancer product which allows SaaS products like hosting services to leverage the global load balancer rather than deploying a load balancer per 25 certificates (the limit per AWS LB).

And now let you enroll for certificates from the same CA they use even if you terminate TLS rather than having them do it for you. They do this via a standard API (ACME) which lets you have uniform and agile device compatibility regardless of how you deploy TLS. AWS doesn't let you do this at all.

(I should note I was the PM for most of these releases and am still the PM for Google Trust Services the CA used for this ACME release)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: