fucken... thought I'd check out the AWS CDN (m.t uses S3, after all) and, uh, CloudFront is super-expensive, eh?

like am I missing something, or is AWS trying to charge $600/month for an SSL certificate?

That's probably the case if you set up your own CA in ACM which you will likely not need.

You can get free certs from ACM, if you employ them only on cloudfront or on elastic load balancers (essentially you cannot download the private key, you can only use them on managed resources)

@ashfurrow only if you need to support IE on Windows XP and need a non-SNI certificate

@roguelazer @ashfurrow this is the answer i’m familiar with. there’s a charge for SSL if you need legacy non-SNI support w/ a custom domain.

@ashfurrow It might auto-check allowing non-SNI clients, which means you're really paying for a dedicated IP

@ashfurrow I switched a project recently to Cloudflare because bandwidth/request cost is atrocious on CloudFront, and their WAF is a joke. I wish there were more choices here.

