On Tue, 11 Feb 2014, Christoph Haas wrote:

> My main concern is CPU power. The system is running on a sponsored
> virtual server from the ISP Vexxhost in Canada. And at peak times the
> load is already around 0.5. I can ask whether they have a kind of SSL
> accelerator at their disposal. Otherwise I could just set up HTTPS at
> the Apache level and see how serious the CPU usage will go up.

I don't think the SSL overhead will be noticeable compared to the load
caused by modern scripting languages.

> Regarding the certificate: does Debian have resources to buy an SSL
> certificate? I usually use a free StartCom certificate for my own
> purposes but I am not sure whether it is suitable for such use. I
> don't think that the sponsor will donate an SSL certificate either but
> I'm willing to ask.

jcristau recently got a cert for france.debian.net from gandi, using the
"put a file on the webserver" method of authentication.  Gandi certs are
around 12 Euros a year.

