Looking to renew my server's wildcard TLS cert for as long as possible (e.g. 3+ years). The last CA I used looks sketchy now (with a dozen different cert offerings, max of 2 yrs).

Where are peeps buying their certs these days?

@mperham All LetsEncrypt here now. Wildcard are a real hassle to renew if you are not using one of the API supported DNSs (then it can be automated) but it's a minor hassle compared to the stupidities of most commercial cert providers.