Progress Towards 100% HTTPS, June 2016
letsencrypt.org
Progress Towards 100% HTTPS, June 2016
1–10 of 109 posts
Re: Progress Towards 100% HTTPS, June 2016
#2That way when https is found to lack some feature, we can easily upgrade to httpz almost immediately?
Re: Progress Towards 100% HTTPS, June 2016
#3Is there any work being done on being able to easily switch out standards? That way when https is found to lack some feature, we can easily upgrade to httpz almost immediately?
The http in https just means http. It has evolved from http/1.0 to http/1.1 to http/2.
I'm not sure what you're asking or how it is relevant to Let's Encrypt.
Re: Progress Towards 100% HTTPS, June 2016
#4How can you cover 7 million unique domains if you've only issued 5 million certificates?
Re: Progress Towards 100% HTTPS, June 2016
#5Let’s Encrypt has issued more than 5 million certificates in total since we launched to the general public on December 3, 2015. Approximately 3.8 million of those are active, meaning unexpired and unrevoked. Our active certificates cover more than 7 million unique domains. How can you cover 7 million unique domains if you've only issued 5 million certificates?
Re: Progress Towards 100% HTTPS, June 2016
#6Let’s Encrypt has issued more than 5 million certificates in total since we launched to the general public on December 3, 2015. Approximately 3.8 million of those are active, meaning unexpired and unrevoked. Our active certificates cover more than 7 million unique domains. How can you cover 7 million unique domains if you've only issued 5 million certificates?
Re: Progress Towards 100% HTTPS, June 2016
#7Re: Progress Towards 100% HTTPS, June 2016
#8Is there any work being done on being able to easily switch out standards? That way when https is found to lack some feature, we can easily upgrade to httpz almost immediately?
Re: Progress Towards 100% HTTPS, June 2016
#9Is it still problematic to issue lots of certs for lots of subdomains? I mean, still no wildcard certs and crazy rate limits, that disallow issuing 1000s of certs per day for user-generated subdomains?
https://community.letsencrypt.org/t/rate-limits-for-lets-enc...
Re: Progress Towards 100% HTTPS, June 2016
#10Is there any work being done on being able to easily switch out standards? That way when https is found to lack some feature, we can easily upgrade to httpz almost immediately?
The "s" in HTTPS is for "secure", and TLS provides that security.
TLS is a evolving standard which is updated over time to add new features when necessary. When HTTPS is negotiated, it can seamlessly choose which version of TLS to use, based off what the client and server want to use.
So, HTTPS will never die due to lack of features. A new version of TLS will just be approved and deployed, and newer devices can use that while older devices can get by on an older version of TLS.
TLS is the successor to SSL. They are backwards compatible, so devices that support TLS also support SSL. The full version history, from newest to oldest, is: TLS 1.2, TLS 1.1, TLS 1.0, SSL 3, SSL 2. In reality, very few servers still use SSL 3 or SSL 2, due to known weaknesses, but colloquially, all the versions are just called "SSL".
TLS 1.3 is underway and will shortly be ready for primetime. Firefox and Cloudflare have already written some implementations based on the draft spec (sorta how routers will implemented the newest 802.11 standards before they are 100% official).