Let’s Encrypt has issued more than 5 million certificates in total since we launched to the general public on December 3, 2015. Approximately 3.8 million of those are active, meaning unexpired and unrevoked. Our active certificates cover more than 7 million unique domains. How can you cover 7 million unique domains if you've only issued 5 million certificates?
One certificate can be for more than one domain.
Progress Towards 100% HTTPS, June 2016
11–20 of 109 posts
Re: Progress Towards 100% HTTPS, June 2016
#12Earlier quoted context omitted.
One certificate can be for more than one domain.
For example, a single cert can serve www.example.com as well as example.com
Re: Progress Towards 100% HTTPS, June 2016
#13Is it still problematic to issue lots of certs for lots of subdomains? I mean, still no wildcard certs and crazy rate limits, that disallow issuing 1000s of certs per day for user-generated subdomains?
Though, it would be nice if the likes of dyndns names were given exception, since they are effectively second level tld's.
Re: Progress Towards 100% HTTPS, June 2016
#14How effective is something like certificate pinning against fraudulent certs?
Re: Progress Towards 100% HTTPS, June 2016
#15Let’s Encrypt has issued more than 5 million certificates in total since we launched to the general public on December 3, 2015. Approximately 3.8 million of those are active, meaning unexpired and unrevoked. Our active certificates cover more than 7 million unique domains. How can you cover 7 million unique domains if you've only issued 5 million certificates?
Re: Progress Towards 100% HTTPS, June 2016
#16Browsers and OS vendors shipping CAs seems to be the root of the problem, in my mind. Those should be distributed by the service providers, who are the actual trustworthy entities in the user's minds.
Re: Progress Towards 100% HTTPS, June 2016
#17Just at the entire world is going HTTPS, my faith in the system is seriously waning. When Symantec bought Blue Coat, it made me start to think about how fragile this is. How long before Symantec gets an NSL demanding an appliance that can mint bogus certs on the fly for dropbox.com, facebook.com, twitter.com, etc...? How effective is something like certificate pinning against fraudulent certs?
Re: Progress Towards 100% HTTPS, June 2016
#18Earlier quoted context omitted.
For example, a single cert can serve www.example.com as well as example.com
That is true, but in this case I think Let's Encrypt and also parent to your comment mean different domains as in e.g. one certificate to cover all three of example.com, example.net and example.org.
Re: Progress Towards 100% HTTPS, June 2016
#19I'm still bitter about this chain of trust model. The fact that I have to get some other party to tell my users that they can trust me just seems wrong. They trust me because of personal history, not because some banner says they should. Browsers and OS vendors shipping CAs seems to be the root of the problem, in my mind. Those should be distributed by the service providers, who are the actual trustworthy entities in…
That's the point. Having some authority who did at least some minimal checking, to extensive checking, and who will verify you really are who you purport to be. Trust but verify probably plays a part in this.
But, remember, you don't have to go to HTTPS. There is no requirement for you to do so.
Re: Progress Towards 100% HTTPS, June 2016
#20Just at the entire world is going HTTPS, my faith in the system is seriously waning. When Symantec bought Blue Coat, it made me start to think about how fragile this is. How long before Symantec gets an NSL demanding an appliance that can mint bogus certs on the fly for dropbox.com, facebook.com, twitter.com, etc...? How effective is something like certificate pinning against fraudulent certs?
I don't think they would be considered fraudulent at all, and in fact I'm pretty sure that's the "safety valve" built into the system and why public encryption is now being encouraged. I share your tinfoil hatted feelings wholeheartedly.
Er, by whom?