The one thing stopping adoption for a lot of people is wilcard support. https://community.letsencrypt.org/t/please-support-wildcard-...
It's been discussed in details here the reason why they don't support wildcard: "doing domain validation for wildcard certificates is not currently in the ACME spec because it's a hard problem."[1] LetsEncrypt CA allows Subject Alternative Names (SAN), the true need for an unlimited sub-domains TLS cert vs. a SAN TLS cert is minimum, given Certbot's automation capability. [1]: https://github.com/certbot/certbot/issue…
Let's Encrypt root certificate trusted by Mozilla
31–40 of 166 posts
Re: Let's Encrypt root certificate trusted by Mozilla
#32The one thing stopping adoption for a lot of people is wilcard support. https://community.letsencrypt.org/t/please-support-wildcard-...
Check out GlobalSigns Cloud SSL product if you want a cert that can mix wildcards with top level SANs....not free but.... https://www.globalsign.com/en/cloud/
Re: Let's Encrypt root certificate trusted by Mozilla
#33The one thing stopping adoption for a lot of people is wilcard support. https://community.letsencrypt.org/t/please-support-wildcard-...
Re: Let's Encrypt root certificate trusted by Mozilla
#34Earlier quoted context omitted.
Let's Encrypt is pretty great, but if you have the money get a paid SSL. Not all SSL certs are created equal.
> Let's Encrypt is pretty great, but if you have the money get a paid SSL. Not all SSL certs are created equal. Say what? Besides the faux security of the green bar for an EV cert, what's the difference between a LetsEncrypt and a paid one? (non-EV)
Tying real world identities to public keys is very much a part of crypto. Windows does it with package signing and EV, Debian does it with people holding up their passports at Linux events, and web sites do it with EV HTTPS.
And yes, we (CertSimple) are looking at Certbot support for EV.
Re: Let's Encrypt root certificate trusted by Mozilla
#35Question: any possible case of bad apples that make let's encrypt suddenly lose their trust? Eg bcoz it's free, it's used by "bad guys" just like .info tld.
Re: Let's Encrypt root certificate trusted by Mozilla
#36Earlier quoted context omitted.
It's been discussed in details here the reason why they don't support wildcard: "doing domain validation for wildcard certificates is not currently in the ACME spec because it's a hard problem."[1] LetsEncrypt CA allows Subject Alternative Names (SAN), the true need for an unlimited sub-domains TLS cert vs. a SAN TLS cert is minimum, given Certbot's automation capability. [1]: https://github.com/certbot/certbot/issue…
SAN isn't a practical solution for cases where you don't want to expose which subdomains exist, or where you allocate them dynamically.
Re: Let's Encrypt root certificate trusted by Mozilla
#37It's about time that HN switches to Let's Encrypt.
It appears that HN's cert is a wildcard, so they can't switch yet anyway.
Re: Let's Encrypt root certificate trusted by Mozilla
#38Earlier quoted context omitted.
It's been discussed in details here the reason why they don't support wildcard: "doing domain validation for wildcard certificates is not currently in the ACME spec because it's a hard problem."[1] LetsEncrypt CA allows Subject Alternative Names (SAN), the true need for an unlimited sub-domains TLS cert vs. a SAN TLS cert is minimum, given Certbot's automation capability. [1]: https://github.com/certbot/certbot/issue…
SAN isn't a practical solution for cases where you don't want to expose which subdomains exist, or where you allocate them dynamically.
Re: Let's Encrypt root certificate trusted by Mozilla
#39Re: Let's Encrypt root certificate trusted by Mozilla
#40Earlier quoted context omitted.
Other browsers do not have their own certificate stores but use those provided by the OS. Next interesting things are whether Windows and Mac OS X add the root certificate. I think Linux distributions tend to follow Mozilla's trust.
RE: Linux, You're correct, they're provided through the ca-certificates package[0]: "It includes, among others, certificate authorities used by the Debian infrastructure and those shipped with Mozilla's browsers. " RE: OSX - If you can get into Mozilla's trust stores, it's the same steps (and pro forma, more or less) [1] [0] https://packages.debian.org/wheezy/ca-certificates [1] https://www.apple.com/certificateautho…