Earlier quoted context omitted.
Sometimes magic isn't a good thing, especially when you're operating a service used by as many people as hn daily. Magic means things happened that I didn't explicitly instruct.
That's called automation and it's a good thing.
Let's Encrypt root certificate trusted by Mozilla
81–90 of 166 posts
Re: Let's Encrypt root certificate trusted by Mozilla
#82Earlier quoted context omitted.
> Tying real world identities to public keys is very much a part of crypto. Windows does it with package signing and EV, Debian does it with people holding up their passports at Linux events, and web sites do it with EV HTTPS. This would be a legit argument if EV HTTPS actually achieved that goal. They don't, though: the identity verification around EV HTTPS is a joke.
Can you elaborate?
Re: Let's Encrypt root certificate trusted by Mozilla
#83Re: Let's Encrypt root certificate trusted by Mozilla
#84The one thing stopping adoption for a lot of people is wilcard support. https://community.letsencrypt.org/t/please-support-wildcard-...
I spoke about this earlier this week at a meetup. The consensus in the group was that wildcard certificates are desirable because they're easier to manage. If your tooling is good, the automation afforded by ACME can invalidate the need for wildcard certificates.
I don't understand why Let's Encrypt can't consider validation of the root domain good enough to produce a wildcard. Email at the root domain is what most providers use, not exactly much worse.
EDIT: It's now 20 per domain per week, better but still not viable for even a mid scale operation. A single wildcard is a much nicer and easier to maintain solution in any case.
Re: Let's Encrypt root certificate trusted by Mozilla
#85Earlier quoted context omitted.
HN uses ycombinator's wildcard certificate, and it's not up until August 2019. It's likely that they don't want to go through the trouble until it's really needed.
With Let's Encrypt, the trouble became "Whoaaa I just ran a command and everything works like magic!"
I still love Let's Encrypt for its principle, but I don't dare running it in full auto mode anymore. A few custom shell scripts get the job done easily enough.
Re: Let's Encrypt root certificate trusted by Mozilla
#86Re: Let's Encrypt root certificate trusted by Mozilla
#87Re: Let's Encrypt root certificate trusted by Mozilla
#88Earlier quoted context omitted.
That's called automation and it's a good thing.
Automation is not a universal good, it can be useful and it can be detrimental. Like all tools it should be used with care.
Re: Let's Encrypt root certificate trusted by Mozilla
#89Earlier quoted context omitted.
With Let's Encrypt, the trouble became "Whoaaa I just ran a command and everything works like magic!"
Yeah until two hours later when you notice it messed with random shit it wasn't even supposed to touch. At least, that was my experience; I suppose it depends on how common your setup happens to be. I still love Let's Encrypt for its principle, but I don't dare running it in full auto mode anymore. A few custom shell scripts get the job done easily enough.
Am I missing something that would make this magically work?
Installing a SSL certificate is relatively easy anyhow. It's one of the most common things you do with a http server.
Re: Let's Encrypt root certificate trusted by Mozilla
#90Earlier quoted context omitted.
That's the joke
More specifically, Comodo's defense of that included "We did a 30 day free SSL certificate first! Let's Encrypt is copying our business model!" The free certificate they were referring to was a time-limited free trial that you could use once and then start paying for.
One of their sales droids hassled me a while back with some deeply slimy tactics, so I started grilling him about this and the various hacks they've had. Flat out lied about ever having had unauthorized certs made, and claimed he'd never heard of LE, but he just knew they'd never do that, and I must have bad information. (The first part of the second part I can believe.)
Who knows, maybe Comodo could come back after some strategic executive-ectomies. Microsoft seems to be trying hard to rejoin the ranks of the not-outstandingly-terrible. But as of now, I have serious doubts I'd ever choose their services over someone more trustworthy, like, say, Bernie Madoff.