Live data from Hacker News

Let's Encrypt makes certs for 30% of web domains

leebutterman.com

11–20 of 147 posts

Re: Let's Encrypt makes certs for 30% of web domains

#11

can someone please share how they deploy/distribute Let's encrypt certificates with auto renewal on load balanced multiple EC2 servers for the same dns name. I had tried this a while but had to give up and just bought SSL certs which I then include in my EC2 image.

You can store the cert and key in a key/val store and each EC2 server would only need to renew the cert.

Re: Let's Encrypt makes certs for 30% of web domains

#14

can someone please share how they deploy/distribute Let's encrypt certificates with auto renewal on load balanced multiple EC2 servers for the same dns name. I had tried this a while but had to give up and just bought SSL certs which I then include in my EC2 image.

Have you tried using Caddy? It handles automatic HTTPS (a.k.a Let's Encrypt) renewal across a fleet.

https://caddyserver.com/docs/automatic-https#fleet

Re: Let's Encrypt makes certs for 30% of web domains

#15
post #6

The GCP self-serving platform for certs is very welcome, but still kinda janky. You end up waiting hours for their batch jobs to run at unknown cycles. Let's encrypt is awesome because it's instantaneous! You'd think Google would understand that aspect. Edit: GCP people: Please give us a an explicit "retry" button to press when we've set up the DNS records. (I'm talking about the Google Cloud Balancing Service here.…

If you use Google cloud enough you'll soon realize they're not very fast at anything.

Better hope you don't get your account automatically banned because one of your employees does sketchy things on their own personal account

Re: Let's Encrypt makes certs for 30% of web domains

#17
post #9

A few of these things, while not necessarily wrong, should be put into context. E.g. "Hundreds of thousands of domains' certs expire after 2099". Yeah, but no publicly trusted certs. They're capped at a bit more than 2 years and there's a discussion to cap them even more. The certs they're seeing are almost certainly mostly: "let's create a test selfsigned cert for this host. how long should it last? let's type in a…

Yes, but...

Historically there were some certs that kept getting grandfathered in after lifetimes were restricted because they'd been issued before there were any rules - maybe ten years to expire or even more? I think the last of those probably went away because of the Symantec distrust (not that they were issued by Symantec, but they were issued by a CA which was bought by a CA which in turn was bought by Symantec before it was distrusted) and also of course they'd have either MD5 or SHA-1 signatures, which are not accepted today anyway.

There were still certs issued right up until the end of March 2018 with the old 39 month lifetime maximum. You can see them most easily in the annualised CT logs for 2021. A while back CT log operators realised that logs just get longer (of course) and so they would need to periodically make new ones and archive the old ones. Very quickly they struck upon the idea of annualising them, instead of running FooBar Log, run FooBar Log 2019, FooBar Log 2020 and FooBar Log 2021, and then require any submissions to use the log matching the year of expiry of the certificate they were logging. This way you can archive FooBar Log 2019 when people get back from holidays after celebrating New Year 2020, all the certs in that log are expired anyway now.

I guess that today the last of those 39 month certs will actually expire before a brand new 825 day cert, but they are still out there, so don't write software that assumes leaf certs can't last more than 825 days just yet.

Re: Let's Encrypt makes certs for 30% of web domains

#18
post #16

This kind of centralization is not good. Even thought let's encrypt is non profit and has a very good service record. We desperately need more like it spread around the globe.

What problems would decentralization solve here?

Improved security. So many sites are trusting Let's Encrypt and have cron jobs set to refresh data from them. If Let's encrypt were comprised or went offline, they are now a huge single-point-of-failure (or worse, single-point-of-exploit?) for all these domains. It's become a kind of monoculture. A more diverse ecosystem of offerings would be resilient to any single attack or failure.

Re: Let's Encrypt makes certs for 30% of web domains

#19
post #16

This kind of centralization is not good. Even thought let's encrypt is non profit and has a very good service record. We desperately need more like it spread around the globe.

What problems would decentralization solve here?

Letsencrypt doesnt issue certs to Iran, Syria, Cuba, Sudan et al.
Post reply on HN