That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international friendly" versions that supported 40 bit encryption, or "fancy secure" versions with 128 bit encryption.
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
101–110 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#102Earlier quoted context omitted.
love thought-terminating cliches. really helps keep from actually thinking ever.
Your comment reads like a thought-terminating cliché. If Russia occupied your city, killed your family and friends and left you homeless, you might reconsider giving freedom to those who take it away from others. Unfortunately, sanctions are often very easy to evade.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#103Earlier quoted context omitted.
3 90-day ACME certs for free. 180€/year for unlimited 90-day certs and 5 yearly ones. That’s a pretty steep increase. I would almost be more interested in a monthly fee per cert.
From their docs[0] this doesn't seem to apply if using ACME, but they don't exactly make that clear... > By using ZeroSSL's ACME feature, you will be able to generate an unlimited amount of 90-day SSL certificates at no charge, also supporting multi-domain certificates and wildcards. Each certificate you create will be stored in your ZeroSSL account. [0]: https://zerossl.com/documentation/acme/
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#104Earlier quoted context omitted.
EU? There’s almost zero information on the company, no privacy policy? The only place I found any mention is the footer, “HID Global Corporation, part of ASSA ABLOY”. Assa Abloy seems Swedish but HID Global is a US company as far as a quick search goes. But without a proper company info page and privacy policy I wouldn’t consider it anywhere near a “good alternative” regardless.
Jumping in here since we’ve been seeing more mentions of ZeroSSL lately, likely related to the recent CA/B Forum discussions around 1‑year certificates and ACME automation. - We’re based in Austria (ZeroSSL GmbH). The company was acquired by HID in 2024, which is part of Assa Abloy (Sweden). - We’re not positioning ourselves as a purely EU-based CA substitute, and we generally don’t market it that way. - For DV certs…
There's no reason to believe they're any less subject to US jurisdiction than LetsEncrypt.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#105This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.
> This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise. I think the "digital tyranny" is a side effect…
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#106Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#107Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#108This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.
Digital certificates that signs software packages are used to enforce exclusion by some manufacturers. Let's encrypt is not in that space to my knowledge, but it is a place where you the owner do not have the right to determine which certificate authority should be trusted, and generally the only one that is trusted is the manufacturer. Its arguable if we even should be calling such entities a certificate authority, even if they technically are the owner of the root certificate that signs the package.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#109This somehow confirms my gut feeling that digital certificates are mainly a means to enforce exclusion on behalf of the certificate authority ownership. It is a tool to prevent people from taking full ownership and control of whatever is affected by digital certificates, be it software, firmware, hardware, or as in this case SSL/TLS. That's digital tyranny in disguise.
I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.