Live data from Hacker News

Let's Encrypt had a higher error rate for 90 minutes today

letsencrypt.status.io

41–50 of 115 posts

Re: Let's Encrypt had a higher error rate for 90 minutes today

#41

That explains why one of my IoT vendors is using an expired certificate. I wish Firefox would just give a mild warning for a recently expired certificate, instead of treating it the same as a true man-in-the-middle attach. It's not like someone who couldn't factor the private key in 200 days could in 201 days or even 300 days. I'm convinced that we'd have better security, if we didn't have so much security theater. Y…

But it's only the extreme warning that alerts the website (usually via a customer complaining) that the cert hasn't been renewed. Having the lesser warning just kicks the can down the road.

The IoT should have updated the certs weeks in advance. If they haven't done it by day 0 then their process is broken and delaying the scary warning to say day +5 won't solve anything.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#42
post #33

That explains why one of my IoT vendors is using an expired certificate. I wish Firefox would just give a mild warning for a recently expired certificate, instead of treating it the same as a true man-in-the-middle attach. It's not like someone who couldn't factor the private key in 200 days could in 201 days or even 300 days. I'm convinced that we'd have better security, if we didn't have so much security theater. Y…

> That explains why one of my IoT vendors is using an expired certificate. I don't think so. There was a dip in success rates for 90 minutes today, but nobody should be renewing their certificate within 90 minutes of expiration. If you're at that point, something went wrong weeks ago.

> weeks ago

How long do you think a certificate lives?

Re: Let's Encrypt had a higher error rate for 90 minutes today

#43
post #28

Seems not ideal for an entity who seems to be pushing for shorter expiration periods all the time

I think it’s mostly Apple and maybe Google who have the hard-ons for the shortest expiries possible.

To be fair, if someone managed to steal a set of keys to Gmail.com and icloud.com, I would want them to expire as short a time as possible too.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#44
post #5

To be clear, “Degraded Performance” means just that, not “down.” Let’s Encrypt’s issuance is mostly working fine.

I see you are unfamiliar with status page-ese. “Degraded performance” is a term which means some form of “the entire datacenter is probably on fire”.

That would a Microsoft'ese, "Some regions are encountering issues" => "The entire world is down, but our status page is working"

Re: Let's Encrypt had a higher error rate for 90 minutes today

#45
post #32

Let's Encrypt has been working normally for most of the day. There was a ~90 minute period during which some of our users would have received a higher error rate due to upstream networking issues, but the majority of requests were successful even during that period. It seems our status.io notes are being misinterpreted as much more severe than they were intended to reflect. Edit: Note that this was written in respons…

I'm not sure if your higher error rate is sticky per user or something, but I've tried 10+ times throughout the day and have had 0 successes. They all come back as internal server error. That's why I eventually posted.

It would not have been sticky for the entire day. If it was sticky at all, it would have been only during the 90 minute period I referenced. It's most likely that there is some other issue with how you're requesting the cert. Folks can help debug at: https://community.letsencrypt.org/

Re: Let's Encrypt had a higher error rate for 90 minutes today

#46
post #28

Earlier quoted context omitted.

I think it’s mostly Apple and maybe Google who have the hard-ons for the shortest expiries possible.

To be fair, if someone managed to steal a set of keys to Gmail.com and icloud.com, I would want them to expire as short a time as possible too.

I think revoking them would be better in such a case.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#47
post #45

Earlier quoted context omitted.

I'm not sure if your higher error rate is sticky per user or something, but I've tried 10+ times throughout the day and have had 0 successes. They all come back as internal server error. That's why I eventually posted.

It would not have been sticky for the entire day. If it was sticky at all, it would have been only during the 90 minute period I referenced. It's most likely that there is some other issue with how you're requesting the cert. Folks can help debug at: https://community.letsencrypt.org/

I ran the exact same command now and it's working, so it is possible I was unlucky and was hitting all the worst possible cases.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#48
post #6

What are the viable alternatives to LE? And in case none exists, what does it take to build one? Requirements: free, available to everyone, automation friendly, issues certificates that are actually considered trustworthy by other parties.

Have the EU or Canada pushed to launch an analog of their own?

It seems a bit silly that a service that could be forced by EO to revoke foreign certificates is the backbone of so much of the internet.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#49
post #45

Earlier quoted context omitted.

I'm not sure if your higher error rate is sticky per user or something, but I've tried 10+ times throughout the day and have had 0 successes. They all come back as internal server error. That's why I eventually posted.

It would not have been sticky for the entire day. If it was sticky at all, it would have been only during the 90 minute period I referenced. It's most likely that there is some other issue with how you're requesting the cert. Folks can help debug at: https://community.letsencrypt.org/

Could it be that he was simply throttled while retrying? That seems plausible, and it would make it seem like a long outage.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#50
post #45

Earlier quoted context omitted.

I'm not sure if your higher error rate is sticky per user or something, but I've tried 10+ times throughout the day and have had 0 successes. They all come back as internal server error. That's why I eventually posted.

It would not have been sticky for the entire day. If it was sticky at all, it would have been only during the 90 minute period I referenced. It's most likely that there is some other issue with how you're requesting the cert. Folks can help debug at: https://community.letsencrypt.org/

I updated the post title to say (Fixed) now.
Post reply on HN