Six day and IP address certificate options in 2025
11–20 of 166 posts
Re: Six day and IP address certificate options in 2025
#12> Our six-day certificates will not include OCSP or CRL URLs. If someone else did this, Mozilla would be threatening to remove them from their trusted roots. IP address certs sound like a security nightmare that could be subverted by BGP hijacking. Which is why most CAs don't issue them. Does accessing the ACME challenge from multiple endpoints adequately prevent this type of attack?
Re: Six day and IP address certificate options in 2025
#13> Our six-day certificates will not include OCSP or CRL URLs. If someone else did this, Mozilla would be threatening to remove them from their trusted roots. IP address certs sound like a security nightmare that could be subverted by BGP hijacking. Which is why most CAs don't issue them. Does accessing the ACME challenge from multiple endpoints adequately prevent this type of attack?
I wonder if they could mandate that IP address certs could only be issued for IPs owned by an AS that has RPKI enabled.
Re: Six day and IP address certificate options in 2025
#14I don't disagree with anything they say here: https://letsencrypt.org/2025/01/16/6-day-and-ip-certs/#short... But... How often do these types of compromises happen? I can't say I've ever seen or heard of it happening.
Re: Six day and IP address certificate options in 2025
#15Will this work for IPv6?
Re: Six day and IP address certificate options in 2025
#16Earlier quoted context omitted.
I wonder if they could mandate that IP address certs could only be issued for IPs owned by an AS that has RPKI enabled.
Last I read, RPKI data gets stripped if it passes through an AS that doesn’t support it.. Has that changed?
Re: Six day and IP address certificate options in 2025
#17Re: Six day and IP address certificate options in 2025
#18Re: Six day and IP address certificate options in 2025
#19Re: Six day and IP address certificate options in 2025
#20Earlier quoted context omitted.
Yes, a forward looking org like Let's Encrypt would have said IPv4 if needed. Here is an example from Cloudflare https://[2606:4700:4700::1111]
Why does the url say one.one.one.one in my browser?