Live data from Hacker News

Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

letsencrypt.status.io

11–20 of 97 posts

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#11
post #4

There is one little-discussed down side to ever shorter-lived certificates...

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong. If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.

You're holding your 6-day cert wrong

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#13

That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now. Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuan…

Considering the open source nature of Letsencrypt, I wonder what the barriers/costs would be (theoretically) to a wealthy benefactor who wanted to duplicate its server side infrastructure and a core staffing level of persons, and fund a "parallel" equally trusted, alternative entity with a solid governing board. Same general idea how Acton funded the Signal foundation.

Somewhere that none of the physical infrastructure/hosting environment overlapped with existing Letsencrypt stuff so that the failure of one entity would have zero blast radius affecting the other.

I know there's a long and complicated process to go through to become a trusted root CA and get your CA public cert auto-installed in every OS and browser trust store. Indeed in the early days of letsencrypt I recall their root CA certs were signed by other older root CAs.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#15
post #4

There is one little-discussed down side to ever shorter-lived certificates...

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong. If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.

Only as long as LE isn’t down for 17 days, then we’re in big trouble.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#16
post #4

There is one little-discussed down side to ever shorter-lived certificates...

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong. If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.

Short-lived = 6 days. Even if you reissue after 2 or 3 days, that's… not a lot of breathing room.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#17
post #7

Discord is out too right now, probably unrelated though.

Just speculating, but I don't think it's unrelated. Discord heavily utilizes Cloudflare, and Cloudflare uses Let's Encrypt for a certificate issuance. If they happened to have a certificate signing dependency in some operational rollout today, I think it could explain it. Certainly the timing is very correlated.
Post reply on HN