Live data from Hacker News

Let’s Encrypt to transition to ISRG root

scotthelme.co.uk

111–114 of 114 posts

Re: Let’s Encrypt to transition to ISRG root

#111
post #104

Earlier quoted context omitted.

I wonder what Google will do with their Cloud Platform Google-managed SSL certificates that have used Let's Encrypt so far... But I guess in the worst case I can just buy traditional certificates for a couple of years.

You can literally exchange the certificates manually in the chain delivered by your webserver using a text editor.

There are no configuration options of any kind in Google App Engine with managed SSL security enabled (since the point is to let Google manage it), which I'd rather keep enabled if feasible to avoid having to worry about renewals etc.

Re: Let’s Encrypt to transition to ISRG root

#112

So what motivates one CA to cross-sign another? I would have thought, if you were a CA you'd prefer not to enable your competitors - especially one who's planning to give away the product for free.

CA market was so competitive, and with a free and open CAs coming in the future, IdenTrust probably grabbed the opportunity. It would be someone else if it wasn't IdenTrust.

IdenTrust has OV, EV, managed PKI, and even DV certificates with 2 year validity that some legacy organization infrastructure requires.

Re: Let’s Encrypt to transition to ISRG root

#113

Earlier quoted context omitted.

Something like Ubuntu sounds like a great fit then.

Modern ubuntu is getting pretty heavyweight. Gone are the days it'll run on any old laptop.

Absolutely. I just refurbished old Core 2 Duo desktops. Ubuntu creaked along (it was Disco Beta).

I found Linux Lite, based on Ubuntu 18.04 LTS:

https://www.linuxliteos.com

Re: Let’s Encrypt to transition to ISRG root

#114
post #100

Earlier quoted context omitted.

It's worth noting here, too, that the vast majority of commercial CAs do not make a lot of money from their public SSL business. The public SSL business is viewed as a loss leader that provides a public profile and security assurance for the company, but most of them make far more money from their private PKI engagements (providing all of the certificates for a company's Active Directory infrastructure, e.g.). As suc…

There's no way that a multi-thousand dollar EV wildcard cert is a "loss leader".

I dunno, if you look at the legacy of DigiNotar it seems like you're dealing with a lot of potential headaches for a couple thousand bucks that your customers hate paying you anyway.

(DigiNotar, of course, famously gave out a fraudulent * .google.com cert and is now defunct.)

As a CA you're assuming a whole lot of liability for not that much money (not that much at the scale of even a small business, anyway), and that just doesn't seem like it'd scale to a wildly profitable venture, especially considering the kinds of people who are actually well equipped to run a CA can probably make a lot more money doing basically anything else in web security. When you add up the contingency risks, the opportunity costs, and whatever actual day-to-day business expenses, it does seem like you'd be looking for other ways to make more comfortable profits.

That doesn't mean CAs should charge more or anything, just that I could accept that SSL certs for standard websites isn't what anyone with a good vision for their business is really trying to hold onto.

Post reply on HN