Earlier quoted context omitted.
What do you think is a realistic estimate to get a new CA off the ground? Just the minimal cost for hardware and audits and whatnot to create the required artifacts and get them into the three major root programs. Not including staff and ongoing operational expenses (I can estimate that myself). I’ve heard it can be done for as little as $250,000. Also, timeline. It took Let’s Encrypt a couple years to get in root pr…
Not much: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 It's not about the money, either. LetsEncrypt had their intermediate certificates cross-signed by IdenTrust, otherwise they wouldn't have the 30% market share. It takes a lot of time with the CA application process. You will need to convince Microsoft, Apple, Mozilla, Java, etc that you will be a good CA with good practices. Multiple security audits (start…
Let's Encrypt makes certs for 30% of web domains
121–130 of 147 posts
Re: Let's Encrypt makes certs for 30% of web domains
#122Earlier quoted context omitted.
Convergence was a project to have multiple notaries to vouch for a TLS certificate instead of a chain of CAs. There are way to decentralize the internet, but there never will be much interest for it.
Extremely funny video by Moxie Marlinspike about it: https://m.youtube.com/watch?v=Z7Wl2FW2TcA
Re: Let's Encrypt makes certs for 30% of web domains
#123Earlier quoted context omitted.
Because where is the incentive? Why would anyone be a "miner"? What reward would there be?
could be a nonprofit, like letsencrypt
Re: Let's Encrypt makes certs for 30% of web domains
#124Earlier quoted context omitted.
Letsencrypt doesnt issue certs to Iran, Syria, Cuba, Sudan et al.
Yes we do. On what basis did you make that statement? We comply with U.S. sanctions by not issuing to entities on the SDN list, but that doesn't prevent us from serving the vast majority of people in those countries.
What are good non-US CAs?
Re: Let's Encrypt makes certs for 30% of web domains
#125Earlier quoted context omitted.
could be a nonprofit, like letsencrypt
That's not the point. In a decentralized system, every actor needs an incentive to mine new blocks in the chain. In cryptocurrencies, the incentive is the creation of new money attached to your name. But what if we're not dealing with a currency, but something else?
Re: Let's Encrypt makes certs for 30% of web domains
#126Earlier quoted context omitted.
Not much: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 It's not about the money, either. LetsEncrypt had their intermediate certificates cross-signed by IdenTrust, otherwise they wouldn't have the 30% market share. It takes a lot of time with the CA application process. You will need to convince Microsoft, Apple, Mozilla, Java, etc that you will be a good CA with good practices. Multiple security audits (start…
That link is amazing. Thank you for that. Yea I have a pretty good idea of what’s involved. None of that is impossible to do. Time consuming? Sure. Impossible? Far from it. The root programs have documented processes to get included and will (eventually) accept a legit new CA that’s passed WebTrust audit and has good practices (afaik). Hardest thing is finding someone to cross-sign to accelerate the process. That’s w…
Re: Let's Encrypt makes certs for 30% of web domains
#127Earlier quoted context omitted.
That link is amazing. Thank you for that. Yea I have a pretty good idea of what’s involved. None of that is impossible to do. Time consuming? Sure. Impossible? Far from it. The root programs have documented processes to get included and will (eventually) accept a legit new CA that’s passed WebTrust audit and has good practices (afaik). Hardest thing is finding someone to cross-sign to accelerate the process. That’s w…
LE are pretty open about their expenses, ~$3.6m a year currently, if I remember correctly. They got bootstrapped with a cross-signing from IdenTrust and so were able to get off the ground fairly quickly. That won't have been cheap, and I'd be very surprised if anyone would offer the same service now - there's some pretty big risks associated with it. Getting a new trusted CA off the ground is slow and expensive, sadl…
Re: Let's Encrypt makes certs for 30% of web domains
#128Earlier quoted context omitted.
> Yeah, but no publicly trusted certs. > (Over 1.5M expire in the 2040s alone!) I doubt ~75% of the self signed certs expire in this dataset expire 21-30 years from now. Surely the author is correct that there are a good number of public certs with a very long expiration. Would need to download and filter the dataset to know for sure though.
I doubt anybody has ever issued a "real" (Web PKI) leaf certificate (leaves are the edge of the tree, the certificates presented by TLS servers this work connected to) for 21 years let alone 30. Back in 2011 when the Baseline Requirements were first written, they set 60 months (5 years) as the upper limit, with the intent to further restrict to 39 months in a few years and that eventually happened in 2015 or so. Last…
Re: Let's Encrypt makes certs for 30% of web domains
#129Earlier quoted context omitted.
That's due to US sanctions.
Start a LetTheRestOfUsEncrypt.org based in a different country whose government isn't so full of themselves? Or better yet, is there a way to start a decentralized organization itself so that no jurisdiction has absolute power over it?
Re: Let's Encrypt makes certs for 30% of web domains
#130Earlier quoted context omitted.
Yes we do. On what basis did you make that statement? We comply with U.S. sanctions by not issuing to entities on the SDN list, but that doesn't prevent us from serving the vast majority of people in those countries.
Well that's interesting, so these are political certs?