Live data from Hacker News

Our First Certificate Is Now Live

letsencrypt.org

141–150 of 263 posts

Re: Our First Certificate Is Now Live

#141
post #68

Earlier quoted context omitted.

Well. I missed that memo. Or rather I kinda sorta knew it was getting devalued, but a Padlock in my browser is something I trust . If it's not trust worthy or verified should we not go the whole hog, dump trusted public keys from all browsers and move to the web-of-trust / certificate pinning. From the blog: just too much of a hassle. The application process can be confusing. It usually costs money. It’s tricky to in…

> But a Padlock in my browser is something I trust. On the padlock note, Microsoft Edge shows a hollowed out, grey padlock for DV certificates. Only EV certs get a full green one (as well as the legal name as other browsers show for EV). See https://certsimple.com/blog/dv-ssl-in-microsoft-edge

> Microsoft Edge shows a hollowed out, grey padlock for DV certificates.

Firefox does the same. Luckily, Chrome is unlikely to do the same, since google.com itself is "only" domain validated.

Re: Our First Certificate Is Now Live

#142

I'm so excited for this to take off, and it's good to see they've taken the first steps, but can I at least download the CA Cert over HTTPS? Not sure how comfortable I am installing a CA cert I downloaded via HTTP, since that's kind of the whole point of this whole thing.

I thought the same thing, so I wrote the comment below (I downloaded it using https and checked it against earlier posted copies of the cert):

https://news.ycombinator.com/item?id=10218774

Re: Our First Certificate Is Now Live

#143

How a root CA goes into the trust store? I know Firefox embed them, so older versions of it will not include it. OS minor updates (Windows, OS X, ...) ever updates the trust store? How much time actually takes it before I can safely use it and be sure that the majority of browsers accept it?

In the short term, Let's Encrypt will be primarily trusted through an IdenTrust cross-signature, which should be created in the near future (and before Let's Encrypt certs are available to the general public).

The cross-signature is a delegation of authority from an existing root CA to Let's Encrypt's intermediate CA, saying that Let's Encrypt should also be trusted to issue certificates. Browsers that accept IdenTrust's root, which is widely accepted today, will then also accept the Let's Encrypt certificates as long as the services that present them also present the certificate chain (which includes the cross-signature certificate).

This will happen in parallel to Let's Encrypt's efforts to be accepted as a root CA, and is not dependent on it. For example, if Mozilla decided not to allow Let's Encrypt to be trusted as a root yet, past, current, and future Mozilla browsers would still accept Let's Encrypt end-entity certificates (with the proper chain) because of the cross-signature.

This is discussed in

https://community.letsencrypt.org/t/frequently-asked-questio...

and is also described in more detail at

https://letsencrypt.org/2015/06/04/isrg-ca-certs.html

Re: Our First Certificate Is Now Live

#144
post #97
post #35

It's amazing that it takes a free provider to make things simple: https://letsencrypt.org/howitworks/ I'd actually pay more than I do now for SSL certs to get that kind of simplicity.

Looks awesome! Does anyone know if there's an undo command for `$ letsencrypt run`? I would love to try this, but too scared to do it and mess up with my nginx configs.

The client has a checkpointing mechanism that does back up old configuration versions and can revert them. (This client feature is called the "reverter", in case you care to look at some of the code or issues related to it on our GitHub page.)

I still haven't figured out how that interacts with the automated renewal features (probably not well right now!) but the ability to revert configurations exists.

Also, please don't try the client with a live site right now, because we don't have general public availability (nobody outside of Let's Encrypt can get a cert issued from the Let's Encrypt intermediate -- you'll get one from "happy hacker fake CA" instead), and we don't have the cross-signature. We're not even quite at the beta-test stage yet, let alone the "please use our certificates on your popular public services" stage. :-)

The main exception would be if you currently don't have HTTPS enabled at all and you're in the mood to experiment to learn more about Let's Encrypt.

Re: Our First Certificate Is Now Live

#145
post #92
post #91

Earlier quoted context omitted.

The other side of that argument is that if your registrar is also your CA, they have the ability to give bogus SSL certs to an evil server and the ability to direct your domain to that evil server.

They can already do that, as they could temporarily hijack your NS records and buy a cert somewhere else. If you can't trust your registrar, you have bigger problems (I'd say "all is lost") On the flipside, having a registar act as the only valid CA would mean that choosing a trustworthy registrar suddenly has real value. Power users could make an educated opinion on the trustworthyness of a given domain validated CA…

A lot of folks might not have thought through the weakest-link aspect of the current system: they feel like they're safer because they chose to use a reputable or trustworthy CA. But misissuance events that I've heard of have never involved CAs that the victims had any business relationship with at all.

Re: Our First Certificate Is Now Live

#146
post #64

Earlier quoted context omitted.

HTTP version really should redir to HTTPS.

That won't really fix anything, anyone who wants to MITM the HTTP can just kill the redirect.

Not with HSTS enabled (which they do have). If you get caught before the first request ever, sure, but you've got bigger problems if that is the case.

Re: Our First Certificate Is Now Live

#147
post #98
post #81

Earlier quoted context omitted.

In this case, the previous commenter was explicitly asking for advice about how to get certificates more conveniently today, so the replies about existing services that can do so seem quite relevant.

It's like trying to sell a Ferrari to a guy who's looking for a regular car...

Maybe so, but you know every regular guy driving a regular car would rather have a Ferrari and might even spend time looking at them even though he can't buy one.

Re: Our First Certificate Is Now Live

#149

Earlier quoted context omitted.

As far as I can tell EV certificates are completely worthless. You know the TLS certificate you got from bankofamerica.com is legitimately from bankofamerica.com because of domain validation. What EV tells you on top of that is only that bankofamerica.com belongs to Bank of America Corporation. But you already have that information . Their website is written on the walls of all their bank branches and all the documen…

There's also the fact that obtaining an EV certificate is so unbelievably painful. I swear it gets more difficult every year. Last time I bought an EV cert, Comodo wanted a certification from a Chartered Accountant. Aside from the confusion associated with Comodo wanting a letter "your CA", we then had them Google for "accountants in Sydney" and complain they weren't listed on the front page. "Kindly address the sear…

Wow, that's just absurd.

Re: Our First Certificate Is Now Live

#150
post #98

Earlier quoted context omitted.

It's like trying to sell a Ferrari to a guy who's looking for a regular car...

Maybe so, but you know every regular guy driving a regular car would rather have a Ferrari and might even spend time looking at them even though he can't buy one.

You're wrong. EV is a scam. I can afford to buy EV for most of my sites, but I don't do it. Because consumers don't really care. Even HN doesn't have an EV! Ferrari is what everybody wants, EV is a different story! And stop downvoting all my comments - it shows your subpar human material. Downvote my main point and stop right there. No need to go aggressive and try to silence me and not comment further, because you will "punish" me further as well.
Post reply on HN