Live data from Hacker News

6-Day and IP Address Certificates Are Generally Available

letsencrypt.org

141–150 of 290 posts

Re: 6-Day and IP Address Certificates Are Generally Available

#141

How are IP address certificates useful?

* DoT/DoH * An outer SNI name when doing ECH perhaps * Being able to host secure http/mail/etc without being beholden to a domain registrar

To save others a trip to Kagi: DoT / DoH = DNS over TLS [1] / https [2]

E.g.:

[1] https://developers.cloudflare.com/1.1.1.1/encryption/dns-ove...

[2] https://developers.cloudflare.com/1.1.1.1/encryption/dns-ove...

Re: 6-Day and IP Address Certificates Are Generally Available

#142
post #80

Earlier quoted context omitted.

The push for shorter and shorter cert lifetimes is a really poor idea, and indicates that the people working on these initiatives have no idea how things are done in the wider world.

At some point it makes sense to just let us use self signed certs. Nobody believes SSL is providing attestation anyways.

Then you might as well get rid of TLS altogether.

Re: 6-Day and IP Address Certificates Are Generally Available

#143
post #62

Earlier quoted context omitted.

For better or worse the push down to 47-day certificates is an industry-wide thing, in a few years no provider will issue certificates for longer than that. Nobody is being forced to use 6-day certs for domains though, when the time comes Let's Encrypt will default to 47 days just like everyone else.

> Nobody is being forced to use 6-day certs for domains though Yet

Nobody is being forced to use Let’s Encrypt either.

Re: 6-Day and IP Address Certificates Are Generally Available

#144
post #62

Earlier quoted context omitted.

Well they offer a money-back guarantee. And other providers of SSL certificates exist.

For better or worse the push down to 47-day certificates is an industry-wide thing, in a few years no provider will issue certificates for longer than that. Nobody is being forced to use 6-day certs for domains though, when the time comes Let's Encrypt will default to 47 days just like everyone else.

And you don't think that years ago people would have said "of course you'll be able to keep your security cert for more than two months"?

The people who innovate in security are failing to actually create new ways to verify things, so all that everyone else in the security industry can do to make things more secure is shorten the cert expiration. It's only logical that they'll keep doing it.

Re: 6-Day and IP Address Certificates Are Generally Available

#145
post #122

Earlier quoted context omitted.

It's actually 6 and 2/3rds! I'm trying to figure out a rationale for 160 hours and similarly coming up empty, if anyone knows I'd be interested. 200 would be a nice round number that gets you to 8 1/3 days, so it comes with the benefits of weekly rotation.

It's less than 7 exactly so you cannot set it on a weekly rotation

biweekly rotation?

Re: 6-Day and IP Address Certificates Are Generally Available

#146
post #107

Earlier quoted context omitted.

No, they will only give out certificates if you can prove ownership of the IP, which means it being publicly routable.

It's just control isn't it, not ownership? I can't prove ownership of the IPs assigned to me, but I can prove control.

Yes that’s correct

Re: 6-Day and IP Address Certificates Are Generally Available

#147
post #37

I have now implemented a 2 week renewal interval to test the change to the 45 days, and now they come with a 6-day certificate? This is no criticism, I like what they do, but how am I supposed to do renewals? If something goes wrong, like the pipeline triggering certbot goes wrong, I won't have time to fix this. So I'd be at a two day renewal with a 4 day "debugging" window. I'm certain there are some who need this,…

The push for shorter and shorter cert lifetimes is a really poor idea, and indicates that the people working on these initiatives have no idea how things are done in the wider world.

Which wider world?

These changes are coming from the CAB forum, which includes basically every entity that ships a popular web browser and every entity that ships certificates trusted in those browsers.

There are use cases for certificates that exist outside of that umbrella, but they are by definition niche.

Re: 6-Day and IP Address Certificates Are Generally Available

#148
post #129

Earlier quoted context omitted.

Because it allows to you to work for six days, and rest on the seventh. Like God did.

² By the seventh day God had finished the work He had been doing; so on the seventh day He rested from all His work. ³ Then the on-call tech, Lucifer, the Son of Dawn, was awoken at midnight because God did not renew the heavens' and the earths' HTTPS certificate. ⁴ Thusly Lucifer drafted his resignation in a great fury.

Is this the TLS version of the Bible?

Re: 6-Day and IP Address Certificates Are Generally Available

#149
post #142
post #80

Earlier quoted context omitted.

At some point it makes sense to just let us use self signed certs. Nobody believes SSL is providing attestation anyways.

Then you might as well get rid of TLS altogether.

You'd still want in transit encryption. There are other methods than centralized trust like fingerprinting to detect forgeries.

Re: 6-Day and IP Address Certificates Are Generally Available

#150

Earlier quoted context omitted.

Domains map one-to-one with registrars, but multiple AS can be using the same IP address.

Then it would be a grave error to issue an IP cert without active insight into BGP. (Or it doesn't matter which chain you have.. But calling a website from a sampling of locations can't be a more correct answer.)

>it would be a grave error to issue an IP cert without active insight into BGP

Why? Even regular certs are handed out via IP address.

Post reply on HN