Live data from Hacker News

6-Day and IP Address Certificates Are Generally Available

letsencrypt.org

161–170 of 290 posts

Re: 6-Day and IP Address Certificates Are Generally Available

#161
post #147

Earlier quoted context omitted.

The push for shorter and shorter cert lifetimes is a really poor idea, and indicates that the people working on these initiatives have no idea how things are done in the wider world.

Which wider world? These changes are coming from the CAB forum, which includes basically every entity that ships a popular web browser and every entity that ships certificates trusted in those browsers. There are use cases for certificates that exist outside of that umbrella, but they are by definition niche.

About 99.99% of people and organisations are neither CAs nor Browsers. Hence they have no representation in the CAB Forum.

Hardly 'by definition niche' IMHO.

Re: 6-Day and IP Address Certificates Are Generally Available

#162

This is interesting, I am guessing the use case for ip address certs is so your ephemeral services can do TLS communication, but now you don't need to depend on provisioning a record on the name server as well for something that you might be start hundreds or thousands of, that will only last for like an hour or day.

> I am guessing the use case for ip address certs is so your ephemeral services can do TLS communication There's also this little thing called DNS over TLS and DNS over HTTPS that you might have heard of ? ;)

I don't quite understand how this relates?

Re: 6-Day and IP Address Certificates Are Generally Available

#163
post #147

Earlier quoted context omitted.

The push for shorter and shorter cert lifetimes is a really poor idea, and indicates that the people working on these initiatives have no idea how things are done in the wider world.

Which wider world? These changes are coming from the CAB forum, which includes basically every entity that ships a popular web browser and every entity that ships certificates trusted in those browsers. There are use cases for certificates that exist outside of that umbrella, but they are by definition niche.

>which includes basically every entity that ships a popular web browser and every entity that ships certificates trusted in those browsers.

So no one that actually has to renew these certificates.

Hey! How long does a root certificate from a certificate authority last?

10 to 25 years?

Why don't those last 120 minutes? They're responsible for the "security" of the whole internet aren't they?

Re: 6-Day and IP Address Certificates Are Generally Available

#164
post #33

Earlier quoted context omitted.

Very very true, never thought about orgs like that. However, I don't think someone should use this like a bandaid like that. If the idea is that you want to have a domain associated with a service, then organizationally you probably need to have systems in place to make that easier.

Ideally, sure. But in some places you're what you're proposing is like trying to boil the oceans to make a cup of tea VBA et al succeeded because they enabled workers to move forward on things they would otherwise be blocked on organizationally Also - not seeing this kind of thing could be considered a gap in your vision. When outsiders accuse SV of living in a high-tech ivory tower, blind to the realities of more co…

Bruh, I'm not from SV lol. I just don't work at massive orgs.

Re: 6-Day and IP Address Certificates Are Generally Available

#166

Earlier quoted context omitted.

I'm pretty sure that the .org TLD can be shut off by the US at any point in time.

Lets Encrypt do not control the US president. You could argue that The Don in charge of the US is in control of letsencrypt

Yeah, it's a bit far fetched but after Cloudflare CEO basically threatening to cut off Italy I was wondering what would happen if US really invades Greenland.

A simple windows to linux migration is not enough. If certificates expire without a way to refresh you'd either need to manually touch every machine to swap root certificates or have some of other contingency plan.

Re: 6-Day and IP Address Certificates Are Generally Available

#167
post #103

Earlier quoted context omitted.

I'm pretty sure that the .org TLD can be shut off by the US at any point in time.

That’s not relevant though. These CAs will gladly give you a .se/.dk/.in/whatever cert as long as validation passes.

I hope so, but can we really be sure that .se or .de would still work in such a scenario? Is the TLD root management really split up vertically or is the (presumably US-based) TLD parent organization also the final authority for every country TLD?

It would be nice to at least have a very high level contingency plan because in worst case I won't be able to google it.

Re: 6-Day and IP Address Certificates Are Generally Available

#168
post #147

Earlier quoted context omitted.

Which wider world? These changes are coming from the CAB forum, which includes basically every entity that ships a popular web browser and every entity that ships certificates trusted in those browsers. There are use cases for certificates that exist outside of that umbrella, but they are by definition niche.

About 99.99% of people and organisations are neither CAs nor Browsers. Hence they have no representation in the CAB Forum. Hardly 'by definition niche' IMHO.

The pitch here wasn't that only a few people get a vote, it was that the people making the decisions aren't aware of how "the wider world" works. And they are, clearly. The people making Chrome/Firefox and the people running the CAs every publicly-trusted site uses are aware of what their products do, and how they are used.

Re: 6-Day and IP Address Certificates Are Generally Available

#169

It's a huge ask, but i'm hoping they'll implement code-signing certs some day, even if they charge for it. It would be nice if appstores then accepted those certs instead of directly requiring developer verification.

1) For better or worse, code signing certificates are expected to come with some degree of organizational verification. No one would trust a domain-validated code signing cert, especially not one which was issued with no human involvement. 2) App stores review apps because they want to verify functionality and compliance with rules, not just as a box-checking exercise. A code signing cert provides no assurances in th…

They can just do id verification instead of domain, either in-house or outsource it.

app store review isn't what I was talking about, I meant not having to verify your identity with the appstore, and use your own signing cert which can be used between platforms. Moreover, it would be less costly to develop signed windows apps. It costs several hundred dollars today.

Re: 6-Day and IP Address Certificates Are Generally Available

#170
post #147

Earlier quoted context omitted.

Which wider world? These changes are coming from the CAB forum, which includes basically every entity that ships a popular web browser and every entity that ships certificates trusted in those browsers. There are use cases for certificates that exist outside of that umbrella, but they are by definition niche.

>which includes basically every entity that ships a popular web browser and every entity that ships certificates trusted in those browsers. So no one that actually has to renew these certificates. Hey! How long does a root certificate from a certificate authority last? 10 to 25 years? Why don't those last 120 minutes? They're responsible for the "security" of the whole internet aren't they?

It's almost like the threat models for CA and leaf certs are different.
Post reply on HN