I have now implemented a 2 week renewal interval to test the change to the 45 days, and now they come with a 6-day certificate? This is no criticism, I like what they do, but how am I supposed to do renewals? If something goes wrong, like the pipeline triggering certbot goes wrong, I won't have time to fix this. So I'd be at a two day renewal with a 4 day "debugging" window. I'm certain there are some who need this,…
What worries me more about the push for shorter and shorter cert terms instead of making revoking that works is that if provider fails now you have very little time to switch to new one
6-Day and IP Address Certificates Are Generally Available
191–200 of 290 posts
Re: 6-Day and IP Address Certificates Are Generally Available
#192Re: 6-Day and IP Address Certificates Are Generally Available
#193Earlier quoted context omitted.
You're not thinking creatively enough. I'm only interested in ESP, not IKE. Consider having the TLS handshake negotiate the use of ESP, and when selected the system would plumb ESP for this connection using keys negotiated by TLS (using the exporter). Think ktls/kssl but with ESP. Presto -- no orchestration of IKE credentials, nothing -- it should just work. The real key is getting ESP HW offload.
Oh I agree with it being nice, I'm just imagining more socialization oriented resistance to implementation and both large organizations and hobbyists already have answers that mostly cover the use cases even if not exactly as cleanly. Moving node to node encryption to an accelerated implementation of transport mode would be great, but if you're already using TLS I can see people just sticking in TLS versus hoping bot…
Re: 6-Day and IP Address Certificates Are Generally Available
#194Has anyone actually given a good explanation as to why TLS Client Auth is being removed?
Re: 6-Day and IP Address Certificates Are Generally Available
#195Earlier quoted context omitted.
No, they will only give out certificates if you can prove ownership of the IP, which means it being publicly routable.
Finally a reason to adopt IPv6 for your local development
Re: 6-Day and IP Address Certificates Are Generally Available
#196Earlier quoted context omitted.
>so still no way to support TLS for LAN devices without manual setup or angering security researchers. Arguably setting up letsencrypt is "manual setup". What you can do is run a split-horizon DNS setup inside your LAN on an internet-routable tld, and then run a CA for internal devices. That gives all your internal hosts their own hostname.sub.domain.tld name with HTTPS. Frankly: it's not that much more work, and it'…
> run a CA > easier than remembering IP addresses idk, the 192.168.0 part has been around since forever. The rest is just a matter of .12 for my laptop, .13 for the one behind the telly, .14 for the pi, etc. Every time I try to "run a CA", I start splitting hairs.
1. Running a CA is more work than just setting up certbot for IP addresses, but not that much more
And that enables you to
2. Remember only domain names, which is easier than ip addresses.
I guess if you're ipv4 only and small it's not much benefit but if you have a big or bridged network like wonderLAN or the promised LAN it's much better.
Re: 6-Day and IP Address Certificates Are Generally Available
#197Earlier quoted context omitted.
For example HTTP/2 and HTTP/3 require HTTPS. While technically HTTPS is redundant, .onion sites should avoid requiring browsers to add special casing for them due to their low popularity compared to regular web sites.
What are benefits of HTTP/2 and HTTP/3 for Tor hidden service traffic?
Re: 6-Day and IP Address Certificates Are Generally Available
#198Earlier quoted context omitted.
Which wider world? These changes are coming from the CAB forum, which includes basically every entity that ships a popular web browser and every entity that ships certificates trusted in those browsers. There are use cases for certificates that exist outside of that umbrella, but they are by definition niche.
>which includes basically every entity that ships a popular web browser and every entity that ships certificates trusted in those browsers. So no one that actually has to renew these certificates. Hey! How long does a root certificate from a certificate authority last? 10 to 25 years? Why don't those last 120 minutes? They're responsible for the "security" of the whole internet aren't they?
I believe google, who maintain chrome and are on the CAB, are an entity well known for hosting various websites (iirc, it's their primary source of income), and those websites do use https
Re: 6-Day and IP Address Certificates Are Generally Available
#199Earlier quoted context omitted.
Exactly -- how many 192.168.0.1 certs do you think LetsEncrypt wants to issue?
The BRs specifically forbid issuing such a certificate since 2015. So, slightly before they were required to stop using SHA-1, slight after they were forbidden from issuing certificates for nonsense like .com or .ac.uk which obviously shouldn't be available to anybody even if they do insist they somehow "own" these names.
Re: 6-Day and IP Address Certificates Are Generally Available
#200As a concrete example, I'll probably be able to turn off bootstrap domains for TakingNames[0].