Earlier quoted context omitted.
Many enterprises use a FIPS SSL proxy for all employees web traffic, so all websites with these lets encrypt will effectively be invalidated if the proxies are using openssl FIPs modules, same for FIPS client side applications
I guess that will give them an incentive to fix those devices quickly.
Let’s Encrypt DST Root CA X3 Expiration – September 2021
21–30 of 72 posts
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#22Earlier quoted context omitted.
and a bad thing for e-waste.
Devices that can’t be updated all face an early ewaste destiny, don’t blame expiring certs.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#23Earlier quoted context omitted.
I guess that will give them an incentive to fix those devices quickly.
Ha, good one. For the average company that breaks SSL, I expect something like this instead: "new corporate policy update: for security reasons, you're no longer allowed to visit HTTPS Web sites that use Let's Encrypt. If the Web site you want to visit still allows HTTP, that continues to be acceptable."
You can't practically use the web like that.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#24Is there another provider that could be an alternative to this? (zerossl maybe?)
Basically ZeroSSL and Buypass, yes. Buypass certificates have the additional benefit of being valid for 180 days. The rate limits are a bit stricter than with Let's Encrypt, I believe: https://www.buypass.com/ssl/resources/go-ssl-technical-speci...
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#25Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#26Earlier quoted context omitted.
Ha, good one. For the average company that breaks SSL, I expect something like this instead: "new corporate policy update: for security reasons, you're no longer allowed to visit HTTPS Web sites that use Let's Encrypt. If the Web site you want to visit still allows HTTP, that continues to be acceptable."
Ain't gonna happen. Let's Encrypt is too big to be ignored. You can't practically use the web like that.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#27Earlier quoted context omitted.
and a bad thing for e-waste.
To a point. The environmental footprint of a 486 tower system today would be much higher than modern system because the humans that use it more slowly and who have to maintain it use a lot more resources.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#28I wish Let's Encrypt had a plan to get cross-signed by a CA those older devices still trust.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#29Earlier quoted context omitted.
Many enterprises use a FIPS SSL proxy for all employees web traffic, so all websites with these lets encrypt will effectively be invalidated if the proxies are using openssl FIPs modules, same for FIPS client side applications
It seems quite silly to me to enforce a massive MitM attack while at the same time sticking to the FIPS standards. Then again, a lot of governmental and financial security requirements are nonsensical to me, like mandatory password changes. When I, as a website host, need to choose between accepting millions of Android devices or a few organizations with an esoteric security configuration, I'll go for the Android dev…
Well they're two different things. One is an often government-mandated security standard. The other is a business requirement to be able to audit network traffic, which is also often a government-mandated requirement (due to regulations, due diligence, contractual requirements, etc).
People making tech stuff very often forget that the entire world does not work based on "technical best practices", it works on laws and contracts and customer/business requirements. In the real world there is often no perfect way to satisfy all requirements.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#30Earlier quoted context omitted.
Ain't gonna happen. Let's Encrypt is too big to be ignored. You can't practically use the web like that.
We know this, but I don't think everyone does. I'm sure that at least some places will learn this the hard way.