Live data from Hacker News

Let’s Encrypt DST Root CA X3 Expiration – September 2021

letsencrypt.org

21–30 of 72 posts

Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021

#21
post #20
post #9

Earlier quoted context omitted.

Many enterprises use a FIPS SSL proxy for all employees web traffic, so all websites with these lets encrypt will effectively be invalidated if the proxies are using openssl FIPs modules, same for FIPS client side applications

I guess that will give them an incentive to fix those devices quickly.

Ha, good one. For the average company that breaks SSL, I expect something like this instead: "new corporate policy update: for security reasons, you're no longer allowed to visit HTTPS Web sites that use Let's Encrypt. If the Web site you want to visit still allows HTTP, that continues to be acceptable."

Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021

#22
post #6
post #3

Earlier quoted context omitted.

and a bad thing for e-waste.

Devices that can’t be updated all face an early ewaste destiny, don’t blame expiring certs.

My dad had to replace his working but older Motorola phone because MMS stopped working because of outdated certs and he couldn't update anything to get them working again.

Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021

#23
post #20

Earlier quoted context omitted.

I guess that will give them an incentive to fix those devices quickly.

Ha, good one. For the average company that breaks SSL, I expect something like this instead: "new corporate policy update: for security reasons, you're no longer allowed to visit HTTPS Web sites that use Let's Encrypt. If the Web site you want to visit still allows HTTP, that continues to be acceptable."

Ain't gonna happen. Let's Encrypt is too big to be ignored.

You can't practically use the web like that.

Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021

#24

Is there another provider that could be an alternative to this? (zerossl maybe?)

Basically ZeroSSL and Buypass, yes. Buypass certificates have the additional benefit of being valid for 180 days. The rate limits are a bit stricter than with Let's Encrypt, I believe: https://www.buypass.com/ssl/resources/go-ssl-technical-speci...

I assume they are more trusted by older devices than Let's Encrypt. Source?

Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021

#26
post #23

Earlier quoted context omitted.

Ha, good one. For the average company that breaks SSL, I expect something like this instead: "new corporate policy update: for security reasons, you're no longer allowed to visit HTTPS Web sites that use Let's Encrypt. If the Web site you want to visit still allows HTTP, that continues to be acceptable."

Ain't gonna happen. Let's Encrypt is too big to be ignored. You can't practically use the web like that.

We know this, but I don't think everyone does. I'm sure that at least some places will learn this the hard way.

Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021

#27
post #3

Earlier quoted context omitted.

and a bad thing for e-waste.

To a point. The environmental footprint of a 486 tower system today would be much higher than modern system because the humans that use it more slowly and who have to maintain it use a lot more resources.

Given lightweight software, a 486 tower is usable indefinitely with a zero environmental footprint as long as the electricity comes from a sustainable source (such as solar).

Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021

#29
post #9

Earlier quoted context omitted.

Many enterprises use a FIPS SSL proxy for all employees web traffic, so all websites with these lets encrypt will effectively be invalidated if the proxies are using openssl FIPs modules, same for FIPS client side applications

It seems quite silly to me to enforce a massive MitM attack while at the same time sticking to the FIPS standards. Then again, a lot of governmental and financial security requirements are nonsensical to me, like mandatory password changes. When I, as a website host, need to choose between accepting millions of Android devices or a few organizations with an esoteric security configuration, I'll go for the Android dev…

> It seems quite silly to me to enforce a massive MitM attack while at the same time sticking to the FIPS standards.

Well they're two different things. One is an often government-mandated security standard. The other is a business requirement to be able to audit network traffic, which is also often a government-mandated requirement (due to regulations, due diligence, contractual requirements, etc).

People making tech stuff very often forget that the entire world does not work based on "technical best practices", it works on laws and contracts and customer/business requirements. In the real world there is often no perfect way to satisfy all requirements.

Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021

#30
post #23

Earlier quoted context omitted.

Ain't gonna happen. Let's Encrypt is too big to be ignored. You can't practically use the web like that.

We know this, but I don't think everyone does. I'm sure that at least some places will learn this the hard way.

They will just add an additional TLS proxy with a self-signed cert that ignores all validation. Security will be broken but users will be able to continue to do their work.
Post reply on HN