That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now. Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuan…
Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
21–30 of 97 posts
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#22That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now. Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuan…
And donation supported no less
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#23There is one little-discussed down side to ever shorter-lived certificates...
Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong. If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#24Hopefully it's just a technical issue and not something like a key compromise. This could have disastrous effects considering how much of the web runs on LE certs these days. Granted if it's configured properly everyone should have 30 days of leeway before having to issue new certs...
"We have been made aware of a potential incident and are shutting down all issuance" seems to lean towards the latter and not simply a technical issue :(
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#25There is one little-discussed down side to ever shorter-lived certificates...
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#26Earlier quoted context omitted.
Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong. If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.
You're holding your 6-day cert wrong
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#27Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#28This is a compliance incident, we should be issuing again shortly. Update: Issuance is back up. Update: Preliminary incident report: https://bugzilla.mozilla.org/show_bug.cgi?id=2038351
Uh. I don't know if I like the sound of that...
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#29Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#30This is a compliance incident, we should be issuing again shortly. Update: Issuance is back up. Update: Preliminary incident report: https://bugzilla.mozilla.org/show_bug.cgi?id=2038351