Live data from Hacker News

6-Day and IP Address Certificates Are Generally Available

letsencrypt.org

211–220 of 290 posts

Re: 6-Day and IP Address Certificates Are Generally Available

#211

Why 6 day and not 8? - 8 is a lucky number and a power of 2 - 8 lets me refresh weekly and have a fixed day of the week to check whether there was some API 429 timeout - 6 is the value of every digit in the number of the beast - I just don't like 6!

> 8 lets me refresh weekly and have a fixed day of the week to check whether there was some API 429 timeout There’s your answer. 6 days means on a long enough enough timeframe the load will end up evenly distributed across a week. 8 days would result in things getting hammered on specific days of the week.

I thought people generally run it daily? It’s a no-op if it doesn’t need renewal.

Re: 6-Day and IP Address Certificates Are Generally Available

#212

Earlier quoted context omitted.

> No dependency on a registrar sounds nice. Actually the main benefit is no dependency on DNS (booth direct and root). IP is a simple primitive, i.e. "is it routable or not ?".

The popular HTTP validation method has the same drawback whether using DNS or IP certificates? Namely, if you can compromise routes to hijack traffic, you can also hijack the validation requests. Right?

Yes, there have been cases where this has happened (https://notes.valdikss.org.ru/jabber.ru-mitm/), but it's really now into the realm of

1) How to secure routing information: some says RPKI, some argues that's not enough and are experimenting with something like SCION (https://docs.scion.org/en/latest/)

2) Principal-Agent problem: jabber.ru's hijack relied on (presumably) Hetzner being forced to do it by German law agents based on the powers provided under the German Telecommunications Act (TKG)

Re: 6-Day and IP Address Certificates Are Generally Available

#213

Earlier quoted context omitted.

All major root store programs (Chrome, Apple, Microsoft, Mozilla) have this power. They set the requirements that CAs must follow to be included in their root store, and for most CAs their certs would be useless if they aren't included in all major ones. I don't think the root programs take these kind of decisions lightly and I don't see any selfish motives they could have. They need to find a balance between not ove…

The "client cert" requirements were specifically not a CABF rule because that would rule it out for everyone complying with those rules, which is much broader than just the CAs included in Chrome. Some CAs will continue to run PKIs which support client certs, for use outside of Chrome. In general, the "baseline requirements" are intended to be just that: A shared baseline that is met by everyone. All the major root p…

Thanks for chiming in! I remember now that you also said this on the LE community forum.

Right, that explains it. So the use would be for things other than websites or for websites that don't need to support Chrome (and also need clientAuth)?

I guess I find it hard to wrap my head around this because I don't have experience with any applications where this plus a publicly trusted certificate makes sense. But I suppose they must exist, otherwise there would've been an effort to vote it into the BRs.

If you or someone else here knows more about these use cases, then I'd like to hear about it to better understand this.

Re: 6-Day and IP Address Certificates Are Generally Available

#215

Earlier quoted context omitted.

1) For better or worse, code signing certificates are expected to come with some degree of organizational verification. No one would trust a domain-validated code signing cert, especially not one which was issued with no human involvement. 2) App stores review apps because they want to verify functionality and compliance with rules, not just as a box-checking exercise. A code signing cert provides no assurances in th…

They can just do id verification instead of domain, either in-house or outsource it. app store review isn't what I was talking about, I meant not having to verify your identity with the appstore, and use your own signing cert which can be used between platforms. Moreover, it would be less costly to develop signed windows apps. It costs several hundred dollars today.

Azure has a service ('Artifact Signing') which is $10/month for signing Windows executables (not Windows Store apps, which don't need it.)

That's pretty reasonable, considering it is built in to all the major code signing tools on Windows, they perform the identity verification, and the private keys are fully managed by Azure. Code signing certs are required to be on HSMs, so you're most likely going to be paying some cloud CA anyway.

Re: 6-Day and IP Address Certificates Are Generally Available

#217

Why 6 day and not 8? - 8 is a lucky number and a power of 2 - 8 lets me refresh weekly and have a fixed day of the week to check whether there was some API 429 timeout - 6 is the value of every digit in the number of the beast - I just don't like 6!

Six is the smallest perfect number. Perfection is key here.

Re: 6-Day and IP Address Certificates Are Generally Available

#218
post #152
post #123

Earlier quoted context omitted.

Worry not, cause it's not 6 days (144 hours), it is 6-ish days: 160 hours And 160 is the sum of the first 11 primes, as well as the sum of the cubes of the first three primes!

Mr Ramanujan, I presume?

Every K-Paxian knows this.

Re: 6-Day and IP Address Certificates Are Generally Available

#219
post #168

Earlier quoted context omitted.

About 99.99% of people and organisations are neither CAs nor Browsers. Hence they have no representation in the CAB Forum. Hardly 'by definition niche' IMHO.

The pitch here wasn't that only a few people get a vote, it was that the people making the decisions aren't aware of how "the wider world" works. And they are, clearly. The people making Chrome/Firefox and the people running the CAs every publicly-trusted site uses are aware of what their products do, and how they are used.

They're aware of the major use cases. I doubt the minority cases are even on their radar.

So great for E-Commerce, not so great for anyone else.

Re: 6-Day and IP Address Certificates Are Generally Available

#220
post #129

Earlier quoted context omitted.

Because it allows to you to work for six days, and rest on the seventh. Like God did.

² By the seventh day God had finished the work He had been doing; so on the seventh day He rested from all His work. ³ Then the on-call tech, Lucifer, the Son of Dawn, was awoken at midnight because God did not renew the heavens' and the earths' HTTPS certificate. ⁴ Thusly Lucifer drafted his resignation in a great fury.

I just got home from a stressful day in retail (oh who am I kidding; every day is stress in retail) and this gave me a chuckle I really needed. Thank you.
Post reply on HN