Live data from Hacker News

6-Day and IP Address Certificates Are Generally Available

letsencrypt.org

241–250 of 290 posts

Re: 6-Day and IP Address Certificates Are Generally Available

#241
post #174

Earlier quoted context omitted.

I hope so, but can we really be sure that .se or .de would still work in such a scenario? Is the TLD root management really split up vertically or is the (presumably US-based) TLD parent organization also the final authority for every country TLD? It would be nice to at least have a very high level contingency plan because in worst case I won't be able to google it.

Not sure what the exact concern is here. So far, virtually all countries on Earth are still represented in DNS. Venezuela, Iran, Somalia, etc etc. You can also read a lot of anti-Trump articles and comments on countless web-sites, some under .com and some under other top-domains. As lunatic as Trump is, he hasn’t shut that down. “Is the TLD root management really split up vertically” AFAIK, yes, it is. But if the glo…

Global DNS servers are spread across the world. Most are operated by America but three are operated by Sweden, Japan and Netherlands.

The majority of people use their own ISP or an anycast address from a US company (cloudflare, google, opendns). Quad9 is European.

However any split in the root dns servers signals the end of an interconnected global network. Any ISP can advertise anycast addresses into its own network, so if the US were to be cut off from the world that wouldn't be an issue per-se, but the breakdown of the internet in the western world would be a massive economic shock.

It wouldn't surprise me if it happens in the next decade or two though.

Re: 6-Day and IP Address Certificates Are Generally Available

#242

Earlier quoted context omitted.

Lets Encrypt do not control the US president. You could argue that The Don in charge of the US is in control of letsencrypt

Yeah, it's a bit far fetched but after Cloudflare CEO basically threatening to cut off Italy I was wondering what would happen if US really invades Greenland. A simple windows to linux migration is not enough. If certificates expire without a way to refresh you'd either need to manually touch every machine to swap root certificates or have some of other contingency plan.

Windows (and apple, google, mozilla) trust dozens of root certificates. I've got 148 pems in my /etc/ssl/certs directory on my laptop. 59 are from the US and thus 89 aren't. 10 are from China, 9 Germany, 7 UK. Others are India, Japan, Korea etc.

The far bigger problem is the American government forcing Microsoft/Apple/Google to push out a windows/iphone|mac/android|chrome update which removes all CAs not approved by the American government.

Canonical/Suse may be immune to such overt pressure, but once you get to that point you're way past the end of the international internet and it doesn't really matter anyway.

Re: 6-Day and IP Address Certificates Are Generally Available

#243
post #76

Earlier quoted context omitted.

Makes sense. I assume each of them is in control and at the whims of US president?

> Makes sense. I assume each of them is in control and at the whims of US president? Absolutely not. If the president attempted to force a US-based CA to do something bad they don't want to do, they would sue the government. So far, this administration loses 80% of the lawsuits brought against it.

You're putting a lot of trust in US institutions (courts etc). The rest of the world is starting to see them as not a strong and independent as they were once assumed.

And that's before more overt issues. Microsoft/Google/etc could sue to stop the US ordering them to do what they should. Is the CEO really willing to risk their life to do that? Be a terrible shame if their kids got caught up in a traffic accident.

Re: 6-Day and IP Address Certificates Are Generally Available

#244

Earlier quoted context omitted.

It's actually 6 and 2/3rds! I'm trying to figure out a rationale for 160 hours and similarly coming up empty, if anyone knows I'd be interested. 200 would be a nice round number that gets you to 8 1/3 days, so it comes with the benefits of weekly rotation.

I chose 160 hours. The CA/B Forum defines a "short-lived" certificate as 7 days, which has some reduced requirements on revocation that we want. That time, in turn, was chosen based on previous requirements on OCSP responses. We chose a value that's under the maximum, which we do in general, to make sure we have some wiggle room. https://bugzilla.mozilla.org/show_bug.cgi?id=1715455 is one example of why. Those are ba…

I have always been a bit puzzled by this. By issuing fixed length certificates you practically guarantee oscillation. If you have a massive traffic spike from, say, a CDN mass reissuing after a data breach - you are guaranteed to have the same spike [160 - $renewal_buffer] hours later.

Fuzzing the lifetime of certificates would smooth out traffic, encourage no hardcoded values, and most importantly statistical analysis from CT logs could add confidence that these validity windows are not carefully selected to further a cryptographic or practical attack.

A https://en.wikipedia.org/wiki/Nothing-up-my-sleeve_number if you will.

Re: 6-Day and IP Address Certificates Are Generally Available

#245
post #147

Earlier quoted context omitted.

The push for shorter and shorter cert lifetimes is a really poor idea, and indicates that the people working on these initiatives have no idea how things are done in the wider world.

Which wider world? These changes are coming from the CAB forum, which includes basically every entity that ships a popular web browser and every entity that ships certificates trusted in those browsers. There are use cases for certificates that exist outside of that umbrella, but they are by definition niche.

You're kidding, right? You've never seen a server completely inaccessible just because the owner had trouble renewing the cert? A lot of websites went down this way. And they served static content. Shortening that windows is just asking for trouble.

Re: 6-Day and IP Address Certificates Are Generally Available

#246

It's a huge ask, but i'm hoping they'll implement code-signing certs some day, even if they charge for it. It would be nice if appstores then accepted those certs instead of directly requiring developer verification.

I see how this would be useful once we take binary signing for granted. It would probably even be quite unobjectionable if it were simply a domain binding.

However, the very act of trying to make this system less impractical is a concession in the war on general purpose computing. To subsidize its cost would be to voluntarily loose that non-moral line of argument.

Re: 6-Day and IP Address Certificates Are Generally Available

#247
post #231

Earlier quoted context omitted.

Because it allows to you to work for six days, and rest on the seventh. Like God did.

Didn't the Garden of Eden have a pretty massive vulnerability where eating one apple would give you access to all data on good and evil?

Standard memory disclosure: the apple when eaten would be freed, but it would still be read, leaking its contents. Luckily its volume was low, so they couldn't exfiltrate all of it. But still, the heavens are closed for maintenance, pending a rewrite in Rust.

Re: 6-Day and IP Address Certificates Are Generally Available

#248

Earlier quoted context omitted.

* DoT/DoH * An outer SNI name when doing ECH perhaps * Being able to host secure http/mail/etc without being beholden to a domain registrar

IP addresses arent valid for the SNI used with ECH, even with TLS. On paper I do agree though it would be a decent option should things one day change there.

I think that would have been an alternate present rather than a plausible future.

ECH needs for the outer (unencrypted) SNI to be somewhat plausible as a destination. For ECH GREASE what happens is that this outer SNI was real, what looks like the encrypted inner ECH data is just random noise.

For non-GREASE ECH we want to look as much like the GREASE as we can, except that it's not noise that's the encrypted payload with a real inner SNI among other things.

Re: 6-Day and IP Address Certificates Are Generally Available

#250
post #37

I have now implemented a 2 week renewal interval to test the change to the 45 days, and now they come with a 6-day certificate? This is no criticism, I like what they do, but how am I supposed to do renewals? If something goes wrong, like the pipeline triggering certbot goes wrong, I won't have time to fix this. So I'd be at a two day renewal with a 4 day "debugging" window. I'm certain there are some who need this,…

The push for shorter and shorter cert lifetimes is a really poor idea, and indicates that the people working on these initiatives have no idea how things are done in the wider world.

How are things done in the wider world ?

In your answer (and excluding those using ACME): is this a good behavior (that should be kept) or a lame behavior (that we should aim to improve) ?

Shorter and shorter cert lifetime is a good idea because it is the only way to effectively handle a private key leak. Better idea might exist but nobody found one yet

Post reply on HN