Live data from Hacker News

6-Day and IP Address Certificates Are Generally Available

letsencrypt.org

281–290 of 290 posts

Re: 6-Day and IP Address Certificates Are Generally Available

#282
"forced" short lived certificates sucks so much.

Now you will have an American entity be controlling all your assets that you want online on a very regular basis. No way than calling home regularly. Impossible to manage your own local certificate authority as sub CA without a nightmarish constant process of renewal and distribution.

For security this means that everything will be expected to have almost constant external traffic, RW servers to overwrite the certificates, keys spreaded for that...

And maybe I miss something but would IP address certificate be a nightmare in term of security?

Like when using mobile network or common networks like university networks, it might be very easy to snap certificates for ip shared by multiple unrelated entities. No?

Re: 6-Day and IP Address Certificates Are Generally Available

#283
post #204

Earlier quoted context omitted.

No, they will only give out certificates if you can prove ownership of the IP, which means it being publicly routable.

Sorry, I wasn’t precise enough. I’m at a university and our IP addresses are publicly routable, I think.

Ask Google "what is my IP" and compare it to your DHCP assigned address. If they are different your DHCP address isn't publically routeable.

Re: 6-Day and IP Address Certificates Are Generally Available

#284
post #37

I have now implemented a 2 week renewal interval to test the change to the 45 days, and now they come with a 6-day certificate? This is no criticism, I like what they do, but how am I supposed to do renewals? If something goes wrong, like the pipeline triggering certbot goes wrong, I won't have time to fix this. So I'd be at a two day renewal with a 4 day "debugging" window. I'm certain there are some who need this,…

> Are IP addresses more transient than a domain within a 45 day window? The static IPs you get when you rent a vps, they're not transient. They can be as transient as you want. For example, on AWS, you can release an elastic IP any time you want. So imagine I reserve an elastic IP, then get a 45 day cert for it, then release it immediately. I could repeat this a bunch of times, only renting the IP for a few minutes b…

You could do same trick even for 6 day certificate.

Re: 6-Day and IP Address Certificates Are Generally Available

#285

Earlier quoted context omitted.

The "client cert" requirements were specifically not a CABF rule because that would rule it out for everyone complying with those rules, which is much broader than just the CAs included in Chrome. Some CAs will continue to run PKIs which support client certs, for use outside of Chrome. In general, the "baseline requirements" are intended to be just that: A shared baseline that is met by everyone. All the major root p…

Thanks for chiming in! I remember now that you also said this on the LE community forum. Right, that explains it. So the use would be for things other than websites or for websites that don't need to support Chrome (and also need clientAuth)? I guess I find it hard to wrap my head around this because I don't have experience with any applications where this plus a publicly trusted certificate makes sense. But I suppos…

Are you asking why an HTTPS server would need to use client auth outside of the browser? The answer is mTLS. If you want to use one cert for your one domain to serve both "normal" browser content and HTTPS APIs with mTLS, your cert needs to be able to do it all.

Re: 6-Day and IP Address Certificates Are Generally Available

#286
post #267

Earlier quoted context omitted.

I don't understand where the argument is. Being able to publish content that others can authenticate and then trust sounds like a huge win to me. I don't even see why it has to be restricted to code. It's just verifying who the signer is. More trusted systems and more progress happens when we trust the foundations we're building. I don't think that's a war on general purpose computing. I feel like there is this older…

Technologies cannot be normatively evaluated without considering the power structures they facilitate. Consider secure boot; assuming it's properly implemented, could defend against an entire class of attacks—evil maid: if a third party physically compromises your machine while you're away to install malware, you'd be alerted or stopped from booting the modified image. This is a technical statement. Now whose keys ar…

I think you're changing the topic here. But i'll bite a bit, we're talking about let's encrypt here, so for every argument you made, it would be let's encrypt issuing the certificates. All the "open source" use cases you have can also be supported by them.

The whole point of let's encrypt doing this would be to reduce the fees for open source devs and poor devs in general. But ultimately, software published to the public is a matter of consumer safety and welfare. to that end, if you have a solution that enables operating systems to authenticate and review software before consumers are exposed to it, feel free to suggest an alternative, short of that, too bad for the open source dev. Nothing stoping you from using alternative devices. You don't have any entitlement over operatins systems or hardware sold to the public. The needs of software developers as a whole is not important in the slightest bit when it comes to consumer devices and software. Just the same as the plumbers needs are irrelevant when it comes to evaluating the safety of water and sewage pipes, or the construction person's needs are irrelevant when it comes to evaluating the safety of the building they're working on.

If construction worker claims they don't need regulatory certified construction materials because that means random people building cabins in the woods can't sell their house, too bad right? They can still build their own cabin and live in it, but to sell the cabin house it must pass inspection (fees), zoning requirements, accessibility and fire safety requirements,etc.. why is your software dev industry so special?

And yes, microsoft and google get to police things, just like in every other regulated industry there are professional certification boards. You need to pass the law BAR to be a lawyer, you need to pass the medicine BAR to practice medicine on the public. And those BAR associations are made up of industry leaders. Nothing prevents you from going to medical school and treating your own self without passing the BAR. Nothing stops you from writing your own software and using it. but when other people use it, they expect the government to keep them safe from malpractice and harm, that supersedes any needs or desires you may have for open source. You can even argue that it should be free, and that's the whole point of this, let's encrypt made TLS certs free, maybe it can make code signing/dev auth free too! But if it doesn't ,i consider it gross incompetence and dereliction of duty, if the government doesn't require software signing and secure boot on every consumer accessible software system.

Re: 6-Day and IP Address Certificates Are Generally Available

#287

Earlier quoted context omitted.

Thanks for chiming in! I remember now that you also said this on the LE community forum. Right, that explains it. So the use would be for things other than websites or for websites that don't need to support Chrome (and also need clientAuth)? I guess I find it hard to wrap my head around this because I don't have experience with any applications where this plus a publicly trusted certificate makes sense. But I suppos…

Are you asking why an HTTPS server would need to use client auth outside of the browser? The answer is mTLS. If you want to use one cert for your one domain to serve both "normal" browser content and HTTPS APIs with mTLS, your cert needs to be able to do it all.

The server that wants to authenticate clients via mTLS doesn't need the clientAuth EKU on its certificate, only the clients do.

Most of the time you set up mTLS by creating your own self-signed certificate and verifying that the client has that cert (or one that chains up to it). I'm wondering what systems exist that need a publicly trusted cert with clientAuth.

Only think I've heard of so far is XMPP for server-to-server auth, but there are alternative auth methods it supports.

Re: 6-Day and IP Address Certificates Are Generally Available

#289

Earlier quoted context omitted.

> Makes sense. I assume each of them is in control and at the whims of US president? Absolutely not. If the president attempted to force a US-based CA to do something bad they don't want to do, they would sue the government. So far, this administration loses 80% of the lawsuits brought against it.

You're putting a lot of trust in US institutions (courts etc). The rest of the world is starting to see them as not a strong and independent as they were once assumed. And that's before more overt issues. Microsoft/Google/etc could sue to stop the US ordering them to do what they should. Is the CEO really willing to risk their life to do that? Be a terrible shame if their kids got caught up in a traffic accident.

> You're putting a lot of trust in US institutions (courts etc)

I don't have a lot of trust in US institutions actually. The most powerful universities, corporations and law firms have capitulated to him.

So far, the tech companies have placated Trump by contributing to his causes and heaping praise upon him and not speaking out regarding the tariffs. That's enough for now.

> Is the CEO really willing to risk their life to do that?

We're not at that point; at least not so far. Besides, it's much easier to blackmail them for more money or for the Department of Justice to open an investigation or to stop a merger they want to do.

Also these companies aren't just sitting around doing nothing. Apple reworked their supply chain; all iPhones sold in the US are now made in India.

Re: 6-Day and IP Address Certificates Are Generally Available

#290

Earlier quoted context omitted.

They can just do id verification instead of domain, either in-house or outsource it. app store review isn't what I was talking about, I meant not having to verify your identity with the appstore, and use your own signing cert which can be used between platforms. Moreover, it would be less costly to develop signed windows apps. It costs several hundred dollars today.

Azure has a service ('Artifact Signing') which is $10/month for signing Windows executables (not Windows Store apps, which don't need it.) That's pretty reasonable, considering it is built in to all the major code signing tools on Windows, they perform the identity verification, and the private keys are fully managed by Azure. Code signing certs are required to be on HSMs, so you're most likely going to be paying som…

Hey, how long did the identity validation take?
Post reply on HN