Earlier quoted context omitted.
Incorrect. Inclusion into the Firefox root store is being tracked in https://bugzil.la/1204656 and has not yet been resolved. Firefox trusts the cert on TFA because letsencrypt.org itself is using a certificate signed by IdenTrust.
Looking at http://helloworld.letsencrypt.org/ I see: > Let's Encrypt hasn't yet been added as a trusted authority to the major browsers (that will be happening soon), so for now, you'll need to add the ISRG root certificate yourself. Specifics will depend on your browser. In Firefox, just click the link.
Our First Certificate Is Now Live
31–40 of 263 posts
Re: Our First Certificate Is Now Live
#32Earlier quoted context omitted.
Incorrect. Inclusion into the Firefox root store is being tracked in https://bugzil.la/1204656 and has not yet been resolved. Firefox trusts the cert on TFA because letsencrypt.org itself is using a certificate signed by IdenTrust.
Looking at http://helloworld.letsencrypt.org/ I see: > Let's Encrypt hasn't yet been added as a trusted authority to the major browsers (that will be happening soon), so for now, you'll need to add the ISRG root certificate yourself. Specifics will depend on your browser. In Firefox, just click the link.
It should read "specifics will depend on your browser. In Firefox, just click the link [to the .der file, and you will see a prompt allowing you to trust it.]" It looks like this: http://imgur.com/dzC89xI
Without importing the root, Firefox absolutely distrusts https://helloworld.letsencrypt.org/, and will do so until Bug 1204656 is marked RESOLVED FIXED. :)
Re: Our First Certificate Is Now Live
#33Earlier quoted context omitted.
> This is not what regular style certificates verify. That is what Extended Validation certificates verify and they're not issued by letsencrypt.org and generally are a lot more expensive. I'd like to see LetsEncrypt move into this territory though. What current private business providers are charging for this service is border-line extortion.
But the certificate is (supposed) to say we have verified that this person / organisation exists and is "allowed" this domain. Now if we extend the idea of every business or even human having their own (sub)-domain (lots of good benefits there) then we are in the territory of ensuring the CA's track you from birth - that's what governments do, and boy are they expensive. I think what I am saying is we either have CA…
Re: Our First Certificate Is Now Live
#34This is a tiny bit odd. So they have issued their first certificate, but they don't have cross-signing in place yet? So between now and november 16th they'll be issuing a whole bunch of effectively broken certificates unless people manually install their root CA? Why even push this today if you don't have cross-signing available? Without that Let's Encrypt is effectively broken out of the box. PS - I actually like Le…
Re: Our First Certificate Is Now Live
#35https://letsencrypt.org/howitworks/
I'd actually pay more than I do now for SSL certs to get that kind of simplicity.
Re: Our First Certificate Is Now Live
#36Everyone repeat after me, wildcards, wildcards, wildcards. (just hoping they will appear next year) One more nail in the coffin of the ssl cert mafia.
Re: Our First Certificate Is Now Live
#37Everyone repeat after me, wildcards, wildcards, wildcards. (just hoping they will appear next year) One more nail in the coffin of the ssl cert mafia.
Altough because of SNI (https://en.wikipedia.org/wiki/Server_Name_Indication) the need for wildcard certificates has greatly diminished.
Re: Our First Certificate Is Now Live
#38Earlier quoted context omitted.
Incorrect. Inclusion into the Firefox root store is being tracked in https://bugzil.la/1204656 and has not yet been resolved. Firefox trusts the cert on TFA because letsencrypt.org itself is using a certificate signed by IdenTrust.
Hmm, that's taking a long time assuming Mozilla itself is involved in the project.
Mozilla's not a nepotist with regard to its root store. :-)
Re: Our First Certificate Is Now Live
#39Everyone repeat after me, wildcards, wildcards, wildcards. (just hoping they will appear next year) One more nail in the coffin of the ssl cert mafia.
The major problem with this is that the IETF validation working group hasn't come up with a definite procedure for deciding what the apex of a domain is, and how to validate control over all subdomains above it yet.
Re: Our First Certificate Is Now Live
#40Earlier quoted context omitted.
But the certificate is (supposed) to say we have verified that this person / organisation exists and is "allowed" this domain. Now if we extend the idea of every business or even human having their own (sub)-domain (lots of good benefits there) then we are in the territory of ensuring the CA's track you from birth - that's what governments do, and boy are they expensive. I think what I am saying is we either have CA…
That ship has sailed years ago. And now we have EV certificates to deal with that problem.