Live data from Hacker News

Our First Certificate Is Now Live

letsencrypt.org

31–40 of 263 posts

Re: Our First Certificate Is Now Live

#31

Earlier quoted context omitted.

Incorrect. Inclusion into the Firefox root store is being tracked in https://bugzil.la/1204656 and has not yet been resolved. Firefox trusts the cert on TFA because letsencrypt.org itself is using a certificate signed by IdenTrust.

Looking at http://helloworld.letsencrypt.org/ I see: > Let's Encrypt hasn't yet been added as a trusted authority to the major browsers (that will be happening soon), so for now, you'll need to add the ISRG root certificate yourself. Specifics will depend on your browser. In Firefox, just click the link.

the iSRG root is not in FF[1][2]...you're visiting the http version of that URL.

1 http://idzr.org/y1pg

2 http://idzr.org/ee91

Re: Our First Certificate Is Now Live

#32

Earlier quoted context omitted.

Incorrect. Inclusion into the Firefox root store is being tracked in https://bugzil.la/1204656 and has not yet been resolved. Firefox trusts the cert on TFA because letsencrypt.org itself is using a certificate signed by IdenTrust.

Looking at http://helloworld.letsencrypt.org/ I see: > Let's Encrypt hasn't yet been added as a trusted authority to the major browsers (that will be happening soon), so for now, you'll need to add the ISRG root certificate yourself. Specifics will depend on your browser. In Firefox, just click the link.

Ah, that is a bit misleading. When it says "just click the link," it's referring to the process for installing the root certificate.

It should read "specifics will depend on your browser. In Firefox, just click the link [to the .der file, and you will see a prompt allowing you to trust it.]" It looks like this: http://imgur.com/dzC89xI

Without importing the root, Firefox absolutely distrusts https://helloworld.letsencrypt.org/, and will do so until Bug 1204656 is marked RESOLVED FIXED. :)

Re: Our First Certificate Is Now Live

#33

Earlier quoted context omitted.

> This is not what regular style certificates verify. That is what Extended Validation certificates verify and they're not issued by letsencrypt.org and generally are a lot more expensive. I'd like to see LetsEncrypt move into this territory though. What current private business providers are charging for this service is border-line extortion.

But the certificate is (supposed) to say we have verified that this person / organisation exists and is "allowed" this domain. Now if we extend the idea of every business or even human having their own (sub)-domain (lots of good benefits there) then we are in the territory of ensuring the CA's track you from birth - that's what governments do, and boy are they expensive. I think what I am saying is we either have CA…

That ship has sailed years ago. And now we have EV certificates to deal with that problem.

Re: Our First Certificate Is Now Live

#34

This is a tiny bit odd. So they have issued their first certificate, but they don't have cross-signing in place yet? So between now and november 16th they'll be issuing a whole bunch of effectively broken certificates unless people manually install their root CA? Why even push this today if you don't have cross-signing available? Without that Let's Encrypt is effectively broken out of the box. PS - I actually like Le…

We need to demonstrate proper issuance under our root and gain confidence in our live systems before getting cross-signed. Issuing without a cross-signature for a bit is how we do this.

Re: Our First Certificate Is Now Live

#36
post #23

Everyone repeat after me, wildcards, wildcards, wildcards. (just hoping they will appear next year) One more nail in the coffin of the ssl cert mafia.

The major problem with this is that the IETF validation working group hasn't come up with a definite procedure for deciding what the apex of a domain is, and how to validate control over all subdomains above it yet.

Re: Our First Certificate Is Now Live

#37
post #23

Everyone repeat after me, wildcards, wildcards, wildcards. (just hoping they will appear next year) One more nail in the coffin of the ssl cert mafia.

They won't support those on launch?

Altough because of SNI (https://en.wikipedia.org/wiki/Server_Name_Indication) the need for wildcard certificates has greatly diminished.

Re: Our First Certificate Is Now Live

#38
post #29

Earlier quoted context omitted.

Incorrect. Inclusion into the Firefox root store is being tracked in https://bugzil.la/1204656 and has not yet been resolved. Firefox trusts the cert on TFA because letsencrypt.org itself is using a certificate signed by IdenTrust.

Hmm, that's taking a long time assuming Mozilla itself is involved in the project.

My understanding is that Mozilla is primarily just a sponsor of ISRG, the non-profit behind Let's Encrypt. Some of their sponsorship includes dedicated engineering time, but LetsEncrypt still has to pass all the same audits and requirements as any other CA, as defined in the Mozilla CA Certificate Policy at https://www.mozilla.org/en-US/about/governance/policies/secu....

Mozilla's not a nepotist with regard to its root store. :-)

Re: Our First Certificate Is Now Live

#39
post #23

Everyone repeat after me, wildcards, wildcards, wildcards. (just hoping they will appear next year) One more nail in the coffin of the ssl cert mafia.

The major problem with this is that the IETF validation working group hasn't come up with a definite procedure for deciding what the apex of a domain is, and how to validate control over all subdomains above it yet.

Doesn't ownership of domain.tld also imply ownership of *.domain.tld?

Re: Our First Certificate Is Now Live

#40

Earlier quoted context omitted.

But the certificate is (supposed) to say we have verified that this person / organisation exists and is "allowed" this domain. Now if we extend the idea of every business or even human having their own (sub)-domain (lots of good benefits there) then we are in the territory of ensuring the CA's track you from birth - that's what governments do, and boy are they expensive. I think what I am saying is we either have CA…

That ship has sailed years ago. And now we have EV certificates to deal with that problem.

For the time being, it's DNS registrars who define who is allowed particular domain names, and DV CAs just try to draw the connection between what the registrars have said and the server you're visiting at a particular moment.
Post reply on HN