Live data from Hacker News

Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

letsencrypt.status.io

31–40 of 97 posts

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#31
post #11

Earlier quoted context omitted.

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong. If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.

You're holding your 6-day cert wrong

Chill, it's 2 hours. They recommend renewing at the first third of the 160 hrs.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#32
post #16

Earlier quoted context omitted.

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong. If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.

Short-lived = 6 days. Even if you reissue after 2 or 3 days, that's… not a lot of breathing room.

3-4 days is a ton of breathing room

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#33
post #16

Earlier quoted context omitted.

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong. If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.

Short-lived = 6 days. Even if you reissue after 2 or 3 days, that's… not a lot of breathing room.

You have to opt in, and they are honest about the tradeoffs when discussing them:

> Short-lived certificates are opt-in and we have no plan to make them the default at this time. Subscribers that have fully automated their renewal process should be able to switch to short-lived certificates easily if they wish, but we understand that not everyone is in that position and generally comfortable with this significantly shorter lifetime. We hope that over time everyone moves to automated solutions and we can demonstrate that short-lived certificates work well.

https://letsencrypt.org/2026/01/15/6day-and-ip-general-avail...

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#35

That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now. Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuan…

Considering the open source nature of Letsencrypt, I wonder what the barriers/costs would be (theoretically) to a wealthy benefactor who wanted to duplicate its server side infrastructure and a core staffing level of persons, and fund a "parallel" equally trusted, alternative entity with a solid governing board. Same general idea how Acton funded the Signal foundation. Somewhere that none of the physical infrastructu…

[dead]

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#36

That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now. Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuan…

I just find it incredible that in 30+ years the industry hasn't adapted one bit to the brittle failure modes of certificates. I did some subcontract work with Verisign to deploy their CA infrastructure back in the early oughties and it felt like a solution was overdue way back then. I was at Google in the teensies when gmail broke due to expired SMTP certs. WAAAY overdue by then. Here we are, a decade later and it's still the same lol.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#37
post #24

Earlier quoted context omitted.

"We have been made aware of a potential incident and are shutting down all issuance" seems to lean towards the latter and not simply a technical issue :(

Josh Aas is on the thread. It's a compliance issue, they expect to be issuing shortly.

What if they get kicked out of trusted roots because non-compliant ?

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#39
post #4

There is one little-discussed down side to ever shorter-lived certificates...

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong. If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.

[deleted]
Post reply on HN