Live data from Hacker News

Let's Encrypt had a higher error rate for 90 minutes today

letsencrypt.status.io

31–40 of 115 posts

Re: Let's Encrypt had a higher error rate for 90 minutes today

#31
post #6

What are the viable alternatives to LE? And in case none exists, what does it take to build one? Requirements: free, available to everyone, automation friendly, issues certificates that are actually considered trustworthy by other parties.

This video explores a little on how certificate authorities were given their authority and a lot on how it can fail: https://www.youtube.com/watch?v=M1si1y5lvkk

It's a bit mathy, but if you can make it through that, I highly recommend watching the whole video, especially if you like dad jokes.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#32
Let's Encrypt has been working normally for most of the day. There was a ~90 minute period during which some of our users would have received a higher error rate due to upstream networking issues, but the majority of requests were successful even during that period.

It seems our status.io notes are being misinterpreted as much more severe than they were intended to reflect.

Edit: Note that this was written in response to a previous submission title implying that Let's Encrypt was entirely down most of the day.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#33

That explains why one of my IoT vendors is using an expired certificate. I wish Firefox would just give a mild warning for a recently expired certificate, instead of treating it the same as a true man-in-the-middle attach. It's not like someone who couldn't factor the private key in 200 days could in 201 days or even 300 days. I'm convinced that we'd have better security, if we didn't have so much security theater. Y…

> That explains why one of my IoT vendors is using an expired certificate.

I don't think so. There was a dip in success rates for 90 minutes today, but nobody should be renewing their certificate within 90 minutes of expiration. If you're at that point, something went wrong weeks ago.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#34
post #6

What are the viable alternatives to LE? And in case none exists, what does it take to build one? Requirements: free, available to everyone, automation friendly, issues certificates that are actually considered trustworthy by other parties.

ZeroSSL – free 90-day certs via ACME, also has a web UI for cert management Google Trust Services – free ACME certs, requires a Google account for registration SSL.com Free DV SSL – offers free 90-day certs through ACME

I use acme.sh for certs on my personal server and was a little surprised when it started using ZeroSSL by default. Despite being more "corporate" I decided to roll with it and it's worked just fine.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#35
post #5

To be clear, “Degraded Performance” means just that, not “down.” Let’s Encrypt’s issuance is mostly working fine.

I see you are unfamiliar with status page-ese. “Degraded performance” is a term which means some form of “the entire datacenter is probably on fire”.

A common confusion; this interpretation only applies to OVH.

ref: https://www.reuters.com/article/world/millions-of-websites-o...

Re: Let's Encrypt had a higher error rate for 90 minutes today

#36

That explains why one of my IoT vendors is using an expired certificate. I wish Firefox would just give a mild warning for a recently expired certificate, instead of treating it the same as a true man-in-the-middle attach. It's not like someone who couldn't factor the private key in 200 days could in 201 days or even 300 days. I'm convinced that we'd have better security, if we didn't have so much security theater. Y…

> I wish Firefox would just give a mild warning for a recently expired certificate

Nope, if the SSL industry continues to insist on increasingly short cert lifetimes then I want Firefox to give no quarter when a cert expires.

Play by their rules and fall by their rules too.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#37

That explains why one of my IoT vendors is using an expired certificate. I wish Firefox would just give a mild warning for a recently expired certificate, instead of treating it the same as a true man-in-the-middle attach. It's not like someone who couldn't factor the private key in 200 days could in 201 days or even 300 days. I'm convinced that we'd have better security, if we didn't have so much security theater. Y…

omg new tom7!

Re: Let's Encrypt had a higher error rate for 90 minutes today

#38
post #32

Let's Encrypt has been working normally for most of the day. There was a ~90 minute period during which some of our users would have received a higher error rate due to upstream networking issues, but the majority of requests were successful even during that period. It seems our status.io notes are being misinterpreted as much more severe than they were intended to reflect. Edit: Note that this was written in respons…

I'm not sure if your higher error rate is sticky per user or something, but I've tried 10+ times throughout the day and have had 0 successes. They all come back as internal server error. That's why I eventually posted.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#39
post #10

Earlier quoted context omitted.

I see you are unfamiliar with status page-ese. “Degraded performance” is a term which means some form of “the entire datacenter is probably on fire”.

Although I only post here personally, I work for Let’s Encrypt.

It would be better to say this upfront. I am not blaming you in any way but this would prevent responses such as the parent's (hopefully).

Re: Let's Encrypt had a higher error rate for 90 minutes today

#40

That explains why one of my IoT vendors is using an expired certificate. I wish Firefox would just give a mild warning for a recently expired certificate, instead of treating it the same as a true man-in-the-middle attach. It's not like someone who couldn't factor the private key in 200 days could in 201 days or even 300 days. I'm convinced that we'd have better security, if we didn't have so much security theater. Y…

[deleted]
Post reply on HN