Live data from Hacker News

10 Years of Let's Encrypt

letsencrypt.org

331–340 of 361 posts

Re: 10 Years of Let's Encrypt

#331

Earlier quoted context omitted.

Caddy's way of using plugins seems to require building custom binaries, may I know if that's what you did? I preferred to use wildcard certs, which requires a plugin for the dns

Well, I use Arch Linux and the caddy package from pacman just works. You may checkout https://github.com/caddyserver/xcaddy for custom caddy build. Besides, I don't use wildcard certs. I use caddy to reverse proxy a number of self-hosting things, and manually assign domain names to each of them. Caddy can handles many certs just fine.

I plan to make use of a Caddy on a cheap VPS to expose some self-hosted services behind Tailscale, behind Caddy will be a mix of Raspberry Pi and a occasional hosted VPS when trying things out.

How's your experience with Caddy regarding memory usage? I am currently serving a static site with 500 MB, but this is with very low to zero traffic.

Re: 10 Years of Let's Encrypt

#332

Earlier quoted context omitted.

has anyone actually commented to you in a negative way about using Let's Encrypt? I couldn't imagine, but curious on others' experiences. One thing I heard recently which might be a valid point - that LE is based in US, which makes it a subject to US laws. Read from that what you will though.

Why is that problematic? They don't have your private keys and their "level of access" is equivalent to any other certificate authority that your browser trusts.

> Why is that problematic? They don't have your private keys and their "level of access" is equivalent to any other certificate authority that your browser trusts.

Let's Encrypt could stop issuing certificates to you, if the administration decided that necessary. This would at least disrupt whatever you were serving. Not that I think this is likely, only possible.

I think LE clealy demonstrated the need for a accessible free ACME authority. But it is high time for more alternatives (EU and China at least). FWIW: Everything around public infrastructure should be run decentralized not-for-profit using national resources. Things like DNS Registrars are silly if you think about it. They just buy it from TLD holders anyway.

Re: 10 Years of Let's Encrypt

#333
post #64

Earlier quoted context omitted.

Depends on the registrar. Globalsign required the phone number to be one publicly listed for the company in some business registry (I forget exactly which one), so it had to be someone in our main corporate office who'd deal with them on the phone.

Dun and Bradstreet (?). I believe I'm remembering this correctly. I still deal with a few financial institutions that insist on using an EV SSL certificate on their websites. I may be wrong, but I believe that having an EV SSL gives a larger insurance dollar amount should the security be compromised from the EV certificate (although I imagine it would be nearly impossible to prove). When I last reissued an EV SSL (re…

I do believe Dun & Bradstreet was it. Thanks!

Re: 10 Years of Let's Encrypt

#334

Earlier quoted context omitted.

I don't want to trust my own root CA as I don't trust myself to keep it secure. I want to important it only for a specific set of domains. "Allow this rootca to authenticate mydomain.com, addmanager.com, debuggingsite.com", which means even if compromised it won't be intercepting mybank.com

You can absolutely do that with name constraints extension set on the root CA certificate. You should verify compatibility but it's pretty universally supported on modern browsers and consumer devices last I checked. nameConstraints=critical,permitted;DNS:.iso1631.internal - "critical" ensures that any clients who don't understand this extension fail the certificate validation outright instead of ignoring it. - "DNS:…

If you generate the root CA sure. However name constraints aren't well supported.

A far better option would be to allow me, the user, to do this in the user agent. I can import my mitm cert and today I can trust it for "abc123.com" and point that to something I want to access in that manner for some reason, but tomorrow simply toggle that trust off.

If I find that I want to use a specific website and want to do something with the traffic, then I could point that DNS to my middle-box and turn that on in my browser. With name constraints I'd have to regenerate the root certificate with the new domain, and then re-import it.

the entire concept of the name constraints puts the power into the CA issuing person rather than the user.

Re: 10 Years of Let's Encrypt

#335

Earlier quoted context omitted.

If LE goes down for a week you can't deploy new certs, but your existing ones will work, as you renew them a few weeks before expiry anyway That also gives you enough time to change to get your certs from elsewhere As you mention zerossl exista, and I think google GCM will give you free certs too. Globalsign has an ACME interface for paying customers, although I'm told it has issues (you have to rotate keys manually…

> If LE goes down for a week you can't deploy new certs, but your existing ones will work, as you renew them a few weeks before expiry anyway Assuming certificate expiration times remain over 7 days per certificate.

There's no (current) plans to drop below 45 day certificates with an expected renewal with 2 weeks to go.

I agree if cert lifetimes drop towards week long then it becomes problematic. A sensible thing at that point is to ensure you can issue certificates from different CAs on different underlying stacks, in the same way you use multiple DNS servers

Re: 10 Years of Let's Encrypt

#336
post #174

Earlier quoted context omitted.

A big factor is that they are serving so many certs , with only a tiny amount of funding. Anything beyond the most basic pre-written list of blocked domain names is infeasible. Analyzing the content of every single domain would increase their resource needs by several orders of magnitude. That's reasonably close to a technical guarantee, if you ask me.

> That's reasonably close to a technical guarantee, if you ask me. Until the feds show up like: Okay, either you block these domains, or you're going to jail: politician-x-did-something-bad.com politician-y-is-corrupt.com country-z-did-crimes-against-humanity.com political-opposition-party-w-homepage.com blog-that-mentions-any-of-the-above.com ... (rest of the list that works for 10 or 100'000 domains) I complained a…

Yes, but that's still a pre-defined list. They can't say "block every website mentioning politician x doing bad things from getting a cert", because that'd be impossible to validate.

The feds are left playing whack-a-mole, and getting the right paperwork to block each new domain popping up is probably going to take a few weeks. Besides, at that point they could also force the .com operator to do the same, could they not?

I do agree that it would be better if LE was more distributed, though. Having a legally-independent second nonprofit running the same software in Switzerland or something would prevent LE from turning into a massive target for the US government.

Re: 10 Years of Let's Encrypt

#337
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

> The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". Spoken like a true dinosaur. How can a certificate based on open, public and proven secure protocols be cheap? > So my question: has anyone actually commented to you in a negative way about using Let's Encrypt? No, but I personally judge businesses which claim to be tech savvy if they don’t have an ACME issued cer…

Yeah you've correctly identified the mindset there that the leadership had in my case. They didn't want to upgrade to an in-support version of MySQL either...

Re: 10 Years of Let's Encrypt

#338
post #275

The pathetic part of EVs is that they should have been issued by whatever the business register/regulator is in the country of issue. Not some arbitrary group like D&B etc. The US/other countries should have ensured that each state/registration area had an appropriate cert to sign with. It should be part of my company's annual registration/reporting expenses that they issue the appropriate certificate for "*. . . ",…

Companies probably prefer to use "apple.com" instead of "apple-computer-inc.co.ca.us". It's even worse if you want to use truly unique identifiers like ISIN, LEI, DUNS, or IBRN, as that means something closer to "US0378331005.com".

Re: 10 Years of Let's Encrypt

#339

Earlier quoted context omitted.

I mean, these are the steps that can bring it. And with Let's Encrypt as a safe fallback, it actually is feasible this time. Long shot? Yes. But not impossible.

What's the incentive for individual sites or browsers to do this? From the site's perspective, they're going to need to have a WebPKI certificate for the foreseeable future, basically until there is no appreciable population of WebPKI-only clients, which is years in the future. So DANE is strictly more work. From the browser's perspective, very few sites actually support DANE, and the current situation is satisfactor…

DANE could've worked as an alternative to LetsEncrypt, if all CAs had refused to cross-sign it and essentially killed it for years until everyone's cert stores had caught up.

Re: 10 Years of Let's Encrypt

#340
post #251

Earlier quoted context omitted.

For someone who runs a small personal website and uses LE to secure this + some web exposed services, could you explain how this is different/better than acme-dns-certbot?

Let's Encrypt is a single point of failure. WebPKI also suffers from an inability to properly do delegation. It's not possible for me to create an intermediary certificate valid only for *.mycompany.com If I want to use WebPKI, I have to either expose every host inside my company to everyone (via CT transparency logs) or use a wildcard certificate. And wildcard certs allow attackers to impersonate anything within my…

CT logs do allow enumeration, but avoiding that is just security through obscurity. WebPKI is intended for publicly-accessible hosts, so hopefully you already have some kind of firewall in place to protect them! If you want to avoid enumeration of internal-only hosts: just use your own self-signed root cert. CT logs are a crucial part of protecting against rogue CAs, so don't expect that to go away any time soon.

With ACME most of the delegation issues have pretty much been solved. Publicly-accessible hosts can easily get a cert - if and only if the domain resolves to that host. Want even stricter enforcement? Nobody's stopping you from writing an ACME proxy which only forwards requests from known-good hosts to LE & friends.

Post reply on HN