Live data from Hacker News

10 Years of Let's Encrypt

letsencrypt.org

341–350 of 361 posts

Re: 10 Years of Let's Encrypt

#341

Earlier quoted context omitted.

You can absolutely do that with name constraints extension set on the root CA certificate. You should verify compatibility but it's pretty universally supported on modern browsers and consumer devices last I checked. nameConstraints=critical,permitted;DNS:.iso1631.internal - "critical" ensures that any clients who don't understand this extension fail the certificate validation outright instead of ignoring it. - "DNS:…

If you generate the root CA sure. However name constraints aren't well supported. A far better option would be to allow me, the user, to do this in the user agent. I can import my mitm cert and today I can trust it for "abc123.com" and point that to something I want to access in that manner for some reason, but tomorrow simply toggle that trust off. If I find that I want to use a specific website and want to do somet…

Where are you finding that name constraints aren't supported? I've only come across that on embedded/IoT devices. They work fine for me across Firefox and Chrome on Linux, on Android, and they are supposed to work fine on Apple devices too.

> If I find that I want to use a specific website and want to do something with the traffic...

I agree but that's a different problem. If you just need a certificate for your router and some internal services (the original discussion), you can do that using an internal root CA and you have nothing to worry about as long as you using name constraints.

On IoT devices without nameConstraints support I just use an alternative CA certificate without name constraints (same key, different extensions).

Re: 10 Years of Let's Encrypt

#342
post #340

Earlier quoted context omitted.

Let's Encrypt is a single point of failure. WebPKI also suffers from an inability to properly do delegation. It's not possible for me to create an intermediary certificate valid only for *.mycompany.com If I want to use WebPKI, I have to either expose every host inside my company to everyone (via CT transparency logs) or use a wildcard certificate. And wildcard certs allow attackers to impersonate anything within my…

CT logs do allow enumeration, but avoiding that is just security through obscurity. WebPKI is intended for publicly-accessible hosts, so hopefully you already have some kind of firewall in place to protect them! If you want to avoid enumeration of internal-only hosts: just use your own self-signed root cert. CT logs are a crucial part of protecting against rogue CAs, so don't expect that to go away any time soon. Wit…

> CT logs do allow enumeration, but avoiding that is just security through obscurity.

Well, yes. There are also other issues, like rate limits. Some companies have hundreds of thousands of hosts (some virtual) and requesting certificates for all of them might be problematic.

> If you want to avoid enumeration of internal-only hosts: just use your own self-signed root cert.

This becomes increasingly problematic, as browsers start relying on DoH/DoT, or making it more difficult to enroll custom root certs.

> Nobody's stopping you from writing an ACME proxy which only forwards requests from known-good hosts to LE & friends.

I actually tried that. LE uses multiple viewpoints to resolve the challenges, so you need to open your internal DNS resolvers/HTTPS to basically all the world. Or play with the horror of split-horizon DNS.

Re: 10 Years of Let's Encrypt

#343

I still remember the original announcement around LE and thought "Great idea, no idea if they'll be able to get buy-in from browsers/etc", now I use it on all my self-hosted sites and will probably be transitioning my employer over to it when we switch to automated renewal sometime next year. LE has been an amazing resource and every time I setup a new website and get a LE cert I smile. Especially after having lived/…

We actually spent some time making sure that we weren't going to run into problems with browsers. However, as the OP points out, because LE had a cross-signature from an existing CA, browsers didn't have to any positive action to make LE certificates work. This was absolutely essential to getting things off the ground.

Oh, I know you all did and I remember the cross-signing. I worried that you'd get slapped down somehow, that the crappy cert companies would find a way to stop/reverse it, that the project would fizzle out, etc. I thought it was cool as hell but it seemed something so clearly good couldn't stay good but you all have only gotten better over time.

Re: 10 Years of Let's Encrypt

#344
post #296

Earlier quoted context omitted.

For me it’s hidden behind a kebab menu in that thingamajig you described.

Well, either it isn't there in my Safari (macOS 15.7.2) or I can't find it. I have found "Connection Security Details…" in the "Safari" menu, though. But my point still stands: average users won't see any certificate information without serious effort.

Ah no, i am on iOS 26.

Re: 10 Years of Let's Encrypt

#345

Earlier quoted context omitted.

StartSSL, WoSign were the ones I've used. Very convenient services, much more convenient, compared to this certbot insanity. I think that the rest of the world does not have much choice, because US uses their IT superiority to force political decisions to the rest of the world. I experienced that first-hand. When my country wanted to implement MITM to improve Internet usability for their citizens, US companies blackl…

In what way do MITM certificates "improve Internet usability for their citizens"?

I just explained that. Basically government wants to block some specific webpage, say https://en.wikipedia.org/wiki/Nursultan_Nazarbayev. Without MITM, they'll end up with blocking the entire en.wikipedia.org domain, so citizens will lose access to a lot of information. With MITM, they'll be able to target precisely one page and I can read any other wikipedia article without issues.

Re: 10 Years of Let's Encrypt

#346

Earlier quoted context omitted.

Well, I use Arch Linux and the caddy package from pacman just works. You may checkout https://github.com/caddyserver/xcaddy for custom caddy build. Besides, I don't use wildcard certs. I use caddy to reverse proxy a number of self-hosting things, and manually assign domain names to each of them. Caddy can handles many certs just fine.

I plan to make use of a Caddy on a cheap VPS to expose some self-hosted services behind Tailscale, behind Caddy will be a mix of Raspberry Pi and a occasional hosted VPS when trying things out. How's your experience with Caddy regarding memory usage? I am currently serving a static site with 500 MB, but this is with very low to zero traffic.

I see 3-4% of 1GB ram usage for caddy only. Note that in my case caddy serves as reverse proxy and there is also very little traffic.

Re: 10 Years of Let's Encrypt

#347
post #5

Let's Encrypt was _huge_ in making it's absurd to not have TLS and now we (I, at least) take it for granted because it's just the baseline for any website I build. Incredible, free service that helped make the web a more secure place. What a wonderful service - thank you to the entire team. The CEO at my last company (2022) refused to use Let's Encrypt because "it looked cheap to customers". That is absurd to me beca…

I used to deal with a couple people who were against any automatic or free certs. It was part of their jobs to procure the annual certs, look them over, present them to the developers and maintain automatic checks to regularly inspect the certificates. This was partly how they justified their jobs, but they relished the ceremony and being able to tell developers what to do, even if only for a few minutes a year. They repeatedly blocked introduction of LetsEncrypt.

Just checked. They’re still using that manually installed cert!

Re: 10 Years of Let's Encrypt

#348
post #338
post #275

The pathetic part of EVs is that they should have been issued by whatever the business register/regulator is in the country of issue. Not some arbitrary group like D&B etc. The US/other countries should have ensured that each state/registration area had an appropriate cert to sign with. It should be part of my company's annual registration/reporting expenses that they issue the appropriate certificate for "*. . . ",…

Companies probably prefer to use "apple.com" instead of "apple-computer-inc.co.ca.us". It's even worse if you want to use truly unique identifiers like ISIN, LEI, DUNS, or IBRN, as that means something closer to "US0378331005.com".

The point is that I (as an Australian) don't trust a private organization like D&B any more than any other organization.

Corporate existence is dependent on some form of government regulator granting the corporation existence.

If EVs are/were a good idea (debatable at best), then having those EVs issued by the same government regulator that allows corporates to use trademarks etc makes sense.

If "apple" is a trademark for computers, then Apple Computer Inc as the owner of that trademark should get an EV issued by the regulator of trademarks.

Of course, the URL should be apple.com.us or apple.tm.us.

The historical error was not requiring the US to move to 2LDs for it's com/org/net/gov/mil etc domains.

Note this is for corporate entities, none of which exist outside regulatory environments.

Re: 10 Years of Let's Encrypt

#349

Earlier quoted context omitted.

In what way do MITM certificates "improve Internet usability for their citizens"?

I just explained that. Basically government wants to block some specific webpage, say https://en.wikipedia.org/wiki/Nursultan_Nazarbayev . Without MITM, they'll end up with blocking the entire en.wikipedia.org domain, so citizens will lose access to a lot of information. With MITM, they'll be able to target precisely one page and I can read any other wikipedia article without issues.

And with MITM they can read literally all of your private internet traffic… That seems like a significantly worse tradeoff to just using a VPN to browse Wikipedia.

Re: 10 Years of Let's Encrypt

#350
post #174

Earlier quoted context omitted.

A big factor is that they are serving so many certs , with only a tiny amount of funding. Anything beyond the most basic pre-written list of blocked domain names is infeasible. Analyzing the content of every single domain would increase their resource needs by several orders of magnitude. That's reasonably close to a technical guarantee, if you ask me.

> That's reasonably close to a technical guarantee, if you ask me. Until the feds show up like: Okay, either you block these domains, or you're going to jail: politician-x-did-something-bad.com politician-y-is-corrupt.com country-z-did-crimes-against-humanity.com political-opposition-party-w-homepage.com blog-that-mentions-any-of-the-above.com ... (rest of the list that works for 10 or 100'000 domains) I complained a…

Why would the feds bother with let’s encrypt in this situation when it would make way more sense to just go to ICANN and get the domain names unregistered. They already do that all the time.
Post reply on HN