Earlier quoted context omitted.
Unfortunately the CA/B Forum has high requirements for constrained subordinate CA certificates[1], which to me sounds a lot like regulatory capture. [1] https://community.letsencrypt.org/t/sub-ca-with-wildcard-cer...
It's not that high of a requirement. The sub-CA is allowed to self audit. But the original CA does have to check a percentage of certificates issued by the sub-CA. So that's not going to be free. But it might be possible to do it if you were big enough to pay for it. I have dreams of having my private CA also signed off on by webpki so apps and browsers could use the same servers without having to include webpki in m…
Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
391–400 of 404 posts
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#392Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#393Earlier quoted context omitted.
Let's encrypt is not some code or even a company that you can split into different branches. Their existence is one based on trust relations that let's encrypt has with browsers and operative systems. It is in one part similar to both domain names and IP address space, in that the technical aspects of creating alternative roots is almost trivial in comparison to getting the trust that is required for an alternative r…
Russia already has its own root CA, the issue is that state-owned root CAs are by definition not safe from MITM attacks by the same government.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#394Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#395Couldn't LE have a branch in Europe or anywhere outside the USA and its minions? Because they're betraying their own goals, as stated in their About page: “It is a service run for the public’s benefit. [...] Anyone who owns a domain name can use Let’s Encrypt to obtain a trusted certificate at zero cost. [...] Let’s Encrypt is a joint effort to benefit the community, beyond the control of any one organization.” Now t…
They could, but if the branch didn’t follow these laws, the main US branch would still be liable.
If they set up a subsidiary in Europe, they could be held liable for actions of European subsidiary.
If an independent org is stood up in Europe, with European directors, staff and funding, legally independent of US org, and the US org just provides advice/assistance to Europe org without ability to control it-legal liability for US org for Europe org’s decisions is less likely. Of course, ask a lawyer-but if you openly say “we are doing this to work around US sanctions” you could still be liable; if you say “this has nothing to do with sanctions this is about resilience of global digital infrastructure and European digital sovereignty” then under what legal theory is the US org liable?
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#396Earlier quoted context omitted.
It's not that high of a requirement. The sub-CA is allowed to self audit. But the original CA does have to check a percentage of certificates issued by the sub-CA. So that's not going to be free. But it might be possible to do it if you were big enough to pay for it. I have dreams of having my private CA also signed off on by webpki so apps and browsers could use the same servers without having to include webpki in m…
I also started going down this rabbit hole when I wanted my homelab to just work in any device, and for advanced use cases Let's Encrypt isn't enough. I tried long and hard to get a sub-CA certificate, but apparently that's in the realm of «if you need to ask, you can't afford it».
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#397Earlier quoted context omitted.
This is incredible. How did you find these certs?
I only noticed the star net one (not sure if it’s even in use) when writing this. I noticed the Pyongyang Zoo (which shares an IP with the Architects Society—one on 443 and one on 80 lmao) first, just from flipping through their very small IP space on Shodan. You can see them all on crt.sh, because LE has to upload them to a CT log for browsers to trust them. (That’s how most of those subdomain finder websites work t…
http://www.koreanarchitecture.gov.kp/index.php?kt=TWFnYXppbm...
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#398Iran is blocking internet for months, US ...bans creation of secure connections - that'll show 'em! Russian quasi-government structures are spending quadrillion of rubles on a TSPU (censorship system) to spy on Russian residents, US ...helps them by making snooping on what is currently encrypted traffic possible by banning accessible encryption!
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#399Let's Encrypt’s mission is to create a more secure and privacy-respecting web, except for people residing in countries with the most need for a more secure and privacy-respecting web. Sure, that's great. That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international fr…
Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population. This subscriber agreement update was intended to better reflect our legal…
> Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population.
It doesn't work that way.
Blocking governments from getting certs doesn't hurt them in the slightest. The government can just create their own pki.
But it hurts the general population instead. People do not live in vacuum, they still need to access government sites. And thus people are forced to install root certificates of questionable trust.
When Let's Encrypt blocks government entities, it instead puts respective vulnerable population in even less secure environment.
Although, given the current events, I am not sure Let's Encrypt continues to deserve the trust it had.
Re: Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
#400Earlier quoted context omitted.
The problem is that finding a root source of trust aren't easy this days. LE was neutral, now nobody is. Russian government issued their new root certificate years ago. Nobody trusted it enough to request a certificate from them or install it on their computers. Including almost all of the russian residents. If Let's Encrypt enforces the rules, as written in pdf, a lot of people would lose a choice. Frankly, even pub…
> Nobody trusted it Let's be real here… 99.99999999999999% of internet users have no idea what root CAs even are. It's the browser vendor mafia that makes the decision.
Forcing is as easy, as blocking access to important services behind the certificate wall.