Live data from Hacker News

New TLS certificate for .herokuapp.com hostnames

devcenter.heroku.com

41–43 of 43 posts

Re: New TLS certificate for .herokuapp.com hostnames

#41

Something that's nice about Let's Encrypt is that it forces you to change something every few months. After the first couple months, you'll probably get your issues worked out. If you just change certs every few years, then every few years you have some sort of disaster because of the "well we fixed it, we don't have to worry for two years" effect. A broader lesson is the importance of "trying out" rare events, even…

Although, speaking of Let's Encrypt, there will be a series of disruptive events over the next 18 months or so. * Soon (although when exactly I'm not sure because it has been delayed at least once) the Let's Encrypt systems will tell compliant ACME clients that the "correct" intermediate is Let's Encrypt's ISRG-signed X3 intermediate. This is a different certificate for the same X3 private key you're used to but not…

Security means you don’t support

> Six year old Android phones, the Windows XP system you know should have been retired, a VoIP desk phone running out-of-date firmware, stuff like that.

If these can’t connect that is a feature, not a bug.

Re: New TLS certificate for .herokuapp.com hostnames

#42

Earlier quoted context omitted.

This inspired me to look into my system's trusted roots. Here's the root CA expirations coming up in the next 18 months. The last one on this list really hits home, as anyone who did TLS back in the early 00's may remember. 2020-09-12 - DST Root CA X4 2021-03-17 - QuoVadis Root Certification Authority 2021-04-06 - Sonera Class X2 2021-09-30 - DST Root CA X3 2021-11-09 - Admin-Root-CA 2021-12-15 - Belgium Root CA2 202…

Admin-Root-CA shows us how far we've come, I think today that even if Mozilla's root programme didn't forbid them people would guess that ultra-vague names aren't a good idea. For reference that is the Swiss government's root and it isn't trusted by Mozilla so as a consequence it's unlikely that any systems you have facing ordinary web browsers depend on this root to be trusted. It's also funny to go back and look at…

Certificate Transparency logs would provide the answer to this.

Re: New TLS certificate for .herokuapp.com hostnames

#43

Wow. I really hope they’ll get it done before the expiration date but I always thought they’d be renewing months in advance at minimum. Are they trying to negotiate something?

Get what done? Heroku replaced their wildcard certificate in plenty of time but many customers do not anticipate anything changing ever and will fiercely resist this simple fact, so for those customers stuff blew up. Remember the Y2K problem is the result of software written not in 1901 or even just 1981 but even well into the 1990s with the calm certainty that all years begin 19xx. Heroku can try brown out policies,…

This is called ‘enterprise’ and everyone in it will tell you a million excuses why it’s the only way.
Post reply on HN