Earlier quoted context omitted.
This change will only add the grey 'not secure' text to the address bar and not hinder functionality. So it is just less green and not more red as with invalid or self-signed certificates where you have to perform additional steps to continue.
That's in this version. How many versions until we get the ridiculous harassment already required for self-signed certs?
Chrome will mark all HTTP sites as ‘not secure’ starting in July
51–60 of 143 posts
Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July
#52Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July
#53Earlier quoted context omitted.
The other option is to register a domain and use that to get either LetsEncrypt cetts or purchase a wildcard.
That’s what I do. And LE actually supports wildcards, so that’s no problem. If your local network is firewalled off LE can still issue you a cert so long as you use DNS record validation.
Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July
#54So, what is the Chromes team solution for local network devices like routers? Proxy it over the manufacturers server for a complete loss of any privacy and security, but hey, there is a green check mark then?
The problem is really _naming_ these devices first of all. If they have (global) names there's no problem to issue a certificate for those names. But so often the device doesn't have any name at all, so it's maybe 10.0.0.1, and so is everything else, the problem only appears to be in the security layer because that's the first place which absolutely insists that you can't have a situation where everybody is just name…
Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July
#55Earlier quoted context omitted.
I don't know why there is still no standardization for advertising/providing CA services for local networks. How difficult would it be to just put local ACME endpoint to DHCP options?
adding a local CA means you can middleman anything you want to, seems like something that should be difficult to do, to me.
Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July
#56Earlier quoted context omitted.
That’s what I do. And LE actually supports wildcards, so that’s no problem. If your local network is firewalled off LE can still issue you a cert so long as you use DNS record validation.
It depends how often you want to update things I guess. A wildcard costs less than $50 a year these days, so if that might be better for some people than renewing their LE every few months.
1. Maximum cert lifetimes are falling, once upon a time you'd just pony up the cash and get five years. A year ago it was 36 months, for a few months now it's been 825 days, and there is downward pressure. So you are still going to need to renew this cert, and that means...
2. You can and should automate. Imagine buying a device in 2018 that expects you to manually input an IP address because "Eh, we could do DHCP but this was less effort (for us)". That'd be crazy right? Time to feel the same way about certificate automation.
Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July
#57If you wonder how to get HTTPS for your local virtual hosts: 1. create a local CA 2. create a certificate using that local CA 3. Then you can add the CA in your trusted authorities (Firefox does need an extra step: either enable the "security.enterprise_roots.enabled" flag, either import the CA certificate manually in it). Details at: https://gist.github.com/cecilemuller/9492b848eb8fe46d462abeb...
Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July
#58So, what is the Chromes team solution for local network devices like routers? Proxy it over the manufacturers server for a complete loss of any privacy and security, but hey, there is a green check mark then?
I don't know why there is still no standardization for advertising/providing CA services for local networks. How difficult would it be to just put local ACME endpoint to DHCP options?
As a user, I don’t want local networks setting me up to make me recognize their CA services.
At first I liked SSL everywhere, but now I’m seeing a lot of hacks that are going to make SSL less useful.
Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July
#59If you wonder how to get HTTPS for your local virtual hosts: 1. create a local CA 2. create a certificate using that local CA 3. Then you can add the CA in your trusted authorities (Firefox does need an extra step: either enable the "security.enterprise_roots.enabled" flag, either import the CA certificate manually in it). Details at: https://gist.github.com/cecilemuller/9492b848eb8fe46d462abeb...
Re: Chrome will mark all HTTP sites as ‘not secure’ starting in July
#60If you wonder how to get HTTPS for your local virtual hosts: 1. create a local CA 2. create a certificate using that local CA 3. Then you can add the CA in your trusted authorities (Firefox does need an extra step: either enable the "security.enterprise_roots.enabled" flag, either import the CA certificate manually in it). Details at: https://gist.github.com/cecilemuller/9492b848eb8fe46d462abeb...
Let’s push for self-signed certicates everywhere ! Let’s do Trust On First Use like SSH and now we’re done with all this certificates authorities bloated bureaucraties