Live data from Hacker News

Let's Encrypt had a higher error rate for 90 minutes today

letsencrypt.status.io

51–60 of 115 posts

Re: Let's Encrypt had a higher error rate for 90 minutes today

#51

That explains why one of my IoT vendors is using an expired certificate. I wish Firefox would just give a mild warning for a recently expired certificate, instead of treating it the same as a true man-in-the-middle attach. It's not like someone who couldn't factor the private key in 200 days could in 201 days or even 300 days. I'm convinced that we'd have better security, if we didn't have so much security theater. Y…

> I wish Firefox would just give a mild warning for a recently expired certificate Nope, if the SSL industry continues to insist on increasingly short cert lifetimes then I want Firefox to give no quarter when a cert expires. Play by their rules and fall by their rules too.

How does that help? Seems like mostly the end user suffers.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#52
post #42
post #33

Earlier quoted context omitted.

> That explains why one of my IoT vendors is using an expired certificate. I don't think so. There was a dip in success rates for 90 minutes today, but nobody should be renewing their certificate within 90 minutes of expiration. If you're at that point, something went wrong weeks ago.

> weeks ago How long do you think a certificate lives?

Mostly 90 days, and we recommend renewing at 60 days for 90 day certs. That gives more than four weeks of leeway.

If you're one of the few early adopters of short-lived (6-day) certs you should renew at 3 days, giving you 3 days for a successful renewal. A 90 minute outage, even if it was a full outage, would not interfere with a successful renewal.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#53
post #33

That explains why one of my IoT vendors is using an expired certificate. I wish Firefox would just give a mild warning for a recently expired certificate, instead of treating it the same as a true man-in-the-middle attach. It's not like someone who couldn't factor the private key in 200 days could in 201 days or even 300 days. I'm convinced that we'd have better security, if we didn't have so much security theater. Y…

> That explains why one of my IoT vendors is using an expired certificate. I don't think so. There was a dip in success rates for 90 minutes today, but nobody should be renewing their certificate within 90 minutes of expiration. If you're at that point, something went wrong weeks ago.

"nobody should be renewing their certificate within 90 minutes of expiration"

You obviously haven't worked with hardware guys.

"I mean, what's the point of those last 30 days if you need to renew it 30 days before expiration? Why not just renew it before it expires? If I'm required to renew it 30 days before the expiration date then the expiration date is a lie, isn't it?"

Re: Let's Encrypt had a higher error rate for 90 minutes today

#54
post #45

Earlier quoted context omitted.

It would not have been sticky for the entire day. If it was sticky at all, it would have been only during the 90 minute period I referenced. It's most likely that there is some other issue with how you're requesting the cert. Folks can help debug at: https://community.letsencrypt.org/

I updated the post title to say (Fixed) now.

Since Let's Encrypt wasn't down most of the day if would be helpful if you could update the title to reflect that.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#55

[flagged]

You are getting down-voted for this, which I think is a bit unfair. (I expect I'll get the same.)

Although you don't expand your thesis, as a general feeling, I agree. But, to be fair, it has always been thus, and it has been this way in every forum ever.

I'm old enough to remember the irony in "I read about it on the internet so it must be true" statements, which have existed since the internet was News (NNTP) not web.

In truth, any time you get a random group of people together, of different ages and backgrounds, all of whom self-describe as "smart" you're going to get a lot of chaff mixed in with the wheat.

To some extent you need to simply ignore the nonsense. There's plenty of it and "correcting people who are wrong" is seldom received well.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#56

That explains why one of my IoT vendors is using an expired certificate. I wish Firefox would just give a mild warning for a recently expired certificate, instead of treating it the same as a true man-in-the-middle attach. It's not like someone who couldn't factor the private key in 200 days could in 201 days or even 300 days. I'm convinced that we'd have better security, if we didn't have so much security theater. Y…

> I wish Firefox would just give a mild warning for a recently expired certificate Nope, if the SSL industry continues to insist on increasingly short cert lifetimes then I want Firefox to give no quarter when a cert expires. Play by their rules and fall by their rules too.

Certificate expiry is less severe than an untrusted issuer or a host mismatch.

The former is most likely an administrative error (ie: someone forgot to renew, or the auto-renew is failing). The latter is more likely to be an MTM attack.

I'm not sure how you would use an expired cert as an attack vector. By loading in an old cert into an expired domain so you could spoof older content?

Re: Let's Encrypt had a higher error rate for 90 minutes today

#57
post #42
post #33

Earlier quoted context omitted.

> That explains why one of my IoT vendors is using an expired certificate. I don't think so. There was a dip in success rates for 90 minutes today, but nobody should be renewing their certificate within 90 minutes of expiration. If you're at that point, something went wrong weeks ago.

> weeks ago How long do you think a certificate lives?

90 days moving to 45 but you can and should renew earlier than that. Automating this process means that you should be request a new certificates roughly 60 days (or 30 soon) after the issuance of the previous certificate. That way you would have plenty of time to deal with renewal issues. The process for renewal should have back off and retries built in. This prevents a situation where a down time for the issuer means that your production environments are non-functional.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#58
post #53
post #33

Earlier quoted context omitted.

> That explains why one of my IoT vendors is using an expired certificate. I don't think so. There was a dip in success rates for 90 minutes today, but nobody should be renewing their certificate within 90 minutes of expiration. If you're at that point, something went wrong weeks ago.

"nobody should be renewing their certificate within 90 minutes of expiration" You obviously haven't worked with hardware guys. "I mean, what's the point of those last 30 days if you need to renew it 30 days before expiration? Why not just renew it before it expires? If I'm required to renew it 30 days before the expiration date then the expiration date is a lie, isn't it?"

If they make 7 days grace period then expiration date will be a lie and of course every one will use grace period like it would be normal thing ;)

Re: Let's Encrypt had a higher error rate for 90 minutes today

#59
post #54

Earlier quoted context omitted.

I updated the post title to say (Fixed) now.

Since Let's Encrypt wasn't down most of the day if would be helpful if you could update the title to reflect that.

I updated the title. Let me know if you think it's more accurate. It did appear as down for me though.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#60
post #42
post #33

Earlier quoted context omitted.

> That explains why one of my IoT vendors is using an expired certificate. I don't think so. There was a dip in success rates for 90 minutes today, but nobody should be renewing their certificate within 90 minutes of expiration. If you're at that point, something went wrong weeks ago.

> weeks ago How long do you think a certificate lives?

They work at letsencrypt, I'm pretty sure they know.
Post reply on HN