Live data from Hacker News

Let's Encrypt had a higher error rate for 90 minutes today

letsencrypt.status.io

71–80 of 115 posts

Re: Let's Encrypt had a higher error rate for 90 minutes today

#72
post #34

Earlier quoted context omitted.

ZeroSSL – free 90-day certs via ACME, also has a web UI for cert management Google Trust Services – free ACME certs, requires a Google account for registration SSL.com Free DV SSL – offers free 90-day certs through ACME

I use acme.sh for certs on my personal server and was a little surprised when it started using ZeroSSL by default. Despite being more "corporate" I decided to roll with it and it's worked just fine.

acme.sh is maintained by ZeroSSL. https://github.com/acmesh-official/acme.sh#2%EF%B8%8F%E2%83%...

Re: Let's Encrypt had a higher error rate for 90 minutes today

#73
post #22

I realize this is very much not the point, but the fact that the "Active Incident" banner is green is upsetting.

The banner's colour is based on the "Incident Status;" it's green because services are currently operational. It would be yellow or red if the impact were more severe.

Using only color to communicate the status is confusing. If you want to communicate something, it's often best to just say it. The color can be a visual reinforcement of that. Then your explanation would not be needed.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#74
post #58
post #53

Earlier quoted context omitted.

"nobody should be renewing their certificate within 90 minutes of expiration" You obviously haven't worked with hardware guys. "I mean, what's the point of those last 30 days if you need to renew it 30 days before expiration? Why not just renew it before it expires? If I'm required to renew it 30 days before the expiration date then the expiration date is a lie, isn't it?"

If they make 7 days grace period then expiration date will be a lie and of course every one will use grace period like it would be normal thing ;)

Roulette grace period, keep them on their toes.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#76
post #73
post #22

Earlier quoted context omitted.

The banner's colour is based on the "Incident Status;" it's green because services are currently operational. It would be yellow or red if the impact were more severe.

Using only color to communicate the status is confusing. If you want to communicate something, it's often best to just say it. The color can be a visual reinforcement of that. Then your explanation would not be needed.

We do say it. That's what the "Incident Status" field is there for.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#78
post #52
post #42

Earlier quoted context omitted.

> weeks ago How long do you think a certificate lives?

Mostly 90 days, and we recommend renewing at 60 days for 90 day certs. That gives more than four weeks of leeway. If you're one of the few early adopters of short-lived (6-day) certs you should renew at 3 days, giving you 3 days for a successful renewal. A 90 minute outage, even if it was a full outage, would not interfere with a successful renewal.

How's the push for 48 hour certificates going?

Re: Let's Encrypt had a higher error rate for 90 minutes today

#79
post #53
post #33

Earlier quoted context omitted.

> That explains why one of my IoT vendors is using an expired certificate. I don't think so. There was a dip in success rates for 90 minutes today, but nobody should be renewing their certificate within 90 minutes of expiration. If you're at that point, something went wrong weeks ago.

"nobody should be renewing their certificate within 90 minutes of expiration" You obviously haven't worked with hardware guys. "I mean, what's the point of those last 30 days if you need to renew it 30 days before expiration? Why not just renew it before it expires? If I'm required to renew it 30 days before the expiration date then the expiration date is a lie, isn't it?"

> If I'm required to renew it 30 days before the expiration date then the expiration date is a lie, isn't it?

Many countries won't let you enter if your passport expires less than 6 months after your planned departure date. Basically the effective validity of a passport is 0.5 years less than the period you pay for.

Re: Let's Encrypt had a higher error rate for 90 minutes today

#80
post #52
post #42

Earlier quoted context omitted.

> weeks ago How long do you think a certificate lives?

Mostly 90 days, and we recommend renewing at 60 days for 90 day certs. That gives more than four weeks of leeway. If you're one of the few early adopters of short-lived (6-day) certs you should renew at 3 days, giving you 3 days for a successful renewal. A 90 minute outage, even if it was a full outage, would not interfere with a successful renewal.

> If you're one of the few early adopters of short-lived (6-day) certs you should renew at 3 days

Apparently certificates are becoming OCSP-only with a TTL.

Post reply on HN