Live data from Hacker News

Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

letsencrypt.status.io

81–90 of 97 posts

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#81
post #17
post #7

Discord is out too right now, probably unrelated though.

Just speculating, but I don't think it's unrelated. Discord heavily utilizes Cloudflare, and Cloudflare uses Let's Encrypt for a certificate issuance. If they happened to have a certificate signing dependency in some operational rollout today, I think it could explain it. Certainly the timing is very correlated.

Cloudflare doesn't issue let's encrypt certs

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#82

Earlier quoted context omitted.

Considering the open source nature of Letsencrypt, I wonder what the barriers/costs would be (theoretically) to a wealthy benefactor who wanted to duplicate its server side infrastructure and a core staffing level of persons, and fund a "parallel" equally trusted, alternative entity with a solid governing board. Same general idea how Acton funded the Signal foundation. Somewhere that none of the physical infrastructu…

Google has their own free ACME endpoint: https://pki.goog/

They implied it used a GCP account. It would require to give Google personal information, a phone number, and automatic payment permission. And Google not disable your account because your spouse uploaded images for your child's doctor.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#83
post #70

Earlier quoted context omitted.

Google has their own free ACME endpoint: https://pki.goog/

ZeroSSL should also be drop in

ZeroSSL advertised for free 3 certificates with no multiple names or wild cards. The next plan was $180 yearly.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#84
post #34
post #4

There is one little-discussed down side to ever shorter-lived certificates...

Letsencrypt is not the only acme authority. ZeroSSL is the other popular one. There are others.

ZeroSSL offered for free 3 single name certificates. The next plan was $180 yearly.

Actalis offered unlimited single name certificates. Why are ZeroSSL more popular?

Google offered unlimited certificates with multiple names and wild cards. But they required a GCP account seemingly. It would require to give Google personal information, a phone number, and automatic payment permission. And Google not disable your account because your spouse uploaded images for your child's doctor.

All others I saw charged for each certificate.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#85
post #25
post #4

There is one little-discussed down side to ever shorter-lived certificates...

If you're using ACME to handle certificate rotation, can't you just configure multiple providers?

https://news.ycombinator.com/item?id=48071607

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#86
post #58

Earlier quoted context omitted.

> no plan to make them the default at this time At this time! Boil the frog slowly...

Is the frog the guy that still won't automate their certificates?

Mine are automated. Somehow it reminds me of prayer wheels though...

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#87
post #53

That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now. Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuan…

Stopping all issuance is an pretty standard response if a CA thinks what they are issuing might be non-compliant in any way. It's an action we're required to take. It's not necessarily a sign of a more dramatic failure mode or key compromise. That said, the impact is the same for as long as the downtime lasts so it is unfortunate and we're sorry for the disruption. I don't think the premise behind short lived (six da…

> Short lived certificates are optional though, so if it's not worth it to you there are longer lifetime options.

Are they going to be optional forever, or do you plan to eventually get rid of the longer lifetime options?

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#88
post #70

Earlier quoted context omitted.

ZeroSSL should also be drop in

ZeroSSL advertised for free 3 certificates with no multiple names or wild cards. The next plan was $180 yearly.

Their docs say unlimited free and wildcards are supported with ACME. Does require EAB tho

https://zerossl.com/documentation/acme/

Fwiw haven't used them personally

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#89
post #86

Earlier quoted context omitted.

Is the frog the guy that still won't automate their certificates?

Mine are automated. Somehow it reminds me of prayer wheels though...

Forcing certificates to expire in less than a year means people don't forget how to update them, which is a big benefit.

And once people automate, short-lived certificates are a workable plan B for how to revoke certificates and have the revocation actually work.

These are both reasonable goals.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#90
post #17
post #7

Discord is out too right now, probably unrelated though.

Just speculating, but I don't think it's unrelated. Discord heavily utilizes Cloudflare, and Cloudflare uses Let's Encrypt for a certificate issuance. If they happened to have a certificate signing dependency in some operational rollout today, I think it could explain it. Certainly the timing is very correlated.

For domains where they handle the certificates, Cloudflare utilizes multiple CAs, to avoid such a single point of failure: I’ve seen Cloudflare managed certificates issued by Let’s Encrypt, Google Cloud, Sectigo, and SSL.com.

Cloudflare does provide the option for customers to manage their own certificates, which would make it the customer’s responsibility to have alternatives issuers when needed.

Post reply on HN