Discord is out too right now, probably unrelated though.
Just speculating, but I don't think it's unrelated. Discord heavily utilizes Cloudflare, and Cloudflare uses Let's Encrypt for a certificate issuance. If they happened to have a certificate signing dependency in some operational rollout today, I think it could explain it. Certainly the timing is very correlated.
Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
81–90 of 97 posts
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#82Earlier quoted context omitted.
Considering the open source nature of Letsencrypt, I wonder what the barriers/costs would be (theoretically) to a wealthy benefactor who wanted to duplicate its server side infrastructure and a core staffing level of persons, and fund a "parallel" equally trusted, alternative entity with a solid governing board. Same general idea how Acton funded the Signal foundation. Somewhere that none of the physical infrastructu…
Google has their own free ACME endpoint: https://pki.goog/
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#83Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#84There is one little-discussed down side to ever shorter-lived certificates...
Letsencrypt is not the only acme authority. ZeroSSL is the other popular one. There are others.
Actalis offered unlimited single name certificates. Why are ZeroSSL more popular?
Google offered unlimited certificates with multiple names and wild cards. But they required a GCP account seemingly. It would require to give Google personal information, a phone number, and automatic payment permission. And Google not disable your account because your spouse uploaded images for your child's doctor.
All others I saw charged for each certificate.
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#85There is one little-discussed down side to ever shorter-lived certificates...
If you're using ACME to handle certificate rotation, can't you just configure multiple providers?
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#86Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#87That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now. Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuan…
Stopping all issuance is an pretty standard response if a CA thinks what they are issuing might be non-compliant in any way. It's an action we're required to take. It's not necessarily a sign of a more dramatic failure mode or key compromise. That said, the impact is the same for as long as the downtime lasts so it is unfortunate and we're sorry for the disruption. I don't think the premise behind short lived (six da…
Are they going to be optional forever, or do you plan to eventually get rid of the longer lifetime options?
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#88Earlier quoted context omitted.
ZeroSSL should also be drop in
ZeroSSL advertised for free 3 certificates with no multiple names or wild cards. The next plan was $180 yearly.
https://zerossl.com/documentation/acme/
Fwiw haven't used them personally
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#89Earlier quoted context omitted.
Is the frog the guy that still won't automate their certificates?
Mine are automated. Somehow it reminds me of prayer wheels though...
And once people automate, short-lived certificates are a workable plan B for how to revoke certificates and have the revocation actually work.
These are both reasonable goals.
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#90Discord is out too right now, probably unrelated though.
Just speculating, but I don't think it's unrelated. Discord heavily utilizes Cloudflare, and Cloudflare uses Let's Encrypt for a certificate issuance. If they happened to have a certificate signing dependency in some operational rollout today, I think it could explain it. Certainly the timing is very correlated.
Cloudflare does provide the option for customers to manage their own certificates, which would make it the customer’s responsibility to have alternatives issuers when needed.