Live data from Hacker News

Let’s Encrypt to transition to ISRG root

scotthelme.co.uk

91–100 of 114 posts

Re: Let’s Encrypt to transition to ISRG root

#91
post #88

Earlier quoted context omitted.

Yes, they are interchangeable. On my blog ( https://theandrewbailey.com/ ), I have a "health check" page that includes all available trust chains. For my Let's Encrypt certificate, it shows 2: one through an intermediate to the DST Root, and another intermediate to the ISRG Root. I can verify that both exist and are used (though one certificate and intermediate are loaded and served): the current Firefox release (and…

Thanks! I can't seem to find the direct 'health-check' page though. Also, according to the spec, certificates sign a 'tbsCertificate' which contains all data of a certificate except for the actual signature and the field that determines what signing algorithm was used.

It's behind a login, but you can see the browser certificate chain in the browser UI itself. That should work for any Let's Encrypt certificate.

Re: Let’s Encrypt to transition to ISRG root

#92

So what motivates one CA to cross-sign another? I would have thought, if you were a CA you'd prefer not to enable your competitors - especially one who's planning to give away the product for free.

I don't think anybody at Let's Encrypt has spoken on this topic, but in their case specifically there are both moral and pragmatic reasons to choose to cross-sign. Morally is the easy one. If you work for a public CA you presumably think that the Web PKI is a good idea, and Let's Encrypt helped bring that benefit to lots more users, so that's a good thing. Consider the question of whether McDonalds should support a l…

It's worth noting here, too, that the vast majority of commercial CAs do not make a lot of money from their public SSL business. The public SSL business is viewed as a loss leader that provides a public profile and security assurance for the company, but most of them make far more money from their private PKI engagements (providing all of the certificates for a company's Active Directory infrastructure, e.g.). As such, Let's Encrypt enhances people's desire for certificates, but doesn't at all compete in the private-CA space where most CAs make bank.

Re: Let’s Encrypt to transition to ISRG root

#93
post #78
post #20

Earlier quoted context omitted.

This is in their latest blog post "Christine expands our board’s global perspective with her career experience. She worked for many years in the Australian government" I was wondering what impact if she, a board member of ISRG, has to comply with the Australian encryption laws?

Not that I actually would be at all, but hypothetical I would be more concerned with them hiring an Australian engineer than adding an Australian board member. What is the board member going to do to compromise operational security?

Influence hiring to get the engineer spy in. Also CIA docs have been published that said they had a system where people would purposefully tie down a company by being inefficient and causing beaucratic messeshttps://www.cia.gov/news-information/featured-story-archive/...

Re: Let’s Encrypt to transition to ISRG root

#94
post #49

Earlier quoted context omitted.

The reality is, for a bunch of usecases, you're gonna need to support 15 plus year old devices. So Windows XP... There are a lot of old systems out there running API's, automation, industrial systems, etc. They never get updates, and are expected to last decades. Most of them aren't on the public internet, but HTTPS would still be a good idea. This change is going to mean a bunch of them just get changed over to havi…

This is because the IdenTrust root is expiring though, it's not something LetsEncrypt can do anything about.

> it's not something LetsEncrypt can do anything about

This is going to cause a lot of stuff to break, and it's 100% LE's responsibility.

HN's root cert is valid through 2038.

LE could have gotten cross-signed by a cert that didn't expire so soon, but they didn't.

Re: Let’s Encrypt to transition to ISRG root

#96
post #19
post #12

Earlier quoted context omitted.

On Android, the root was first added in Nougat (~half of devices according to Android Distribution Dashboard). But I think that browsers (like Firefox and Chrome) on Android tend to bring their own cacerts rather than using the device's, so it's probably not as bad as it looks. To that end, it was added to NSS 3.26/Firefox 50 (November 2016) and to Chrome 57 (March 2017). On iOS, it was first added in iOS 10 (2016).…

I was eating breakfast with a multitude of Android phones around me and four "older ones" could not access that site. The oldest that could connect was ~5 months old, all using new Mobile Chrome versions.

I built an app that's used on thousands of Android devices in an industrial setting. Most of the devices were acquired last year.

Just tested with the new LE root cert and it doesn't work.

LE says "it's CA problem, not a Let's Encrypt problem", but that's disingenuous.

Let's Encrypt chose to get cross-signed by a root that expires in a couple years.

For example, HN's root doesn't expire until 2038.

This is definitely a Let's Encrypt fuckup that will cause many sites and apps to break.

Re: Let’s Encrypt to transition to ISRG root

#97

So what motivates one CA to cross-sign another? I would have thought, if you were a CA you'd prefer not to enable your competitors - especially one who's planning to give away the product for free.

Let's Encrypt is a nonprofit so all expenses on cross signing would be tax deductible. Also LE only does DV (not OV or EV, and only recently wildcards) and it has purposely short expiry times so it's not a 100% direct competitor.

Re: Let’s Encrypt to transition to ISRG root

#98
post #96
post #19

Earlier quoted context omitted.

I was eating breakfast with a multitude of Android phones around me and four "older ones" could not access that site. The oldest that could connect was ~5 months old, all using new Mobile Chrome versions.

I built an app that's used on thousands of Android devices in an industrial setting. Most of the devices were acquired last year. Just tested with the new LE root cert and it doesn't work. LE says "it's CA problem, not a Let's Encrypt problem", but that's disingenuous. Let's Encrypt chose to get cross-signed by a root that expires in a couple years. For example, HN's root doesn't expire until 2038. This is definitely…

> I built an app that's used on thousands of Android devices in an industrial setting

If its that important to you or if its a commercial offering in an 'industrial setting', you should have no problems acquiring a cheap SSL certificate from another source. You can literally get them as low as $6 a year right now.

LE provides a great service and continues to do so. If you want to nitpick, then jump to a 'competitor'.

Re: Let’s Encrypt to transition to ISRG root

#99
post #30

Earlier quoted context omitted.

Tested on a few tablets my company sell / used to sell : - FAIL Galaxy Tab 4 7" (SM-T230) Android 4.4.2 - FAIL Galaxy Tab A 7" 2016 (SM-T280) Android 5.1.1 - SUCCESS Galaxy Tab A 9.7" (SM-T550) Android 7.1.1 - SUCCESS Galaxy Tab A 10.1" (SM-T580) Android 8.1.0 I don't have any Android 6 device at hand, but this is consistent with @regecks statement "On Android, the root was first added in Nougat" (which is Android 7)…

Tried the test site on a Nexus 7 running Android 6.0.1, Firefox was ok (seems it ships with its own list of roots), but latest Chrome rejected it. My wife runs a blog which generates substantial income and uses certs from Let's Encrypt. It's a non-tech blog with primarily US readership. Checking stats for this month, 7% of all visitors were using Android 4/5/6 (20% of all Android users). The percentage of users on ol…

> a blog which generates substantial income

An SSL cert can be purchased for as low as $6 a year; if this is important to you, try buying one of those.

Re: Let’s Encrypt to transition to ISRG root

#100

Earlier quoted context omitted.

I don't think anybody at Let's Encrypt has spoken on this topic, but in their case specifically there are both moral and pragmatic reasons to choose to cross-sign. Morally is the easy one. If you work for a public CA you presumably think that the Web PKI is a good idea, and Let's Encrypt helped bring that benefit to lots more users, so that's a good thing. Consider the question of whether McDonalds should support a l…

It's worth noting here, too, that the vast majority of commercial CAs do not make a lot of money from their public SSL business. The public SSL business is viewed as a loss leader that provides a public profile and security assurance for the company, but most of them make far more money from their private PKI engagements (providing all of the certificates for a company's Active Directory infrastructure, e.g.). As suc…

There's no way that a multi-thousand dollar EV wildcard cert is a "loss leader".
Post reply on HN