Earlier quoted context omitted.
Letsencrypt is not the only acme authority. ZeroSSL is the other popular one. There are others.
ZeroSSL offered for free 3 single name certificates. The next plan was $180 yearly. Actalis offered unlimited single name certificates. Why are ZeroSSL more popular? Google offered unlimited certificates with multiple names and wild cards. But they required a GCP account seemingly. It would require to give Google personal information, a phone number, and automatic payment permission. And Google not disable your accou…
Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
91–97 of 97 posts
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#92Earlier quoted context omitted.
Stopping all issuance is an pretty standard response if a CA thinks what they are issuing might be non-compliant in any way. It's an action we're required to take. It's not necessarily a sign of a more dramatic failure mode or key compromise. That said, the impact is the same for as long as the downtime lasts so it is unfortunate and we're sorry for the disruption. I don't think the premise behind short lived (six da…
> Short lived certificates are optional though, so if it's not worth it to you there are longer lifetime options. Are they going to be optional forever, or do you plan to eventually get rid of the longer lifetime options?
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#93The title is misspelled. It's “Let's Encrypt”, with an apostrophe.
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#94Earlier quoted context omitted.
Mine are automated. Somehow it reminds me of prayer wheels though...
Forcing certificates to expire in less than a year means people don't forget how to update them, which is a big benefit. And once people automate, short-lived certificates are a workable plan B for how to revoke certificates and have the revocation actually work. These are both reasonable goals.
Seriously? I don't even remember how the letsencrypt auto renew service is called. No idea how I did the initial setup either.
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#95Earlier quoted context omitted.
Forcing certificates to expire in less than a year means people don't forget how to update them, which is a big benefit. And once people automate, short-lived certificates are a workable plan B for how to revoke certificates and have the revocation actually work. These are both reasonable goals.
> people don't forget how to update them Seriously? I don't even remember how the letsencrypt auto renew service is called. No idea how I did the initial setup either.
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#96Earlier quoted context omitted.
A lot of Let’s Encrypt is not the software but a bunch of auditing and process that ensure compliance and make it legible to the required auditors.
I understand there's probably a big thorny problem of duplicating the corporate process/policies on the human level that ensure compliance, but is the back-end software pipelining stuff to CT logs not also something that can be replicated? Or is it not part of the server side stuff which has been open sourced? https://letsencrypt.org/docs/ct-logs/
It's absolutely possible to spin up another new CA; lots of folks have done so over the years. But having time, and money, and prior experience all help a lot.
Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
#97That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now. Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuan…
Wonder what incident that even could have been.