Live data from Hacker News

Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

letsencrypt.status.io

91–97 of 97 posts

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#91
post #34

Earlier quoted context omitted.

Letsencrypt is not the only acme authority. ZeroSSL is the other popular one. There are others.

ZeroSSL offered for free 3 single name certificates. The next plan was $180 yearly. Actalis offered unlimited single name certificates. Why are ZeroSSL more popular? Google offered unlimited certificates with multiple names and wild cards. But they required a GCP account seemingly. It would require to give Google personal information, a phone number, and automatic payment permission. And Google not disable your accou…

It's popular because Caddy uses it. I am not sure if it's default or just an option though.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#92
post #53

Earlier quoted context omitted.

Stopping all issuance is an pretty standard response if a CA thinks what they are issuing might be non-compliant in any way. It's an action we're required to take. It's not necessarily a sign of a more dramatic failure mode or key compromise. That said, the impact is the same for as long as the downtime lasts so it is unfortunate and we're sorry for the disruption. I don't think the premise behind short lived (six da…

> Short lived certificates are optional though, so if it's not worth it to you there are longer lifetime options. Are they going to be optional forever, or do you plan to eventually get rid of the longer lifetime options?

Ask the CA/Browser forum what they will insist upon

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#94
post #86

Earlier quoted context omitted.

Mine are automated. Somehow it reminds me of prayer wheels though...

Forcing certificates to expire in less than a year means people don't forget how to update them, which is a big benefit. And once people automate, short-lived certificates are a workable plan B for how to revoke certificates and have the revocation actually work. These are both reasonable goals.

> people don't forget how to update them

Seriously? I don't even remember how the letsencrypt auto renew service is called. No idea how I did the initial setup either.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#95
post #94

Earlier quoted context omitted.

Forcing certificates to expire in less than a year means people don't forget how to update them, which is a big benefit. And once people automate, short-lived certificates are a workable plan B for how to revoke certificates and have the revocation actually work. These are both reasonable goals.

> people don't forget how to update them Seriously? I don't even remember how the letsencrypt auto renew service is called. No idea how I did the initial setup either.

Yes, seriously. Forgetting how to set up the automation is a different and significantly smaller issue.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#96

Earlier quoted context omitted.

A lot of Let’s Encrypt is not the software but a bunch of auditing and process that ensure compliance and make it legible to the required auditors.

I understand there's probably a big thorny problem of duplicating the corporate process/policies on the human level that ensure compliance, but is the back-end software pipelining stuff to CT logs not also something that can be replicated? Or is it not part of the server side stuff which has been open sourced? https://letsencrypt.org/docs/ct-logs/

Our code for sending stuff to CT logs is fully open source. But that's the tiniest slice of our compliance regime -- the vast majority of it is things like audit logging certain events, preserving audit logs in specific ways for certain amounts of time, ensuring dual-controls on all systems, being both audited and penetration tested annually, maintaining firewalls and vulnerability scanning tools, etc.

It's absolutely possible to spin up another new CA; lots of folks have done so over the years. But having time, and money, and prior experience all help a lot.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#97
post #21

That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now. Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuan…

Wonder what incident that even could have been.

The NSA needed some certs to expire, so you can send plain text. Just to test it. They already have access to the CA, but, if it works easier, why not. /s
Post reply on HN