Live data from Hacker News

Our First Certificate Is Now Live

letsencrypt.org

1–10 of 263 posts

Re: Our First Certificate Is Now Live

#2
This is a tiny bit odd. So they have issued their first certificate, but they don't have cross-signing in place yet? So between now and november 16th they'll be issuing a whole bunch of effectively broken certificates unless people manually install their root CA?

Why even push this today if you don't have cross-signing available? Without that Let's Encrypt is effectively broken out of the box.

PS - I actually like Let's Encrypt and the work they're doing. I will be all queued up when they go live to grab one (and, yes, will put my money where my mouth is and donate). But doing this today without cross-signing seems strange.

Re: Our First Certificate Is Now Live

#3
I'm so excited for this to take off, and it's good to see they've taken the first steps, but can I at least download the CA Cert over HTTPS? Not sure how comfortable I am installing a CA cert I downloaded via HTTP, since that's kind of the whole point of this whole thing.

Re: Our First Certificate Is Now Live

#5

I'm so excited for this to take off, and it's good to see they've taken the first steps, but can I at least download the CA Cert over HTTPS? Not sure how comfortable I am installing a CA cert I downloaded via HTTP, since that's kind of the whole point of this whole thing.

You can download the cert via HTTPS from https://letsencrypt.org/certs/isrgrootx1.der

Re: Our First Certificate Is Now Live

#6

This is a tiny bit odd. So they have issued their first certificate, but they don't have cross-signing in place yet? So between now and november 16th they'll be issuing a whole bunch of effectively broken certificates unless people manually install their root CA? Why even push this today if you don't have cross-signing available? Without that Let's Encrypt is effectively broken out of the box. PS - I actually like Le…

> A cross-signature will be in place before general availability.

https://letsencrypt.org/2015/08/07/updated-lets-encrypt-laun...

Re: Our First Certificate Is Now Live

#7

This is a tiny bit odd. So they have issued their first certificate, but they don't have cross-signing in place yet? So between now and november 16th they'll be issuing a whole bunch of effectively broken certificates unless people manually install their root CA? Why even push this today if you don't have cross-signing available? Without that Let's Encrypt is effectively broken out of the box. PS - I actually like Le…

Baby steps. This is a huge step forward, and I'm willing to cut them some slack considering they're about to shake up an entire industry.

EDIT: Kudos everyone working on Let's Encrypt. You're doing awesome work.

Re: Our First Certificate Is Now Live

#8

I'm so excited for this to take off, and it's good to see they've taken the first steps, but can I at least download the CA Cert over HTTPS? Not sure how comfortable I am installing a CA cert I downloaded via HTTP, since that's kind of the whole point of this whole thing.

Fixed, thanks for pointing that out.

Re: Our First Certificate Is Now Live

#9
post #4

[deleted]

I don't understand what it is we should "beware" of? What's the perceived threat?

In theory, even if the NSA themselves were creating these site certificates, because of how they're created (i.e. you generate the keyset yourself locally, they sign the public part), it should be secure.

So as I said: What is the perceived threat condition here?

Re: Our First Certificate Is Now Live

#10
To be honest I had not heard of them till now, and I am a bit confused even after reading some of their site...

So if the difficult part of being a CA (which I think is verifying that I, Paul Brian, own and control the rights to barlcaysbank.com and should have a certificate in that name) if that bit is either not done (!) or is reliant on donations to be able to afford it, is this going to work?

Post reply on HN