Let’s Encrypt DST Root CA X3 Expiration – September 2021
letsencrypt.org
Let’s Encrypt DST Root CA X3 Expiration – September 2021
1–10 of 72 posts
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#2Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#3At some point old devices that aren't receiving updates really need to go away, a good thing for security.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#4At some point old devices that aren't receiving updates really need to go away, a good thing for security.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#5All current FIPS accredited devices use openssl 1.0.X, so the lets encrypt cross-signing hack will essentially break multiple corporate networks until the next openssl fips module is released at the end of this year. And could take another 6 months to make it into live systems
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#6Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#7"In OpenSSL 1.0.x, a quirk in certificate verification means that even clients that trust ISRG Root X1 will fail" All current FIPS accredited devices use openssl 1.0.X, so the lets encrypt cross-signing hack will essentially break multiple corporate networks until the next openssl fips module is released at the end of this year. And could take another 6 months to make it into live systems
A FIPS device being unpatched or broken for a few months almost seems like the natural state of things, at this point.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#8"In OpenSSL 1.0.x, a quirk in certificate verification means that even clients that trust ISRG Root X1 will fail" All current FIPS accredited devices use openssl 1.0.X, so the lets encrypt cross-signing hack will essentially break multiple corporate networks until the next openssl fips module is released at the end of this year. And could take another 6 months to make it into live systems
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#9"In OpenSSL 1.0.x, a quirk in certificate verification means that even clients that trust ISRG Root X1 will fail" All current FIPS accredited devices use openssl 1.0.X, so the lets encrypt cross-signing hack will essentially break multiple corporate networks until the next openssl fips module is released at the end of this year. And could take another 6 months to make it into live systems
Afaik what lets encrypt did is not a "hack" and perfectly valid. It sounds like users who have FIPS requirement need to fix it for their won use-case since its a bug in what they use and already fixed for everyone else.
Re: Let’s Encrypt DST Root CA X3 Expiration – September 2021
#10Earlier quoted context omitted.
Afaik what lets encrypt did is not a "hack" and perfectly valid. It sounds like users who have FIPS requirement need to fix it for their won use-case since its a bug in what they use and already fixed for everyone else.
Many enterprises use a FIPS SSL proxy for all employees web traffic, so all websites with these lets encrypt will effectively be invalidated if the proxies are using openssl FIPs modules, same for FIPS client side applications