Six day and IP address certificate options in 2025
letsencrypt.org
Six day and IP address certificate options in 2025
1–10 of 166 posts
Re: Six day and IP address certificate options in 2025
#2If someone else did this, Mozilla would be threatening to remove them from their trusted roots.
IP address certs sound like a security nightmare that could be subverted by BGP hijacking. Which is why most CAs don't issue them. Does accessing the ACME challenge from multiple endpoints adequately prevent this type of attack?
Re: Six day and IP address certificate options in 2025
#3(Or I'll switch to a different ACME client I suppose)
Re: Six day and IP address certificate options in 2025
#4> Our six-day certificates will not include OCSP or CRL URLs. If someone else did this, Mozilla would be threatening to remove them from their trusted roots. IP address certs sound like a security nightmare that could be subverted by BGP hijacking. Which is why most CAs don't issue them. Does accessing the ACME challenge from multiple endpoints adequately prevent this type of attack?
Re: Six day and IP address certificate options in 2025
#5https://letsencrypt.org/2025/01/16/6-day-and-ip-certs/#short...
But... How often do these types of compromises happen? I can't say I've ever seen or heard of it happening.
Re: Six day and IP address certificate options in 2025
#6I am gonna try to run a DoH resolver on this and see how it goes.
Re: Six day and IP address certificate options in 2025
#7> Our six-day certificates will not include OCSP or CRL URLs. If someone else did this, Mozilla would be threatening to remove them from their trusted roots. IP address certs sound like a security nightmare that could be subverted by BGP hijacking. Which is why most CAs don't issue them. Does accessing the ACME challenge from multiple endpoints adequately prevent this type of attack?
Not true. CA's are explicitly allowed to omit CRL support for certificates with a lifetime <= 10 days.
> Short-lived Subscriber Certificate: For Certificates issued on or after 15 March 2024 and prior to 15 March 2026, a Subscriber Certificate with a Validity Period less than or equal to 10 days (864,000 seconds). For Certificates issued on or after 15 March 2026, a Subscriber Certificate with a Validity Period less than or equal to 7 days (604,800 seconds).
[…]
> §7.1.2.11.2 CRL Distribution Points
> The CRL Distribution Points extension MUST be present in: Subordinate CA Certificates; and Subscriber Certificates that 1) do not qualify as “Short-lived Subscriber Certificates” and 2) do not include an Authority Information Access extension with an id-ad-ocspaccessMethod.
* https://cabforum.org/working-groups/server/baseline-requirem...
OCSP does not seem to be mandated in the latest Base Requirements.
Re: Six day and IP address certificate options in 2025
#8Re: Six day and IP address certificate options in 2025
#9Re: Six day and IP address certificate options in 2025
#10* https://datatracker.ietf.org/doc/draft-aaron-acme-profiles/
The ACME spec is: