LetsEncrypt Outage
letsencrypt.status.io
LetsEncrypt Outage
1–10 of 112 posts
Re: LetsEncrypt Outage
#2Re: LetsEncrypt Outage
#3Re: LetsEncrypt Outage
#4Did the LLM delete this as well?
Re: LetsEncrypt Outage
#5One notable exception is Cloudflare: They famously no longer rely solely on LetsEncrypt.
Re: LetsEncrypt Outage
#6I hope no one was migrating infra EOD West Coast
Re: LetsEncrypt Outage
#7Especially something that needed to be renewed every 90 or is it 40 days now. How about issuing 100 years certificates as a default?
Re: LetsEncrypt Outage
#8Shall we have some way of freely encrypting the web that is relying on one authority? Especially something that needed to be renewed every 90 or is it 40 days now. How about issuing 100 years certificates as a default?
https://cloud.google.com/certificate-manager/docs/public-ca-... (EDIT: Google is their own CA, with https://pki.goog/ )
The browsers and security people have been pushing towards shorter certs, not longer ones. Knowing how to rotate a cert every year, if not shorter, helps when your certificate or any of your parent certs are compromised and require an emergency rotation.
Re: LetsEncrypt Outage
#9Shall we have some way of freely encrypting the web that is relying on one authority? Especially something that needed to be renewed every 90 or is it 40 days now. How about issuing 100 years certificates as a default?
In a practical sense you likely wouldn't like the alternatives, because for most people's usage of the internet there's exactly one authority which matters: the local government, and it's legal system - i.e. most of my necessary use of TLS is for ecommerce. Which means the ultimate authority is "are you a trusted business entity in the local jurisdiction?"
Very few people would have any reason to ever expand the definition beyond this, and less would have the knowledge to do so safely even if we provided the interfaces - i.e. no one knows what safety numbers in Signal mean, if I can even get them to use Signal.
Re: LetsEncrypt Outage
#10Shall we have some way of freely encrypting the web that is relying on one authority? Especially something that needed to be renewed every 90 or is it 40 days now. How about issuing 100 years certificates as a default?
Caddy uses ZeroSSL as a fallback if Let’s Encrypt fails!