Live data from Hacker News

Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

letsencrypt.status.io

1–10 of 97 posts

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#5
That's really not good. Fortunately I'm not using any short-lived certificates like the recently announced 6 day certs, so have some breathing room. Without further details, I'd imagine anyone with a short-lived cert is getting a bit sweaty right now.

Let's Encrypt has become one of those pieces of critical Internet infrastructure that just quietly hums away in the background, the fact that they've stopped ALL issuance is deeply concerning.

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#6
Hopefully it's just a technical issue and not something like a key compromise. This could have disastrous effects considering how much of the web runs on LE certs these days.

Granted if it's configured properly everyone should have 30 days of leeway before having to issue new certs...

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#8
post #6

Hopefully it's just a technical issue and not something like a key compromise. This could have disastrous effects considering how much of the web runs on LE certs these days. Granted if it's configured properly everyone should have 30 days of leeway before having to issue new certs...

"We have been made aware of a potential incident and are shutting down all issuance" seems to lean towards the latter and not simply a technical issue :(

Re: Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved

#9
post #4

There is one little-discussed down side to ever shorter-lived certificates...

Only if you’re reissuing right before expiration, which is a stupid thing to do. If you have a 47-day cert, best practice is to reissue on day 30, meaning LE would need to be down for more than two weeks before anything went wrong.

If this outage breaks your system, that’s entirely on you, not Let’s Encrypt.

Post reply on HN