16 ms·
Our First Certificate Is Now Live
- Someone1234 11y agoThis is a tiny bit odd. So they have issued their first certificate, but they don't have cross-signing in place yet? So between now and november 16th they'll be issuing a whole bunch of effectively broken certificates unless people manually install their root CA? Why even push this today if you don't have cross-signing available? Without that Let's Encrypt is effectively broken out of the box. PS - I actually like Let's Encrypt and the work they're doing. I will be all queued up when they go live to grab one (and, yes, will put my money where my mouth is and donate). But doing this today without cross-signing seems strange.
- skorecky 11y ago> A cross-signature will be in place before general availability. https://letsencrypt.org/2015/08/07/updated-lets-encrypt-launch-schedule.html https://letsencrypt.org/2015/08/07/updated-lets-encrypt-laun...
- collinmanderson 11y agoWhat about after general availability?
- toomuchtodo 11y agoBaby steps. This is a huge step forward, and I'm willing to cut them some slack considering they're about to shake up an entire industry. EDIT: Kudos everyone working on Let's Encrypt. You're doing awesome work.
- ErikRogneby 11y agoFor real. This is so damn awesome I feel like letting out a Howard Dean like yell.
- willejs 11y ago+1, this is a huge step in the right direction.
- phire 11y agoIt's a bootstrapping process, I don't think they can be accepted as a root certificate until they have proved their automated issuing system it working. One way to prove that their automated issuing system is working, is to turn it on. Looks like they have set it up to only issue certificates for white-listed domains in the beta program, and they will switch to General availability in the Week of November 16th.
- _wmd 11y agoYou should read back over their blog to see how much planning has gone into this so far. This isn't a single-file LAMP app running on a VPS, they're setting up a CA trustworthy enough to have its roots in all the major browsers
- IgorPartola 11y agoAccording to TFA, Firefox already trusts this cert.
- callahad 11y agoIncorrect. Inclusion into the Firefox root store is being tracked in https://bugzil.la/1204656 https://bugzil.la/1204656 and has not yet been resolved. Firefox trusts the cert on TFA because letsencrypt.org itself is using a certificate signed by IdenTrust.
- IgorPartola 11y agoLooking at http://helloworld.letsencrypt.org/ http://helloworld.letsencrypt.org/ I see: > Let's Encrypt hasn't yet been added as a trusted authority to the major browsers (that will be happening soon), so for now, you'll need to add the ISRG root certificate yourself. Specifics will depend on your browser. In Firefox, just click the link.
- aroch 11y agothe iSRG root is not in FF[1][2]...you're visiting the http version of that URL. 1 http://idzr.org/y1pg http://idzr.org/y1pg 2 http://idzr.org/ee91 http://idzr.org/ee91
- callahad 11y agoAh, that is a bit misleading. When it says "just click the link," it's referring to the process for installing the root certificate. It should read "specifics will depend on your browser. In Firefox, just click the link [to the .der file, and you will see a prompt allowing you to trust it.]" It looks like this: http://imgur.com/dzC89xI http://imgur.com/dzC89xI Without importing the root, Firefox absolutely distrusts https://helloworld.letsencrypt.org/ https://helloworld.letsencrypt.org/, and will do so until Bug 1204656 is marked RESOLVED FIXED. :)
- schoen 11y ago
- joshmoz 11y agoWe need to demonstrate proper issuance under our root and gain confidence in our live systems before getting cross-signed. Issuing without a cross-signature for a bit is how we do this.
- dragonwriter 11y agoYou keep saying the word "broken" when nothing is broken at all, just the certificates are only useful in limited contexts.
- stevewilhelm 11y agoEven a "useful in limited contexts" clock is right twice a day.
- kcbanner 11y agoExcept this isn't a clock, it is an SSL certificate.
- mattdeboard 11y agooh
- yuvipanda 11y agoThey aren't making it generally available to the public yet, only to certain beta folks who know what they are getting. It isn't broken out of the box since it isn't 'out of the box' yet.
- andrewstuart2 11y agoI'm so excited for this to take off, and it's good to see they've taken the first steps, but can I at least download the CA Cert over HTTPS? Not sure how comfortable I am installing a CA cert I downloaded via HTTP, since that's kind of the whole point of this whole thing.
- _jomo 11y agoYou can download the cert via HTTPS from https://letsencrypt.org/certs/isrgrootx1.der https://letsencrypt.org/certs/isrgrootx1.der
- deleted 11y ago[deleted]
- joshmoz 11y agoFixed, thanks for pointing that out.
- andrewstuart2 11y agoNo problem :-) I actually noticed the link was HTTPS (presumably after you changed it) and thought I was taking crazy pills.
- nailer 11y agoHTTP version really should redir to HTTPS.
- deleted 11y ago[deleted]
- Someone1234 11y agoI don't understand what it is we should "beware" of? What's the perceived threat? In theory, even if the NSA themselves were creating these site certificates, because of how they're created (i.e. you generate the keyset yourself locally, they sign the public part), it should be secure. So as I said: What is the perceived threat condition here?
- andrewstuart2 11y agoThat's a great example, I'll have to keep it in mind. I'd never thought of such a great example that clarifies how strong the security is, and how it's orthogonal to the trust model.
- callahad 11y ago> because of how they're created (i.e. you generate the keyset yourself locally, they sign the public part), it should be secure. Note that if the CA has the authority to sign certificates, they don't need your private key. They can just locally create a CSR for your domain, sign it, and have their own equivalently valid certificate for your domain. Moreover, in the absence of HPKP, any CA can do this for any domain.
- nailer 11y ago+1 HPKP, also Certificate Transparency: http://www.certificate-transparency.org http://www.certificate-transparency.org Google requires CT for all EV certs.
- macspoofing 11y agoI don't know about the threat, but this solves one use case. A local server connection from a browser pointed at an online web service. For example, Plex which gives you a web-based directory of movies you own, but the movies themselves are hosted on your private server).
- lifeisstillgood 11y agoTo be honest I had not heard of them till now, and I am a bit confused even after reading some of their site... So if the difficult part of being a CA (which I think is verifying that I, Paul Brian, own and control the rights to barlcaysbank.com and should have a certificate in that name) if that bit is either not done (!) or is reliant on donations to be able to afford it, is this going to work?
- tokenizerrr 11y agoThis is not what regular style certificates verify. That is what Extended Validation certificates verify and they're not issued by letsencrypt.org and generally are a lot more expensive. The only thing that regular-style certificates verify (this is what current CAs do, you can also grab a free one with automatic validation at https://www.startssl.com/ https://www.startssl.com/) is that the person who controls the domain name has requested the certificate. This is usually done by serving a specific file over HTTP once, setting a TXT DNS record or responding to mail to postmaster@yourdomain.tld
- toomuchtodo 11y ago> This is not what regular style certificates verify. That is what Extended Validation certificates verify and they're not issued by letsencrypt.org and generally are a lot more expensive. I'd like to see LetsEncrypt move into this territory though. What current private business providers are charging for this service is border-line extortion.
- lifeisstillgood 11y agoBut the certificate is (supposed) to say we have verified that this person / organisation exists and is "allowed" this domain. Now if we extend the idea of every business or even human having their own (sub)-domain (lots of good benefits there) then we are in the territory of ensuring the CA's track you from birth - that's what governments do, and boy are they expensive. I think what I am saying is we either have CA we can trust or we dump the whole thing and go to web of trust
- ck2 11y agoEveryone repeat after me, wildcards, wildcards, wildcards. (just hoping they will appear next year) One more nail in the coffin of the ssl cert mafia.
- ocdtrekkie 11y agoAbsolutely. I badly need a wildcard cert to do any of the SSL-ing I'd like to do.
- bracewel 11y agoThe major problem with this is that the IETF validation working group hasn't come up with a definite procedure for deciding what the apex of a domain is, and how to validate control over all subdomains above it yet.
- dtech 11y agoDoesn't ownership of domain.tld also imply ownership of *.domain.tld?
- bracewel 11y agoThat's the relatively simple case, but there are a number of corner cases that make the process much more complicated. See https://github.com/letsencrypt/acme-spec/pull/97 https://github.com/letsencrypt/acme-spec/pull/97 for a discussion of why this was scraped from the ACME specification proposal.
- 0x0 11y agoI don't get it. Whoever controls the base domain could always just replace the NS records and point any subdomain wherever.
- the_mitsuhiko 11y agoI don't think the owner of "co.uk" should have the power to issue certificates for everything below it.
- deleted 11y ago[deleted]
- jonknee 11y agoIt's amazing that it takes a free provider to make things simple: https://letsencrypt.org/howitworks/ https://letsencrypt.org/howitworks/ I'd actually pay more than I do now for SSL certs to get that kind of simplicity.
- icebraining 11y agoSSLMate seems pretty easy as well: https://sslmate.com/ https://sslmate.com/ (No affiliation, I just saw their HN post some time before)
- nailer 11y agoI run https://certsimple.com https://certsimple.com: we only do EV certificates, we're the fastest place to get an EV cert, we check as much as we can before you pay us a cent, and our application process is 80 seconds.
- kolev 11y agoThese shameless plugs are getting really annoying. We know about you, we know CloudFlare and Let's Encrypt are kinda competitors with their free certificates, but you don't have to comment on each post about them. Really, stop annoying us - it doesn't do you any good, honestly!
- schoen 11y agoIn this case, the previous commenter was explicitly asking for advice about how to get certificates more conveniently today, so the replies about existing services that can do so seem quite relevant.
- kolev 11y agoOh, the commenter asked for the overly expensive EV type? Let's not be the devil's advocate. This is the wrong way to advertise. This is not the beginners corner. You advertise once, twice, three times, people remember, you can search HN - no need to annoy people till the end of the world. The company seems desperate for new business this way anyway.
- RyanZAG 11y agoDoes anybody know if there is any protection built in against MITM or DNS poisoning attacks? It feels like this makes network hop security far more important. If I'm able to insert a MITM or DNS poisoning anywhere between where letsencrypt.org's servers are and where it thinks the requesting server should be then I can generate a false certificate. For example, Amazon's DNS resolves for letsencrypt as 1.2.3.4 which routes along a set path - say 2.3.4.5 and 3.4.5.6. To verify that I control amazon.com, letsencrypt is going to try and fetch http://1.2.3.4/something http://1.2.3.4/something (through DNS resolving). If I can get MITM access on 2.3.4.5 and pass back /something to the request, letsencrypt is going to generate a certificate for me that I can use to say I am amazon.com for the entire world. Is there any protection against this built into letsencrypt for this? Maybe checking if amazon.com already has https:// https:// ? Although I'm not sure if there is any way to get around a DNS poisoning attack... In essence, this seems to mean that you can take a single successful MITM and turn it into a globally authorized MITM. Right?
- superuser2 11y agoAny CA performing domain ownership validation would be vulnerable to the same thing. If you can fake its WHOIS requests or make it appear as if the domain making the request does in fact have the "canary" file they told you to host to prove ownership, then you can get any CA to give you a cert for any site. You have to trust something.
- RyanZAG 11y agoAgreed - but by making this a fully automated system you open up an easily testable and repeatable source of attack. I don't think "You have to trust something" is really right in this case, as you're basically saying "You have to trust every single router between letsencrypt and every server on the internet". I guess it's correct that with most current CAs now automating a lot of this with minimal manual checks, this is probably happening already? I wonder how many amazon.com valid certs are floating around the place? (Or more likely, smaller sites where people wouldn't be checking if the cert is really valid). The original point behind the costs charged by Thawte et al was that they would actually validate that you're who you say you are. I guess that ship has sailed though.
- hartator 11y agoGetting NET::ERR_CERT_AUTHORITY_INVALID on https://helloworld.letsencrypt.org/ https://helloworld.letsencrypt.org/
- Buge 11y ago>Our cross signature is not yet in place, however this certificate is fully functional for clients with the ISRG root in their trust store. When we are cross signed, approximately a month from now, our certificates will work just about anywhere while our root propagates.
- Nadya 11y agoVisit it on http and it explains why. >Let's Encrypt hasn't yet been added as a trusted authority to the major browsers (that will be happening soon), so for now, you'll need to add the ISRG root certificate yourself.
- TazeTSchnitzel 11y agoLast year they did a talk at CCC. Well worth a watch. https://www.youtube.com/watch?v=OZyXx8Ie4pA https://www.youtube.com/watch?v=OZyXx8Ie4pA
- bdamm 11y agoThis whole effort is making me a little bit giddy! Viva la admin-friendly security!
- mahouse 11y agoI feel like these initiatives to make SSL available for everybody just lead to the same conclusion: EV will be the only viable alternative to show real trust, and EV is much, much more expensive than regular SSL ever was.
- notatoad 11y agoBut that's nothing new. If you need real trust, you need EV. The win from LetsEncrypt and any other attempt to make SSL more mainstream is the encryption, not the trust. If you're using SSL you're protected from some government and ISP snooping, and from having the contents of your message or webpage altered in mid-stream by a nefarious third party like AT&T.
- pjzedalis 11y agoI think people are making too big of a deal of SSL. So what if my browser connection to Target or Home Depot is encrypted?
- gboss 11y agoWell it's possible and reasonable that you don't want to have what products your browsing to be snooped on by some sort of MITM attack. While probably not from MITM snooping, Target found out a teenage girl was pregnant before her own parents, and sent her parent's address Diaper and Baby advertisements: http://www.forbes.com/sites/kashmirhill/2012/02/16/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-did/ http://www.forbes.com/sites/kashmirhill/2012/02/16/how-targe...
- pjzedalis 11y agoMy point is all this work and it's only a small part of the equation.
- cpach 11y agoWould you really want you credit card details to be sent in plaintext?
- bluesmoon 11y agoQuick question, apart from having a prettier website, what's the differentiator with StartSSL which is also free, automated, and open?
- gsnedders 11y agoCertificate revocation for free (which is a big deal!), commercial use for free, multiple hosts for free…
- 0x0 11y agoStartSSL might also refuse you if you try to request a certificate on behalf of a friend or a client, as they sometimes checks if WHOIS lines up with your identity validation. Quite the hassle for domain-validated certs :-/
- organsnyder 11y agoUnless things have changed drastically recently (it's been a little while since I've used them), StartSSL is not "open" for any meaningful definition of the word.
- eric_bullington 11y agoStartSSL is not free for any commercial sites, even tiny businesses or personal sites advertising freelance services.
- bluesmoon 11y agoWe used StartSSL for free when we started LogNormal. We were definitely commercial.
- schoen 11y agoIt might not always be enforced in practice, but StartCom's policy doesn't allow use of the free certs for a commercial purpose: > Class 1 certificates are limited to client and server certificates, whereas the later is restricted in its usage for non-commercial purpose only. Subscribers MUST upgrade to Class 2 or higher level for any domain and site of commercial nature, when using high-profile brands and names or if involved in obtaining or relaying sensitive information such as health records, financial details, personal information etc. https://www.startssl.com/policy.pdf https://www.startssl.com/policy.pdf
- charonn0 11y agoI checked the https demo using libcurl, and it failed unexpectedly with error code 35 (Unknown SSL connect error). I was expecting curl error 60 (untrusted certificate).
- MrRadar 11y agoThe test site requires SNI and only accepts TLS 1.1 and 1.2 with ECDHE/DHE+AES-GCM/AES-CBC ciphers[0]. I'm guessing whatever SSL library your libcurl is linked against only supports TLS 1.0, doesn't support SNI, or doesn't support any of those cipher suites (OpenSSL 0.9.x won't work with this site, for example). [0]: https://www.ssllabs.com/ssltest/analyze.html?d=helloworld.letsencrypt.org https://www.ssllabs.com/ssltest/analyze.html?d=helloworld.le...
- lilmeech_ 11y agodance song! daffy dance prod vivid official video worldwide soon new dance song hit the daffy produced by vivid! if you like music check this dance song out this is the the official video too the dance! tutorial on HOW to do the Dance coming soon make sure you guysa be on the look for more exclusive videos! this the link guys! https://youtu.be/Hub032PuylU https://youtu.be/Hub032PuylU
- stevewilhelm 11y agoAnyone tried installing their certificates on AWS or Heroku?
- schoen 11y agoWe do a lot of the client testing on AWS, but a bigger question might be which OS image you use.
- cbpy 11y agoyou got to use Google to sign-up for the beta... ?
- eric_bullington 11y ago-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 For the record, the cert I've downloaded (using SSL over the Let's Encrypt site) from the Let's Encrypt site has the following SHA256 fingerprint: SHA256 Fingerprint=96:BC:EC:06:26:49:76:F3:74:60:77:9A:CF:28:C5:A7:CF:E8:A3:C0:AA:E1:1A:8F:FC:EE:05:C0:BD:DF:08:C6 Works great. To install on Firefox, just click on the first certificate listed here, in der format (just be sure to 'view certificate' and compare with the SHA256 hash I list above): https://letsencrypt.org/certificates/ https://letsencrypt.org/certificates/ For Chrome users, you have to download the cert, then go under "Manage Certificates" in "Advanced Settings". Then click the "Authorities" tab and import button. To check the cert hash, you'll have to run the following on OpenSSL: You can check your own fingerprint using: openssl x509 -fingerprint -sha256 -in isrgrootx1.pem Command line users on Ubuntu and (I think) Debian can install it to all browsers at once using: chmod 644 isgrootx1.pem sudo mkdir /usr/share/ca-certificates/letsencrypt.org sudo cp isrgrootx1.pem /usr/share/ca-certificates/letsencrypt.org/isrgrootx1.crt sudo dpkg-reconfigure ca-certificates For the extra paranoid, this is the same cert that another user posted to a Github gist earlier this summer: https://gist.github.com/rmoriz/1211745a21bc6114e770 https://gist.github.com/rmoriz/1211745a21bc6114e770 And you can verify my GPG signature by fetching my PGP key here (note that the keybase profile is linked to this HN username): https://keybase.io/esbullington https://keybase.io/esbullington -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJV95CmAAoJELGyxBAnWFiCpF4P/0sxqdrobdKm02V2cadHWQX3 AqXEENlPoReoVazf6Xhr3xfcyLw7g798q7YG4Bd0XtZLwofTr8Hq2On4q9w6dufu 6yGv+PyBTqL2EiSvuyY1p29ieYJV3tqOLUTaYjlvf7YGS90wLphRsEF1RVOaKfLK J1HSfx5Gctl1IRqa3Lt4zK6pot8xOzvV2d6V+fW1V/Svx5ZrfEUgJ7hgcyrgCSzB wqKJNhpoZCK50iqzrBlwjByRA+yi4LJckzSZ97l2p86QfvSg8xeVuMWVT+Qw6Pll Lw+rlrh4sLtcVGTcc6qUfBa5FXfoNOfT0vL009uBz5UkCs0vTjmbOwfZTGAMxKgC fD9dfOY3f9lA87nxTCP7nKR/USbDJANztNdQ/14qJwKFVmdusAjvf8LR8MzaIi5Q aBiC6otSuAMDGOTPXJ3aex/v+pt1412K5CgLEq83zeTGK04OoEWV/MMzggT+UxH6 eUpChtwKtFQIjqagzhkWWgc6ti2Qy0PnvZZa36PfFa01iK4jOhRPH9aCkg5UQtbl MjMPF2gAbHwTGP8cSs+PIrFUYyEK8FgWW4HhXBVCbNgedIEjRJwuorr/Ug8D7mJk kx+nFENVIsjEHUa5k64fYYc4eRX244jKORvYxH/iwCvvpCaineBkVmXPIFGIBXqp EYdDJBWF/PWfMvjFYHL3 =es48 -----END PGP SIGNATURE-----
- cpach 11y agoThank you for posting the fingerprint, Eric.
- Walkman 11y agoHow a root CA goes into the trust store? I know Firefox embed them, so older versions of it will not include it. OS minor updates (Windows, OS X, ...) ever updates the trust store? How much time actually takes it before I can safely use it and be sure that the majority of browsers accept it?
- schoen 11y agoIn the short term, Let's Encrypt will be primarily trusted through an IdenTrust cross-signature, which should be created in the near future (and before Let's Encrypt certs are available to the general public). The cross-signature is a delegation of authority from an existing root CA to Let's Encrypt's intermediate CA, saying that Let's Encrypt should also be trusted to issue certificates. Browsers that accept IdenTrust's root, which is widely accepted today, will then also accept the Let's Encrypt certificates as long as the services that present them also present the certificate chain (which includes the cross-signature certificate). This will happen in parallel to Let's Encrypt's efforts to be accepted as a root CA, and is not dependent on it. For example, if Mozilla decided not to allow Let's Encrypt to be trusted as a root yet, past, current, and future Mozilla browsers would still accept Let's Encrypt end-entity certificates (with the proper chain) because of the cross-signature. This is discussed in https://community.letsencrypt.org/t/frequently-asked-questions-faq/26 https://community.letsencrypt.org/t/frequently-asked-questio... and is also described in more detail at https://letsencrypt.org/2015/06/04/isrg-ca-certs.html https://letsencrypt.org/2015/06/04/isrg-ca-certs.html
- paulgayham 11y agoSounds gay
- thingsilearned 11y agoCongrats Josh and team!!!!
- MertsA 11y agoWhat's the target audience of the beta program? I'd love to play around with this on a personal domain but I doubt that there will be more than 2 or 3 unique visitors between now and general availability. Do they want signups for the beta program irrespective of the traffic volume of the site or would toy site signups just be more of a hassle for someone to approve? The verbiage on that page isn't very clear on if there's some manual process for approving beta participants or if it's just grab 100 entries a week out of a Google Sheets page.
- chmike 11y agoI didn't see anything about the price of the certificates. Will it be free ?
- dgoujard 11y agoCertificats will be free
- simula67 11y agoSorry for asking a potentially dumb question : but is it possible for me to set up a domain name thecitibank.com and ask letsencrypt to issue me a certificate ? I can then create a login page to steal IPINs. Isn't that why we have humans in the loop for issuing certificates ?
- superuser2 11y agoWe don't have humans in the loop for issuing certificate; this can and has been exploited for fun and profit, with fun attacks like getting a cert for "citibank.com\0.mydomain.com" which used to trick the C strcmp in most browser certificate checking routines. Moxie has an entertaining talk: https://www.youtube.com/watch?v=MFol6IMbZ7Y https://www.youtube.com/watch?v=MFol6IMbZ7Y Your problem would be getting people to "thecitibank.com." Chrome, Firefox, and GMail would all eventually figure out it was a phishing site and warn users about clicking through to it.
- cbg0 11y agoActually it's automated in most places, simply requiring you to confirm a request via an e-mail address associated with the domain you're getting an SSL for (typically admin@ hostmaster@ webmaster@, though it varies between certificate providers).
- duskwuff 11y agoMost of the reputable CAs have some practices in place to check for keywords related to big brands and auto-reject certificate requests. (So you can't get a certificate for "login-facebook.com" or whatnot, for instance.)
- chetanahuja 11y agoThere's no requirement in the spec for using "reputable" CA's for certificates.
- johnnydoebk 11y agoCould you provide a few examples of reputable and not so reputable CAs?
- acd 11y agoIs there any possibility of peer2peer voting/vetting for certificate genuity?
- Vespasian 11y agoNo there is not. And I don't think they will/should ever go for it. After the CAcert experience, I don't believe community based certificate signing will work in the current TLS ecosystem.
- icc97 11y agoAny one else getting a 'Secure Connection Failed' error at https://helloworld.letsencrypt.org/ https://helloworld.letsencrypt.org/ in FF after adding the root certificate?
- Julio-Guerra 11y agowhy aren't they sponsored by google nor facebook...? isn't it the only way today to support "open internet" ?
- r0bbbo 11y agoCan anyone explain to me what the difficulties of producing secure certs are? What steps do you need to go through to get root CA approval?
- schoen 11y agoRoot CA status is conferred by the individual user-agent developers (for example, Mozilla, Microsoft, Google, Apple, among others). Some browser or OS developers may try to follow others' lead to avoid duplicating effort or creating big divergences in trusted status of a given cert. Each entity that maintains its own root CA list has its own policy and process that people can apply through in order to propose to become a root CA. For example: https://technet.microsoft.com/en-us/library/cc751157.aspx https://technet.microsoft.com/en-us/library/cc751157.aspx https://wiki.mozilla.org/CA https://wiki.mozilla.org/CA These programs have certain criteria, which became more formal and rigorous over time (it used to be quite informal when the CA system was first set up). One commonality is generally to get a WebTrust CA audit, and there are also rules and meta-rules for CAs from the CA/Browser Forum. https://cabforum.org/ https://cabforum.org/ This will require creating and publishing a certification policy and certification practice statement that have certain elements, and the auditors will look at those. There are also physical security issues. For example, CAs use hardware security modules (HSMs) to perform their signing. https://en.wikipedia.org/wiki/Hardware_security_module https://en.wikipedia.org/wiki/Hardware_security_module The HSM will sign requested data, but won't export its private keys into a less-controlled environment like the CA's web server. It's akin to storing your crypto keys on a smartcard, only more expensive. :-)
- stullig 11y agoI still don't get why Mozilla and Google don't accept CACerts. Couldn't a lot of this be solved by just removing the warnings?
- nailer 11y agoThey'll need to pass a webtrust audit, which covers how they handle their key material amongst others. Additionally the Microsoft, Apple and Android roots have their own extra requirements added.
- throwaway7767 11y agoIt always seemed odd to me how strictly CACert is treated given that TrustWave got a pass when they deliberately sold a root CA certificate for man-in-the-middle purposes. It's almost as if money is more important than key management practices.
- stullig 11y agoThanks for all the informed info. I was just always weirded out when my browsers forced me to perform 2-4 clicks because of untrusted connections when visiting websites of say the CCC (who just switched to StartSSL apparently). Or the CACert website itself. Always seemed to me like some kind of joke.
- thomasrossi 11y agoI seem to understand this works just fine with HSTS. I am wondering what happens to key-pinning?
- schoen 11y agoYou can also use key pinning with Let's Encrypt certificates. Hopefully a future version of the client will provide tools to make this more convenient.
- muyuu 11y agoCan this be used for .onion sites?
- octatoan 11y agoDoes anyone familiar with the "paid-for certificate industry" know if anything major is going to happen? I'd guess they're going to be inundated with lawsuits or something. Great work, by the way.