15 ms·
Let's Encrypt is Trusted
- peterwwillis 11y agoRemember that you only need one of the hundreds of CAs (650 at my last count) to generate you a cert to essentially compromise a site's connection security. Free certs mean more sites will use TLS, which means there will be more targets, which means more incentive to start attacking the weakest CAs and/or their verification practices. But this is kind of a good thing, because after enough attacks on the old model, people will ask for an improvement or replacement of the model.
- alwillis 11y agoThanks to HTTP Public Key Pinning (HPKP), this is no longer a threat: HTTP Public Key Pinning, or HPKP, is a security policy delivered via a HTTP response header much like HSTS and CSP. It allows a host to provide information to a user agent about which cryptographic identities it should accept from the host in the future. This can protect a host website from a security compromise at a Certificate Authority where rogue certificates may be issued for your hostname. You can read all about it: https://scotthelme.co.uk/hpkp-http-public-key-pinning/ https://scotthelme.co.uk/hpkp-http-public-key-pinning/ And here are web-based tools for examining and generating HPKP hashes: https://report-uri.io/home/tools https://report-uri.io/home/tools
- peterwwillis 11y agoYou don't get to say there is no threat if almost every website today is vulnerable. First, this is optional software that almost every public server in the world is currently not using. It's like saying just because executable whitelisting exists that downloaded exploit payloads on operating systems is no longer a threat. If nobody uses it, the threat still exists. In addition to actually implementing it on your server, every single user still has to make a secure initial connection over a trusted network on every device they'll ever use to get to that site. But not every client even supports HPKP. There's lots of older software which doesn't support it, and IE doesn't support it at all, which by itself would leave 12% of all clients vulnerable. https://projects.dm.id.lv/Public-Key-Pins_test https://projects.dm.id.lv/Public-Key-Pins_test https://en.wikipedia.org/wiki/Usage_share_of_web_browsers https://en.wikipedia.org/wiki/Usage_share_of_web_browsers
- alwillis 11y agoYou don't get to say there is no threat if almost every website today is vulnerable. I didn't mean that literally the threat has been eliminated due to HPKP; it's yet another tool that can be used. First, this is optional software that almost every public server in the world is currently not using. It's like saying just because executable whitelisting exists that downloaded exploit payloads on operating systems is no longer a threat. If nobody uses it, the threat still exists. HPKP isn't software--just additional HTTP headers that pretty much every web server can be configured to send. In addition to actually implementing it on your server, every single user still has to make a secure initial connection over a trusted network on every device they'll ever use to get to that site. True; it's even described in the RFC: https://tools.ietf.org/html/rfc7469 https://tools.ietf.org/html/rfc7469 Key pinning is a trust-on-first-use (TOFU) mechanism. The first time a UA connects to a host, it lacks the information necessary to perform Pin Validation; UAs can only apply their normal cryptographic identity validation. (In this document, it is assumed that UAs apply X.509 certificate chain validation in accord with [RFC5280].)
- Gregordinary 11y agoIt isn't foolproof, user installed Root CAs or roots installed by 3rd party applications are given permission to override pins. So HPKP wouldn't protect against scenarios like Superfish. https://www.imperialviolet.org/2011/05/04/pinning.html https://www.imperialviolet.org/2011/05/04/pinning.html
- joshmoz 11y agoSee a Let's Encrypt cert in action: https://helloworld.letsencrypt.org/ https://helloworld.letsencrypt.org/ Nice work team!
- Animats 11y ago"This website does not supply ownership information."
- joshmoz 11y agoWe only issue DV (Domain Validation) certs. DV certs don't include ownership information.
- dangrossman 11y agoNeither does https://news.ycombinator.com https://news.ycombinator.com. That's the kind of certificate most websites have now.
- MrOwen 11y agoI thought only EV certs (where you have to turn in some sort of financial and other types of documents to prove you're a real institution) were granted that info in certs. And EV certs are the only certs that turn most browser's address bars green.
- nitrogen 11y agoI was unable to connect using a vendor-specific browser on an old Android 4 device. Is this a limitation of the LE cert, or a cipher suite issue with older browsers, or something else? Really looking forward to spreading HTTPS far and wide.
- joshmoz 11y agoChecked with a sysadmin. I'm pretty sure it's a ciper suite mismatch. The helloworld site is configured with "modern" settings from this page: https://mozilla.github.io/server-side-tls/ssl-config-generator/ https://mozilla.github.io/server-side-tls/ssl-config-generat...
- mholt 11y agoCongratulations LE team! Final Star Wars VII trailer and LE gets cross-signed. Best. Day. Ever.
- ersii 11y agoI would just like to point out the irony in using 'LE' as a short for Let's Encrypt, as 'LE' usually gets used for shortening Law Enforcement. (Also: Congratulations and well done, Team Let's Encrypt!)
- davidcollantes 11y ago"LE" is identified more with "Limited Edition," I think. At least in the US.
- Absentinsomniac 11y agoUsually folks say "LEO" for Law enforcement officer(s) afaik
- jpreiland 11y agoI always associate "LE" with "Lawful Evil", but maybe I'm a nerd
- bracewel 11y agoISRG, the org behind Let's Encrypt, is hiring! -- https://letsencrypt.org/jobs/ https://letsencrypt.org/jobs/
- johncolanduoni 11y agoIt just had to be right after I renewed my SSL cert, didn't it? :P
- mtgx 11y agoWell, we knew Let's Encrypt's rough roadmap for at least half a year now.
- dfc 11y agoThis is not a spur of the moment announcement. Their timeline has been publicized all over the place
- johncolanduoni 11y agoIt was a joke, I was well aware of the timeline. It hasn't moved to general availability anyway.
- davidcollantes 11y agoIt was only $10, right? :-)
- icelancer 11y agoHuge win for them - will help push SSL/TLS on everything. Can't overstate how important this is for the web. Now to get the word out to everyone! edit: initially said SSH. I blame the plane wifi
- landr0id 11y agoI think you meant SSL/TLS
- icelancer 11y agowow what a terrible typo, WTF. fixed thankfully
- MertsA 11y agocan you sign a cert for SSH? I know that you can add the SSH server public key fingerprint as a DNS record and sign an openSSH certificate with your own private CA but are there any public CAs who will sign SSH certs and would the ssh client even trust anything other than a manually added CA?
- bandrami 11y agoYou could, but SSH is used for actual security, and adding the variable of a third party makes that situation strictly worse. SSH keys are meant to be distributed through some side channel.
- darkr 11y agoYeah - [Open]SSH supports signing for host and user keys, and you can operate your own CA, and the certificates you issue can encode a signed set of permissions/access controls with them (E.g permit-agent-forwarding, permit-X11-forwarding, certificate life times) this functionality is IMHO vastly underutilised. OpenSSH certificates are not X509 certificates though, and out of the box SSH servers will not trust any public authority. Also, AFAIK CA cross-signing, intermediates and other things that are fairly commonplace in X509 land are either not supported or not widely supported in OpenSSH.
- scott_karana 11y ago> and we’re excited to be one big step closer to bringing secure connections to every corner of the Web. What steps are left now? :-)
- mholt 11y agoFrom what I can tell, they're polishing their CA software (Boulder), and getting the rest of their infrastructure and policies ready for GA.
- chetanahuja 11y agoto make TLS actually secure? http://www.theregister.co.uk/2015/10/19/snmp_bughunt_turns_up_vuln_in_libressl/ http://www.theregister.co.uk/2015/10/19/snmp_bughunt_turns_u...
- steve19 11y ago"We’re pleased to announce that we’ve received cross-signatures from IdenTrust" How is this beneficial for IdenTrust?
- mholt 11y agoRelated discussion: https://community.letsencrypt.org/t/what-is-the-business-model/310 https://community.letsencrypt.org/t/what-is-the-business-mod... It establishes IdenTrust as a more influential leader of SSL certificates on the Web. There are other ways CAs can make money, and this extra publicity will probably serve them well.
- cpeterso 11y agoIdenTrust is an interesting organization. IdenTrust is a bank consortium acting as a public key certificate authority and secure applications provider whose members include over 60 of the largest banks in the world. John Sculley has been IdenTrust's chairman since 2006. https://en.wikipedia.org/wiki/IdenTrust https://en.wikipedia.org/wiki/IdenTrust
- kruipen 11y agoPrisoner's dilemma?
- emmab 11y agoMaybe they are just being nice.
- jakejake 11y agoCan anyone who knows more than me say - is this the beginning of the end of the SSL cert selling business? Is there still value to buying an expensive cert from another vendor?
- dogma1138 11y agoInsurance if something happens, beyond that nothing.
- alfredxing 11y agoLet's Encrypt is also limited in that it issues Domain Validated certificates only. They aren't planning on issuing EV certificates (the "green address bar").
- UnoriginalGuy 11y agoThey couldn't possibly issue EV certificates without charging. The verification requirements are too high. You need actual staff to verify.
- itistoday2 11y agoEV certs are a total waste of money. Pretty much everyone except maybe the site administrator won't notice and won't consider it a problem when a lock icon is shown instead of a green bar.
- aianus 11y ago> Pretty much everyone except maybe the site administrator won't notice and won't consider it a problem when a lock icon is shown instead of a green bar. I don't know if it's worth the money per se, but you can pin a couple of trusted CA root EV certs via HPKP and know it's much more difficult for someone to "accidentally" issue a valid cert for your site. If you do that, users won't see a lock instead of a green bar, they'll be blocked from accessing the site at all (if it's not their first visit and they're using a modern browser).
- jonah 11y agoChrome says they don't supply Certificate Transparency information. Is this something they should be doing?
- bracewel 11y agoThis is something we entirely plan on doing, in fact we currently submit all issued certificates to a number of CT logs (which can be viewed here https://crt.sh/?Identity=%25&iCAID=7395 https://crt.sh/?Identity=%25&iCAID=7395). Unfortunately the best candidate, at least for us, for supplying SCT receipts to end-users, via x509v3 extensions in OCSP responses, is currently not fully supported in Golang.
- okigan 11y agoCould somebody clarify: LetsEncrypt allows anybody to create certificate for any domain, so would not that allow anybody to create MITM certificate for any such domain?
- mholt 11y agoNo, it allows site owners to create a certificate for any domain they can prove they own. Then, the certificate has to be installed on the server serving the site. Using it from any other server will cause browsers to reject the certificate.
- alfredxing 11y agoLet's Encrypt does validate that you own the domain, using certain "challenges" involving the web server, etc. Their technical overview explains how it works: https://letsencrypt.org/howitworks/technology/ https://letsencrypt.org/howitworks/technology/
- dfabulich 11y agoAs a condition of being trusted, LetsEncrypt has promised to do "domain validation" before creating such a certificate. Domain validation is usually done by sending an email to the technical contact in the domain's WHOIS records.
- mjevans 11y agoIt can also be placing a file of authentication data at a chosen resource location within the domain in question. (which is, I think, what their tool automates doing)
- ubernostrum 11y agoLook at the tech overview: https://letsencrypt.org/howitworks/technology/ https://letsencrypt.org/howitworks/technology/ You can only obtain a certificate for a domain if you can validate that you control the domain. Their steps for that (place arbitrary content at an arbitrary URL they request, or create an arbitrary DNS record they request) are such that, if you weren't the legitimate controller of the domain but could do those things, you wouldn't need a fake cert -- you'd already have pwned it thoroughly enough to be able to MITM it in other ways.
- NateDad 11y agoWhy python for the client software if you obviously already have Go experience in-house? Using python means you have to run all this virtual-env crap in a bash script, apt-get install a bunch of crap for setup and not support Windows. Seems like using a (nearly) dependency-free Go application for the client as well would have been a no brainer. Was it just a case of having more access to python devs, or were there other technical reasons? Anyone know? I bet this has been asked before, but not I'm turning anything up with google.
- mholt 11y agoI can't speak for them obviously, but here's a Go ACME client if you're looking for one: https://github.com/xenolf/lego https://github.com/xenolf/lego - we're using it in Caddy[1] to make HTTPS the default for websites. [1]: https://github.com/mholt/caddy/commits/letsencrypt https://github.com/mholt/caddy/commits/letsencrypt
- NateDad 11y agoWow, that's awesome. Nice work integrating this into caddy. Although, it makes me even more confused as to why they used python for the official client.
- est 11y ago> NateDad 28 minutes ago > Why python for the client software if you obviously already have Go experience in-house? Using python means you have to run all this virtual-env crap in a bash script, apt-get install a bunch of crap for setup and not support Windows. Seems like using (nearly) dependency-free Go application for the client as well would have been a no brainer. Was it just a case of having more access to python devs, or were there other technical reasons? Anyone know? I bet this has been asked before, but not turning anything up with google. wow what's going on here? Auto comment robot gone wrong?
- tlrobinson 11y agoThe client is written in Python, and the parent comment is ranting about it. https://github.com/letsencrypt/letsencrypt https://github.com/letsencrypt/letsencrypt
- SimeVidas 11y agoSo… we’re all still waiting for the client, right?
- mathrawka 11y agoNo, they have announced their launch schedule in the past. Here is the latest update: https://letsencrypt.org/2015/08/07/updated-lets-encrypt-launch-schedule.html https://letsencrypt.org/2015/08/07/updated-lets-encrypt-laun...
- SimeVidas 11y agoBut we are waiting for the client, no? If I understand correctly, the client will enable us to install Let’s Encrypt’s certificate on our web server. I assume, “general availability” is when the client will become available for everyone.
- ludbb 11y agogeneral availability means a certificate, that is accepted by all browsers, can be requested and fulfilled. Right now the closest thing we have is a waiting list + very few https servers answering with such certs.
- mathrawka 11y agoThe source for the client is here: https://github.com/letsencrypt/letsencrypt https://github.com/letsencrypt/letsencrypt However, their release schedule dictates when the service (yes, the client is part of this) is ready for use. Until then you are waiting for the service to be available.
- tokenizerrr 11y agoThe client is already available, but the API is still locked down to just the beta testers.
- bracewel 11y agoA quick look at all the certificates Let's Encrypt has issued so far can be found using Comodo's CT based crt.sh tool. https://crt.sh/?Identity=%25&iCAID=7395 https://crt.sh/?Identity=%25&iCAID=7395
- toast0 11y agoIt seems odd to me that the intermediates were cross signed instead of the having the root be cross signed. With a cross signed root, clients with only the IdenTrust root will validate the cert, and clients with only the LetsEncrypt root can validate the cert. With a cross signed intermediate, the server has to guess which root the client has and serve the correct path, there's a TLS extension to indicate roots the client supports, but nothing actually uses it, so I don't know how the server is going to guess (other than to assume no one has the LetsEncrypt root, since it's new). [1] but some clients are dumb and won't validate successfully when they reach a root they know :/ Most browsers will though.
- j4cob 11y agoThis was a performance decision. Cross-signing the root instead of the intermediate would mean that web servers would have to include both the root and the intermediate in the chain they serve, rather than just the intermediate. That would add a full packet to each handshake.
- Natanael_L 11y agoWhy are there multiple intermediate certs? I don't know the details of the standard procedure.
- vog 11y agoIn case the main intermediate cert has been compromised and must be revoked, the alternative intermediate cert is already signed and can be used immediately for desaster recovery.
- zmmmmm 11y agoYay! Honestly, it is amazing to me that someone like Google or Amazon did not do this as free service a long time ago. But having an independent entity like this do it is far better.
- cinquemb 11y agoSerious question, to what degree is one defined as being independent? When you have "platinum" sponsors like akamai and cisco, and can take donations through paypal?
- zmmmmm 11y agoThey are a separate legal entity, with multiple independent sources of funding and a diverse range of board members[1]. I'm not sure about degrees of independence, but I would say this satisfies my criteria. Are you arguing they aren't really independent of their sponsors? [1] https://letsencrypt.org/isrg/ https://letsencrypt.org/isrg/
- cinquemb 11y agoI wasn't arguing anything just asking a question. But I will say that, without any numbers, its hard for me to say either way. Clearly, RSA was in independent legal entity, but a $x million dollar check didn't stop them from peddling shoddy crypto… though that's not something surprising to hear in this community.
- nodesocket 11y agoAm I missing where I can signup? Love to try them.
- bracewel 11y agoThe general availability period hasn't begun yet, but you can still sign up for the beta program here -- https://docs.google.com/forms/d/15Ucm4A20y2rf9gySCTXD6yoLG6Tba7AwYgglV7CKHmM/viewform?c=0&w=1 https://docs.google.com/forms/d/15Ucm4A20y2rf9gySCTXD6yoLG6T...
- bpicolo 11y agohttps://docs.google.com/forms/d/15Ucm4A20y2rf9gySCTXD6yoLG6Tba7AwYgglV7CKHmM/viewform?edit_requested=true https://docs.google.com/forms/d/15Ucm4A20y2rf9gySCTXD6yoLG6T...
- deleted 11y ago[deleted]
- vbezhenar 11y agoIs there some web interface to sign my certificate, similar to startssl? I don't really want to run new program in my server just to generate certificate.
- Natanael_L 11y agoYou could run it on a laptop to get the cert, then install on the server. But right now it remains an invite only beta until they get ready for general availability
- deleted 11y ago[deleted]
- cm2187 11y agoHas anyone seen anything re IIS integration? [EDIT] I have seen this: https://github.com/ebekker/letsencrypt-win https://github.com/ebekker/letsencrypt-win But ideally we would want Microsoft to add a checkbox in the UI of IIS Manager, which when creating a https binding offers to use let's encrypt instead of an installed certificate.
- lorddoig 11y agoBeing told that you now trust someone with your secrets via a news website is a pleasingly succinct display of everything that's wrong with the CA model.
- vonklaus 11y agoWe’re pleased to announce that we’ve received cross-signatures from IdenTrust This is what is wrong with the CA, model, not their method of announcing it to a community anxiously awaiting the arrival of their product. What is absurd is that identrust has a shitty non-responsive 90's looking website and wants $299 for an SSL certificate, which is something that should be free. I will say though, they really did sell me on their trust worthiness with the alternating images of a fingerprint and a lock. So now I know they're legit. It is worth the $99 for SSL on a single site annually because there is binary data superimposed on some of the pictures.
- sgc 11y agoI don't think he was saying they acted poorly by announcing on HN, but that he would prefer to grant someone trust rather than have it forced on him before he even knew about it. Not an easy task for a functional web, but it would obviously be better if possible.
- Natanael_L 11y agoThere's many ways, all obnoxiously complex unless you go back to a CA-ish voluntary trust model. Keys as addresses (I2P, Tor hidden services, CJDNS) fixes a large part of the security problem, then on top of that you can add your choice of address translation. WoT style individualized trust webs? Trusted lists of name assignments DNS style? First-come first-serve á la Namecoin?
- xorcist 11y agoNot necessarily. You could also place domain validated trust in the registrars, to cryptographically verify their delegations. That would build a chain of trust which you in turn could use to validate keys for services in those domains.
- imjustsaying 11y agoWow that's great. I signed up for the beta months ago, but I still don't have a 'free' certificate. Who the fuck are these guys?
- dadrian 11y agoCongratulations jdkasten!
- mangeletti 11y agoI truly appreciate the hard work Let's Encrypt is doing. However, this is not free. In return for getting an SSL certificate, your users will need to trust an organization to protect the secrets they share with you and vice versa. This organization has no economic incentive to do good for you or to do harm to you. What happens when this organization is compelled by the TLA to give up the lucky charms, and there is no team of attorneys to fight back, and no billions at stake, and there is a gag order? And, given the rate at which a "free" SSL certificate will proliferate, these will be some valuable lucky charms. This is not FUD. This is simply recognizing that "free" SSL certificates don't really address the issues that arise from centralized authority in a decentralized economy.
- vbezhenar 11y agoYou protect your secrets with your private key. That organization is only assures that this particular key belongs to your site. They don't have access to your key. Users don't need to trust anything they don't trust yet.
- mangeletti 11y agoWhich is the whole value proposition of a CA. Without this, a website and its clients are vulnerable to MitM attacks.
- computator 11y agoBut not vulnerable to passive wholesale eavesdropping that the NSA and likely other worldwide spies agencies have been doing.
- mangeletti 11y agoIf vulnerability to active spying is some sort of consultation prize, then why don't browsers disable CA checks and we can all self-sign?
- idibidiart 11y ago
- jamminn 11y agoSo, it's still all about trust then? I thought Let's Encrypt would go beyond trust.
- jrochkind1 11y agoWhat do you mean?
- balabaster 11y agoEr... you're trusted by a CA that's owned by a company that resides in Austin Texas... Texas hasn't exactly got a glowing reputation in the software industry due to its mountain of intellectual property lawsuits filed by patent trolls... er, sorry, I mean non-practicing entities Excuse me while I reserve some skepticism about just how trusted your security certificates should be.
- vtlynch 11y agoAbsolutely pointless and irrelevant. This is the same logic that Donald Trump uses to dismiss all Mexican people as rapists.
- balabaster 11y agoExcept that the courts are used there time and again to strong arm well meaning companies into paying millions out to fight frivolous lawsuits that run them into the ground. Exactly the kind of tactic you'd expect intelligence agencies to use to strong arm encryption companies into giving up their data.
- Karunamon 11y agoI'm not sure what you think CAs have to do with patent trolling. If there was a patent on the PKI, many large companies would have been sued already.
- balabaster 11y agoIt's not the patent trolling per se, it's the abuse of the legal system to strong arm companies into doing things they have no power to prevent that seems prevalent in that area of the country.
- gergles 11y agoI really dislike the fact that a CA is able to bless a new CA completely independently. Does this cause anyone else the slightest amount of anxiety, or am I just being paranoid?
- ColinDabritz 11y agoIt seems like its an important thing to be able to express. They are extending their trust to the new CA. I believe this information is available to clients if they wanted to choose to reject cross signing. You're right that this sort of broad power is scary, but I think it's being used reasonably in this context. Do you have specific concerns you are afraid of? The only problem I thought of was a compromised CA cross-signing a malicious CA, but if they are compromised, you could just issue the main CAs certs anyway.
- pugtor 11y agoIdentTrust is governed by their CP and CPS documents, which specify the criteria for delegating authority.
- belorn 11y agoWhats the alternative to CA being able to delegate signing? Would you prefer having browsers constantly being updated with new lists of CA's, maybe one new per day. Second, would you prefer that browsers blessed a new CA completely independently? If not then who should have that power? Governments? Non-profit organizations like ISRG? The big alternative is to maintain your own list of trusted CA's, going through each and every new CA that you encounter and associate a trust relationship. Not even famous security researchers do this, and I can't really blame them as it is like a lawyer reading every EULA that they encounter and fully investigate the scope of them. The scope and complexity just get beyond what a single person can manage.
- gergles 11y agoYeah, I guess I think it makes more sense for the browser manufacturers to be the people to whom I delegate that responsibility. I already trust them not to run malware on my computer and to accurately display the SSL state of a connection. I just think it's odd that any CA can turn around and make any other random CA fully blessed. It seems like it completely circumvents the browser manufacturers including root CAs at all. Totally agreed re: maintaining your own list of CAs. I mostly do go through the system CA list and disabling any from foreign governments I don't ever plan on trusting, but that's mostly feel-good and not actual security.
- josteink 11y agoFrom a comment on a similar reddit-thread[1]: > So thus beings the transition. EV certs are going to be the only ones that get the "green" chrome in browsers anymore. Sites using standard SSL are going to get the normal no-lock/white treatment. And sites without SSL will get the caution symbol/yellow treatment. I don't like it, but I suspect this is where we're heading. [1] https://www.reddit.com/r/linux/comments/3pg37u/lets_encrypt_is_trusted/ https://www.reddit.com/r/linux/comments/3pg37u/lets_encrypt_...
- cpach 11y ago"EV certs are going to be the only ones that get the 'green' chrome in browsers anymore." Are there any facts to back up this claim? Edit: This is what HN looks like in Firefox 38.0.5: http://img4.imagetitan.com/img4/RsbN6Rsn61k2IMN/12/12_l.png http://img4.imagetitan.com/img4/RsbN6Rsn61k2IMN/12/12_l.png Sure, the background color is white, but there's still a padlock icon.
- jaytagdamian 11y agoImage not found
- cpach 11y agoI don’t know what happened there. Try https://i.imgur.com/cY0Kx6x.png https://i.imgur.com/cY0Kx6x.png
- StavrosK 11y agoAnd the advice will become "make sure the browser bar is not yellow", and everything will be safe by default, and everyone will be happy.
- 1K2bCjh1aH 11y ago./letsencrypt-auto Updating letsencrypt and virtual environment dependencies.....Command "python setup.py egg_info" failed with error code 1 in /tmp/pip-build-KgdEvk/ConfigArgParse
- cpach 11y agoHN is not a support forum. Please look here instead: https://community.letsencrypt.org/t/welcome-to-lets-encrypt-community-support/8 https://community.letsencrypt.org/t/welcome-to-lets-encrypt-...
- arkad 11y agoThis entry has 443 points how and I don't want to upvote to spoil it...
- franciscop 11y agoYes, finally. I've been awaiting this moment from the first announcement. Happy they made it (:
- tychuz 11y agoI'm all for native desktop and mobile applications, but in this case I'd actually love a web app - enter your domain, get certificate. Downloading a tool, reading man page, works out of the box only with apache/nginx - ehhh, seems like a lot of work, considering some comments touting 'user friendliness' compared to StartSSL.
- Natanael_L 11y agoBut you need to run something on the server to validate that you've got control of it on your domain. A web app isn't enough. The better solution is to integrate this tool into various server tools like Apache and Wordpress and in whatever else you might be running with a one-click installer.
- corney91 11y agoExcept a tool can be automated, and a webapp is a pain to maintain for more than one domain.
- throwaway7767 11y agoCan someone who's tried the client confirm if it's possible to get a key/cert out of it without having it mess with my configuration files? I'd like a manual mode, as years of sysadmin work have made me extremely skeptical of tools that try to automatically modify config files.
- EwanToo 11y agoThere's various simple clients springing up already which do that https://github.com/mail-in-a-box/letsencrypt_simpleclient https://github.com/mail-in-a-box/letsencrypt_simpleclient
- vog 11y agoThat was my initial impression, too. However, as far as I understood, there is an API that will just hand out the certificate. I guess they don't want it to be accessed by a web browser because they want us to regenerate and include a newer cert automatically. So you have a somewhat higher setup cost (setup automatic cert update rather than one-time download of your cert), but then you can't forget to update your cert over the years. I believe they also want this is be a fast desaster recovery. So if their main intermediate certficate is compromised, they can revoke it and hand out new certificates (using the backup intermediate cert) for all domains within a very short amount of time. Nevertheless, I would have preferred a good explaination about how to setup this process manually, rather then depending solely on their tool. (In case this process it too cumbersome without their tool, they should simplify it rather than hiding this in their tool.)
- technion 11y agoI have the same issue. I'm particularly partial to this edition: https://github.com/unixcharles/acme-client https://github.com/unixcharles/acme-client
- jdkasten 11y agoYes, there are now several options to manually attain the certificate. There is a "manual" mode, "Here is the file that you need to post, press Enter when you are ready to continue" There is a "standalone" option. If you don't have a webserver running, it will bind to port 443 and solve the challenge for you. There is also a "Webroot" option. Enter in your server's webroot and it will automatically post a file to .well-known and delete the file after validation.
- devit 11y agoThe next step should be to stop trusting any other CA, and have Let's Encrypt support EV certificates by working with other CAs and still requiring Let's Encrypt DV verification. This way, Let's Encrypt in particular would need to be breached for a successful attack, while right now it's enough to breach either Let's Encrypt or any other CA.
- cddotdotslash 11y agoIs there an easy way to pull out the cert and load it into an AWS ELB without running the client on the server it will eventually protect? I'm not a big fan of using software that auto changes my config files, plus you can't actually run scripts on ELBs.
- viraptor 11y agolet's encrypt uses ACME protocol for certificates. You can use your own tools to handle it - either automatically or manually. Their automated client is just a user-friendly wrapper.
- axx 11y agoThe big question: Does this mean we can now all use Let's Encrypt to generate new certificates without people running into problems?
- bifurcation 11y agoIn a word, yes. When a server uses a Let's Encrypt certificate, a browser will consider it as issued under an IdenTrust root CA, which the browser trusts. So it will consider the Let's Encrypt certificate trusted.
- callahad 11y agoIt means certs signed by Let's Encrypt will work just fine for people without any special setup. See https://helloworld.letsencrypt.org/ https://helloworld.letsencrypt.org/ for an example. This does not, however, mean that we can all start using Let's Encrypt. They're doing a slow roll-out before making certs generally available to the public. You can apply for the Beta at https://goo.gl/forms/kf0IGCeAk5 https://goo.gl/forms/kf0IGCeAk5, or wait until general availability later this year.
- axx 11y agoThanks!
- eyuelt 11y agoYep, if you get a certificate signed by one of their intermediate certificates, you're good to go.
- LukeShu 11y ago"Yes", except that general availability doesn't come until the week of November 16th.
- signaler 11y agoThis will still require early stage overhead for many people switching over / 'going dark all the things'. Even though Let's Encrypt's goal is to make the process of encrypting the Transport Layer seamless, ubiquitous and non-commercial. Take for example my setup. It sits on a private NGINX server, and is proxied through a public facing CDN. Trying to simply 'switch on' TLS involves absorbing academic style tutorials from multiple disparate sources, and requires me to have a background in DevOps and that I have at least tried some technical task like this before. In layman's terms: Unnecessary Early Stage Overhead. Now give Let's Encrypt a few more years and it will be a lot more seamless; possibly the default. It could possibly be 'baked in' to things like Softaculous, and cPanel, which are brilliant drivers for the success of web software. Digital Ocean staff are probably already working on a droplet with LetsEncrypt baked in...
- axx 11y agoI don't see how TLS is early stage overhead for someone runnig a private nginx server behind a CDN? Sure, someone with no devops skills at all will have a harder time, but it's for the better. Soon it will be The Way to install a webserver. Thanks to Let's Encrypt it's so easy to install TLS that nearly every future webserver tutorial will include it.
- wyldfire 11y agoDelicious irony: my employer's web proxy supplies their own certificate in place of the real one for https://letsencrypt.org/ https://letsencrypt.org/. Though, to be honest they do this for >90% of https sites, in my experience.
- UserRights 11y agoThe headline is wrong and not very clever for such a project. The project was able to get a CA to sign their keys, this is what happened. Using the word "trust" is simply wrong and might be interpreted as a too simple kind of propaganda after we learned a lot about the untrustable nature of a hierarchical certification infrastructure. Another, even bigger trust-breaking elephant in the room is the fact that this project is USA based - as long as US government and agencies are insisting on practices we know from authoritarian and anti-democratic states like e.g. China or Saudi-Arabia there is no way any US based project can use the word "trust" for their product description - it might be recognized as a simple lie by informed people. Questions to the project leaders: * you must obey US laws and therefore offer MITM access to every Let's-Encrypt "trusted" network stream - why aren't you educating your users about this serious limitation of your product? * why don't you rebase your project to a country where a government policy exists that is allowing companies to build trustable security based products?
- ascorbic 11y agoIt means it's trusted by all major browsers, which is what matters. You may not like the terminology, but that's what it's called.
- andrewmcwatters 11y agoI just want free TLS dude.
- jstalin 11y agoIf there's a government that you trust, then you're mighty naive.
- schoen 11y agoThere is no U.S. law that compels us to "offer MITM access to every Let's Encrypt trusted network stream". TLS sessions are negotiated between TLS clients and servers. Their confidentiality is guaranteed by that negotiation and the certificate authority, if any, doesn't have the server's private key and can't read the server's TLS sessions. What CAs have the power to do is misissue certificates. Using a CA's services generally does not increase your exposure to misissuance attacks by that CA. If Let's Encrypt misissues certificates, it could misissue them for sites that are not and never have been Let's Encrypt users, just as any other CA can issue certificates for any public Internet service. As I've said elsewhere, Let's Encrypt wants to use, and encourage others to use, technologies that limit our power to do the wrong thing, including HPKP and Certificate Transparency. We want more limits on our power and other CAs' power, not fewer, that lead to misissuance events getting caught and attacks on TLS users failing.
- vinay_ys 11y agoIn a mobile only world where your critical business runs only via mobile app do CA based SSLs even matter? Why not use your own CA with your own certificates and don't have to trust any CA?
- schoen 11y agoIf you're doing TLS solely with your own app, this is often described as a best practice -- avoiding exposure to the public PKI entirely. Personally, I'm typing this post into a web site using a web browser, so I appreciate that it has a certificate that my browser can validate!
- teabee89 11y agoAre they planning on not relying on a 3rd party root CA and instead, ask all browsers and OS vendors to include LetsEncrypt CA? IOW, is this [trusting IdenTrust] a first step, or is this the original goal?
- tkinom 11y agoInstead of 3rd party CA, wouldn't it be more secure if the browser will send a hash of website's public key to a few trusted websites and have them verified the public key is valid? If someone needs to create a fake CA/public key, they have to hack multiple trusted sites. It is not current https sys design, but would it be more secure?
- kej 11y agoThis is a temporary step. There are two versions of their intermediate cert, the one in this article that is cross-signed and another that is signed by their own root (which isn't yet included everywhere). There's a diagram on this page that explains the situation: https://letsencrypt.org/certificates/ https://letsencrypt.org/certificates/
- ausjke 11y agoWhat does this mean to a new user? Can I now get a ssl certificate? will it be cheaper, or even free? I saw they have a beta-program for the certificate but don't know what it exactly does.
- andrewrothman 11y agoI can't wait for Let's Encrypt to finally start signing certificates. The future of encrypted communications is among us, and it's going to be huge. Will definitely use this as soon as they open their doors to me.
- dSnapApjw 11y agoI like that statement "community trust"...much the same I have come to trust most of the wisdoms on this site. I for one-learn, and greater, I learn from each of you the value of clarity. So trust as David Abshire says, "Is the coin of the realm, the glue, the oil, (alternative energy-) ingredient."txs, dSnapAp. SFCA.