5 ms·
The LetsEncrypt root is in-house, not third party. Certificates are also cross-signed by IdenTrust, but once the LetsEncrypt root is in all major browsers, it w
by bearbin 11y ago
The LetsEncrypt root is in-house, not third party. Certificates are also cross-signed by IdenTrust, but once the LetsEncrypt root is in all major browsers, it won't be necessary to have a cross-signature.
That's not to say that they don't have some other motive for the 90 day expiry, but I don't think they need the support of major CAs for what they're doing at the moment.
- sandGorgon 11y agoI meant the cross signing. That is the big deal here. And I somehow have this nagging feeling that they were strong armed into the 3 month renewal policy. No other reason to not have yearly renewals. Even if they do get into Browser roots now, there are hundreds of millions of mobile devices out there that will not accept Letsencrypt without a cross sign. Lets face it Letsencrypt is dead in the water without Identrust (or someone similar). Its not a bug, it's a feature.
- vetrom 11y agoAs mentioned in the other threads, 3 month renewal provides a smaller risk window for compromised domains/certificates. This is important, considering that certificate revocation is not a universally solved problem, and that Let's Encrypt is aiming to radically increase the amount of certificate issues as a whole. No strongarming necessary, I'm pretty sure technical considerations ruled the day here.
- amatix 11y agoACMs roots are cross-signed by Starfield (GoDaddy iirc), while they wait for their inclusion in the browser roots... so I can't see a difference with LetsEncrypt? AFAIK either you have the processes/tech in place to secure your CA and issue certificates, or you don't. https://mozillacaprogram.secure.force.com/CA/PendingCACertificateReport https://mozillacaprogram.secure.force.com/CA/PendingCACertif... shows Mozilla's in-progress certifications -- including LetsEncrypt, Amazon, DocuSign, VISA, a bunch of governments, telcos, existing CAs, and others I don't recognise. Cross-signing is a pragmatic solution for older client devices (eg. abandonware Android phones) for _any_ CA root, new or otherwise.
- arcdigital 11y agoIt used to be GoDaddy, but Amazon bought and now owns/operates the Starfield Root CA that cross signed the Amazon CA.