5 ms·
Can anyone think of any advantages LetsEncrypt would provide over this offering from AWS? Or does this basically kill LetsEncrypt's usage on AWS? The only thin
by ubergeek42 11y ago
Can anyone think of any advantages LetsEncrypt would provide over this offering from AWS? Or does this basically kill LetsEncrypt's usage on AWS?
The only thing I can think of is that AWS Certificate Manager only validates by email addresses which can be problematic if you don't have MX records or don't have control over it(Maybe a large organization where the people who do control those email addresses won't click simple verification links)
It seems a bit inconsistent as to when it will use the email on the whois record for the validation too. For some subdomains I try it will allow validation using the whois address, other times it's just the common aliases@sub.domain.com(which requires an mx record)
So I guess if you're nesting deeper than one subdomain(e.g. abc.def.example.com) then maybe it'd be easier to get letsencrypt set up than try to get mx records for abc.def.example.com.
Shameless Plug/Disclaimer: I had been working on a tool to make it dead simple to use Lets-Encrypt certificates for CloudFront/ELBs and handled autorenewal via Lambda. I'm not sure there is any use for this now that this exists though.
https://github.com/ubergeek42/lambda-letsencrypt/ https://github.com/ubergeek42/lambda-letsencrypt/
- tal_berzniz 11y agoLetsEncrypt is automated, so for hosting services who wants to issue certs for customers - LetsEncrypt currently wins
- kevincox 11y agoI believe this requires the use of cloudfront or their load balancer. So if you want to stick with minimal costs you can use letsencrypt with just an ec2 instance.
- ubergeek42 11y agoThat's a good point. For some reason the only thing I was thinking about was cloudfront/elb.
- koolba 11y agoI don't think you have access to the actual private key file so this would be restricted to AWS services like an ELB. With letsencrypt you have the key file as well so you can use it for securing any type of connection (not just a load balancer front end).
- luma 11y agoMy frustration with these offerings is that they tend to only service public-facing HTTPS servers. There are a lot of use cases where valid certificates come into play, and a lot of them aren't facing the public internet or serving HTTP traffic.
- teddythetwig 11y agoIt depends on your security requirements as well. Some people feel the need for end to end encryption as opposed to SSL termination at the load-balancer tier. If you are one of those people, letsencrypt is the way to go
- rdl 11y agoIf it's all going in AWS, I don't see a huge difference between terminating in the ELB vs. terminating on the VMs. It might help you if the ELB got misconfigured, but AWS managing/provisioning the keys keeps them safe from being misplaced, too, so on balance it's probably better. If you had on-premise servers, or a different/more secure host vs. intermediary/load-balancer, I could see the value of end to end. (especially if you have a long-lived cert, a pinned cert, EV, whatever). (and of course crypto between the intermediary and the servers, if it's not on a physically secured LAN segment)
- plasticxme 11y agoSome forms of compliance require end-to-end encryption for certain transmissions. PCI is one that comes to mind.
- jlgaddis 11y agoFWIW, you don't need to have an MX for example.com to get a certificate for it. The e-mail addresses used for domain validation come from WHOIS and can be, e.g., you@not-example.com.
- IceyEC 11y agoplease actually use example.com. It's a domain intended for this usage (including with email!).