5 ms·
HTTPS is a good idea for many (most) scenarios, especially when your traffic goes over uncontrolled/public networks, but depending on where you stand, it may no
by paws 10y ago
HTTPS is a good idea for many (most) scenarios, especially when your traffic goes over uncontrolled/public networks, but depending on where you stand, it may not be necessary for _all_ use cases.
For example if the boss gives you an hour to e.g. stand up a internal company-facing blog on a controlled network environment where you don't necessarily have hostile actors in your threat model, configuring HTTPS might not be your first priority.
Another counterexample you hopefully won't have to experience: if you have to support end users where their device's date and time may be incorrect, e.g. their laptop battery died and NTP hasn't kicked in yet, on page loads users would see a scary 'certificate not trusted' warning[1]. Fixing the laptop's date is a non-obvious solution for end users.
1: https://support.google.com/chrome/answer/98884?hl=en https://support.google.com/chrome/answer/98884?hl=en
- icebraining 10y agoRegarding internal sites, Let's Encrypt requires an external accessible domain, which you might not have (either because you use a local domain, or because it's firewall'ed from the net). On the other hand, the device date is less problematic nowadays, since Chrome recognizes this case and shows a specific message: http://4.bp.blogspot.com/-xOOCv0xLMxo/Vdu_Y8XlHeI/AAAAAAAADqA/JmmcXGVhLbo/s1600/your+clock+is+behind.jpg http://4.bp.blogspot.com/-xOOCv0xLMxo/Vdu_Y8XlHeI/AAAAAAAADq...
- pfg 10y agoDomains don't have to be externally accessible, they just can't be internal names (i.e. "made-up" domain names that you do not actually own), which is true for all public CAs. The DNS-01 challenge type does not require that you open any port, you just need the ability to create TXT records.
- icebraining 10y agoAh, right, forgot about DNS validation.
- newman314 10y agoUnfortunately, there are still idiots (sorry, I feel strongly about this) that somehow thought it was a good idea to use "internal" names. Now I face an uphill battle to get things corrected. ARGH.
- kuschku 10y agoWell, all domains are internal names, just in the root space . Not supporting internal domains is understandable, but requiring https for internal things is an issue.
- pfg 10y agoI'm not sure what your last sentence is referring to. Who or what is requiring https for internal things?
- kuschku 10y agoFor example, Chrome disables several JS features and APIs on non-https pages.
- pfg 10y agoOh, I thought you were referring to something on Let's Encrypt's end. For "real" internal names, internal CAs sound like the best option, and would work just fine with what browsers call "powerful features." For anything else, Let's Encrypt would work.
- kuschku 10y agoExcept, you can't use internal CAs anymore on Android devices. Adding CAs to those is now impossible since Nougat.
- pfg 10y agoAFAIK that is only relevant for apps. It is still possible to import CAs for browser traffic, for example, and it's still possible to opt-in to trusting custom CAs as an app. So this is only really a problem for non-browser apps that a) need to communicate with internal domains and b) are not within the control of the organization the internal domain belongs to. I'm sure use-cases like that exist, but they ought to be exceedingly rare.
- voltagex_ 10y agoWhen I last looked at the DNS-01 challenge type, I couldn't work out how to make it work with my DNS provider, Gandi. How does the DNS challenge work with the delay in propagation of new records?
- pfg 10y agolego seems to have a plugin for Gandi's DNS API[1]. Let's Encrypt always sends DNS queries to the domain's authoritative DNS server and doesn't cache any results, so as soon as your authoritative DNS server has the record, you're good. [1]: https://github.com/xenolf/lego/tree/master/providers/dns/gandi https://github.com/xenolf/lego/tree/master/providers/dns/gan...
- voltagex_ 10y agoAha! The project that was missing Gandi API support was https://github.com/AnalogJ/lexicon https://github.com/AnalogJ/lexicon - but it now has support. I'll look into lego, thanks.
- serge2k 10y agoThose aren't reasons to use Lets Encrypt, those are reasons not to use HTTPS. In fact in the former case the growing ease of using Lets Encrypt is a reason to look at it if you are in such a hurry. The latter seems like a pretty big reach. Oh, the user might see a cert related error so lets just toss out all security.