3 ms·
I've updated the blog post. I don't think, though, it has any material impact on the rest of the text.
by dc352 10y ago
I've updated the blog post. I don't think, though, it has any material impact on the rest of the text.
- pfg 10y agoWhy not? Right now, compromised account keys give you the ability to issue certificates that are valid about as long as certificates are valid (or, in the worst case, +90 days from the original expiration date). Just about any scenario where the account key is compromised is one where the certificate's private key is compromised as well (not to mention typically one where you can just solve another challenge), so you're not really in a much worse position. Even less of a concern once authorizations are valid for only ~7 days.
- lol768 10y ago> I've updated the blog post You still state in your updated post that: "The surprising aspect is that Authz has a validity of 300 days (which is likely to be increased)" [emphasis mine]. This would appear to be incorrect based on the source cited above , where it is stated at "Eventually, we'd like to make authorization objects much shorter than certificate lifetimes, probably 7 days." Perhaps it's worth updating the post again in light of this?
- dc352 10y agoIt is an interesting one - here is the original source (and there were many more mentioning 300 days). https://community.letsencrypt.org/t/dns-authorization-lifetime-on-le-servers/17007/2 https://community.letsencrypt.org/t/dns-authorization-lifeti... It is from 14 June 2016 (a few months back), @pfg states "The CA/B Forum is currently developing new rules for domain validation and is probably going to settle on a validation period that is significantly longer than the 300 days currently in use ..." Is there an authority to say which way it will go?
- pfg 10y agoI think it's 36 months right now, but that's a Baseline Requirements thing, Let's Encrypt can (and does) use shorter periods. 36 months is the upper limit for all CAs. Let's Encrypt currently uses 90 days, and will go to something like 7 days in the near-future[1]. [1]: https://community.letsencrypt.org/t/upcoming-api-changes/17947 https://community.letsencrypt.org/t/upcoming-api-changes/179...
- lightedman 10y agoIf you don't mind, I'd like to add to your blog post. Token issues are something we solved about a decade ago. As to why LetsEncrypt has yet to learn these lessons, I leave that as an exercise to the readers and those familiar with security issues to discover for themselves.
- dc352 10y agoCan I attribute this to a particular name?