9 ms·
This is great news for organizations. I work at a large Fortune 150, and there are lots of services that require wildcard certs. We have a process to get these
by randomf1fan 9y ago
This is great news for organizations. I work at a large Fortune 150, and there are lots of services that require wildcard certs. We have a process to get these from our internal CA as well as a third-party - the internal CA is automated, but the third-party (for external services) can be slow and cumbersome, to the point where many departments just buy their own cert. And then a year later, they move on, forget, etc, and suddenly we have services that have expired certs and there's a scramble to fix them.
This move by Letsencrypt should hopefully make them the standard for any external service that doesn't require an EV cert.
- randomf1fan 9y agoAnd a quick follow up - our security team does not allow rogue * .company.com wildcards - they hunt down those sites and boot them off the network. They do, however, allow *.<service>.company.com.
- SallySwanSmith 9y agoCan you clarify who "our security team" is?
- wolfgang42 9y agoFrom the parent post: > I work at a large Fortune 150 [...] we have [an] internal CA (This was a lot clearer when there weren't so many other comments in between.)
- randomf1fan 9y agoSure - this was in reference to my top level comment, but I see that this dropped lower down the page. I work for a large Fortune 150, one that you've heard of, and we have a security team that is constantly scanning our network for weaknesses and potential exploit vectors. They will kill (firewall off) any sites that might compromise the network and tell the application owner to fix the issue before they allow it back on the public net.
- IncRnd 9y agoThat is excellent advice from your security team.
- Klathmon 9y ago>This move by Letsencrypt should hopefully make them the standard for any external service that doesn't require an EV cert. I'm kind of worried about this myself. No matter how well intentioned, secure, or "good" lets encrypt is, having a significant portion of the world's TLS be under one umbrella isn't a good thing. I'm hoping that we will begin to see other services pop up that are similar to lets encrypt (free, even using the ACME protocol) so that we don't have too many of our eggs in one basket here.
- randomf1fan 9y agoYes, that's a fair point. However, it's still better than having expired certs and a team trying to figure out who owns the app, trying to get in touch with them, asking them to update the cert, finding out that they are no longer with the company... It's even worse when the service is something that a small team created as a POC - which then became customer facing and mission critical, with the team having moved on to something else. And it's funny how often this happens over a holiday weekend. Yes, I know that the issues are deeper and more to do with large company process and bureaucracy than anything technical. But at least you can have secure services that don't fall over.
- problems 9y agoTo use a classic example, who's going to go to bat for you when they get a demand from a government agency - the EFF or the Hong Kong Post Office? I know where I'll place my bets. Go pull up your certificate authority list and ask yourself for each one of them if you trust that company more or less than let's encrypt. Let's encrypt publishes auditable logs of all issued certificates, they're backed by some of the biggest names in online privacy and I trust them much more than other CAs. I for one would be happy if I could delete all other providers from my browser. CAs ultimately are centralized and too trusting, giving that same level of trust to less trustworthy companies just damages the overall security of TLS. There's no distributed trust model for CAs, it's pretty much all or nothing, so in the case of CAs, distribution is not a security benefit like it is in say Tor or Bitcoin, but a problem as it means the attack surface has widened. Short of going to a new, completely decentralized solution like the proposed DNSSEC extensions or Namecoin, a single, very secure CA is probably better than a lot of not secure, often government influenced CAs.
- ynezz 9y agohttps://certificatemonitor.org/ https://certificatemonitor.org/ works quite well
- tokenizerrr 9y agoAs does any monitoring system (nagios, zabbix, etc) that any organisation should already have running.
- SGran 9y agoThis is a helpful use case. Could you message me so I can learn more? press@letsencrypt.org
- randomf1fan 9y agoUnfortunately I'm not authorized to publicly speak for the corporation, so I can't really give you any more details. Sorry about that.
- mark242 9y agoAnd let's be perfectly clear, EV certs are basically a moneygrab by CAs trying to provide some kind of value-add. It used to be that ecommerce sites would have to get an EV cert, now with Chrome desktop showing "Secure" in the address bar, the visual representation of an EV cert isn't nearly as important.