8 ms·
So an attack against one challenge doesn't deterministically succeed.
by codemac 9y ago
So an attack against one challenge doesn't deterministically succeed.
- stephenr 9y agoThe much greater likely scenario is an error in comms/le (such as this issues today) means Caddy will un-deterministically fail
- codemac 9y agoThat is a trade-off for false negatives rather than false positives. It is not an unreasonable choice when dealing with certificates.
- stephenr 9y agoThe default client recommended by LE (certbot) supports multi-challenge registration/renewal. I'm pretty sure I trust their judgement over that of the Caddy project, given their (Caddy) history of weird decisions that backfire and cause user issues.