3 ms·
They already disabled TLS-SNI-01 for new certificates because of security issues [1]. This was a major breaking change, without any advance notice, but nothing
by rkistner 9y ago
They already disabled TLS-SNI-01 for new certificates because of security issues [1].
This was a major breaking change, without any advance notice, but nothing melted down.
I'm sure the other validation endpoints are used a lot more, but the effect shouldn't be any different, especially if give a deprecation notice of a year or two.
[1]: https://community.letsencrypt.org/t/important-what-you-need-to-know-about-tls-sni-validation-issues/50811 https://community.letsencrypt.org/t/important-what-you-need-...
- slrz 9y agoWhile there was no world-destroying core meltdown, it was still super-annoying to deal with. Lots of code needed to be touched. I'd really like a comeback of a fixed TLS-SNI challenge as running a port 80 HTTP server just for LE sucks somewhat. DNS challenges exist and are useful but have more extensive infrastructure requirements. Nothing beats the ease of use of "just put the box up and it'll retrieve its cert as needed".