4 ms·
it depends, let's encrypt might be performing request from different sources (and then it would need a bigger BGP hijack to fake them)
by Manozco 8y ago
it depends, let's encrypt might be performing request from different sources (and then it would need a bigger BGP hijack to fake them)
- notriddle 8y agoIf LetsEncrypt is actually hosted within AWS, then a network request from them to Route53 might not even hit the public internet.
- tialaramex 8y agoYes, Let's Encrypt acknowledges that they perform their validations from multiple observation points on the Internet. They (intentionally) don't provide a list. This occasionally annoys people who have an idea like "I will firewall everything but whitelist Let's Encrypt" and then find out that while you're welcome to try to puzzle out some way to make this work, Let's Encrypt won't help you and when it breaks you get to keep both halves.