5 ms·
I keep seeing people putting Lets Encrypt down. What is so wrong with it?
by kankroc 8y ago
I keep seeing people putting Lets Encrypt down. What is so wrong with it?
- hlieberman 8y agoFor the record, the US DoD /is/ using Let's Encrypt. https://crt.sh/?Identity=%25.mil&iCAID=16418 https://crt.sh/?Identity=%25.mil&iCAID=16418
- kiallmacinnes 8y ago> I keep seeing people putting Lets Encrypt down. That was not my intent at all. I use and love Lets Encrypt's service. The comment was intended more around the fact that the US Military (and many large businesses) would never, and should never, rely on a free service like that. Lets Encrypt is great, I love it, I'd personally use it for business - but if I'm that large, I'm going to need a support contract + binding SLA + etc with every IT vendor - Lets Encrypt doesn't do these.
- tialaramex 8y agoMaybe, but on the other hand, Let's Encrypt's organisation ISRG is a US charity, so it's not a foreign entity, and its nature avoids scenarios where the DoD gets ripped off. There aren't many US-based large CAs that would be in a position to offer the appropriate thing here, an API that all the DoD's disparate IT organisations can use to sort out certificates for outward-facing web sites, mail servers, etcetera. It would also be nice (for Congress in particular) for this not to add another budget line item. It appears that IdenTrust (the small CA that cross-signed Let's Encrypt) used to provide services into the DoD, perhaps they still do, and doubtless they'd like a juicy DoD contract for more of that, but are they in a position to offer ACME (or a proprietary equivalent)? Do they handle the scale to just shove 50 000 DoD site certificates out the door like it's nothing (which Let's Encrypt absolutely could)? Big Hitters in this space today are: Let's Encrypt, Comodo (British, not American), DigiCert (possibly an option), GoDaddy (surely not), GlobalSign (Belgian / Japanese). After that it's all small potatoes, and a five person company that issues less than a thousand certificates per week is not the right size for a DoD national contract. Long term the US Government had expressed interest via 18F in actually running a "real" CA, to be limited (in clients like Firefox that know how) to the .gov TLD but you can imagine it's not hard to add .mil there. However 18F is not what it once was under Trump. This is not a good time to be in Washington if your goal isn't to stuff as much cash as possible into your underwear and then waddle off into the sunset, so I'd guess the CA plan is back-burnered and maybe dead for good.