3 ms·
> (Its the same complaint I have against Let’s Encrypt. They shoved down a policy which is antithetical to helping their mission.) Can you expand what you mean
by lwf 8y ago
> (Its the same complaint I have against Let’s Encrypt. They shoved down a policy which is antithetical to helping their mission.)
Can you expand what you mean by this? I'm drawing a blank.
- geofft 8y agoI assume they're referring to the 3-month certificate lifetimes, which all but force you to automate certificate renewal, whereas the 1+-year certificates of the past let you treat it as manual sysadmin work. This was based on a belief that automating certificate renewals is the right thing to do. Still, LE seems to be wildly more successful than IPv6. I suspect in part that's because they were more technically right - or at least it's more feasible to add the automation than to rearchitect an IPv4 network - and in part because you can do manual certificate updates. (For complicated and entirely uninteresting reasons, I do manual certificate updates on my personal website every three months using certbot certonly --manual and scp, and it works.) I'm also way more personally sympathetic to LE because they're pushing the change for security reasons (revocation doesn't work, so we need to move to very short-lived certs) and not mere elegance ones. Rolling out IPv6 as designed brings no security benefits either to the user or to the ecosystem, and carries quite a few potential security risks.
- saurik 8y agoI think another big thing with Let's Encrypt is that they are free while their legacy competitors cost money, which is on the brutal end of incentives.
- dane-pgp 8y agoIt's worth pointing out, in terms of LE being "wildly more successful", that this represents a single organisation, with a security critical role on the web, approaching a monopoly. That's actually a worse situation than if 100% of hosts on the internet supported (different but compatible implementations of) IPv6. Here is a chart showing the trend for LE marketshare (under the IdenTrust root): https://w3techs.com/technologies/history_overview/ssl_certificate https://w3techs.com/technologies/history_overview/ssl_certif... I really support LE's mission, and celebrate their success, but would feel more comfortable if a separate organisation tried replicating what they had done, running the same service but with distinct personnel and assets. For reference, here is another chart showing the run down of the remaining IPv4 supply: http://www.potaroo.net/tools/ipv4/plotend.png http://www.potaroo.net/tools/ipv4/plotend.png