12 ms·
Let's Encrypt makes certs for 30% of web domains
- lsb 7y agoAuthor here. I'd figured they were big, but I had no idea that big until I did a www-wide TLS scan. Here for questions
- mmalone 7y agoKinda surprised that Google is so much bigger than Amazon...
- lsb 7y agoBlogspot!
- mmalone 7y agoThat's just stupid enough to be the answer :).
- simcop2387 7y agoKeep in mind that Amazon now offers their own free certs for customers that aren't from LE. That probably also has a big impact on things.
- mmalone 7y agoYea that's why I'm surprised that Google has issued more certs than Amazon has :P.
- tialaramex 7y agoYou list the ciphersuite that got chosen for each connection, but I think this could use at least a caveat explaining that the way this works means you'd need to do a LOT more work to figure out what the servers might have agreed to do for some other client. What I mean here is that TLS up until TLS 1.2 goes like this: Client: "Hi, I know ciphersuites A, B, C, D, E, F and G" Server: "OK, let's do C" And so you can't tell whether the server actually knows A, B, D, E, F, G or even I through Z. They just decided to pick C this time for some reason. In TLS 1.3 it's sort of better (all of the ciphersuites you shouldn't use don't exist any more) and sort of worse because now it goes: Client: "Hi, let's do method B, I'll go first, 123456 and a goldfish and the colour yellow" Server: "Cool, method B works for me, I pick 567890, a swan and mauve" Probably all TLS 1.3 servers today are willing to do anything method not just method B, since all the methods are shiny and new. But perhaps not, and you can't tell except by failing the connection which takes more round trips.
- jefftk 7y ago> Probably all TLS 1.3 servers today are willing to do anything method not just method B, since all the methods are shiny and new. But perhaps not, and you can't tell except by failing the connection which takes more round trips. You can have a round trip all the time, or just in the case where the client chooses an ciphersuite the server doesn't support. TLS 1.3 makes the typical cases much better without hurting the worst case much.
- achillean 7y agoWith regards to the supported SSL/ TLS versions you can get that information from Shodan. We do explicit handshakes using each version. For example, here is an overview of servers supporting TLS 1.3: https://www.shodan.io/report/unklm3m7 https://www.shodan.io/report/unklm3m7 Disclaimer: I run Shodan.
- walrus01 7y agoGiven that the population of browser useragents that only understand TLS1.0 and TLS1.1 is under 1% now, I've set all of my public facing apache2 httpd to only speak TLS1.2 and better. Have had things that way for about two years now and with zero reported usability issues.
- tpmx 7y agoThe GCP self-serving platform for certs is very welcome, but still kinda janky. You end up waiting hours for their batch jobs to run at unknown cycles. Let's encrypt is awesome because it's instantaneous! You'd think Google would understand that aspect. Edit: GCP people: Please give us a an explicit "retry" button to press when we've set up the DNS records. (I'm talking about the Google Cloud Balancing Service here. The UI was awesome up until the point it wasn't. The one thing lacking was a "retry" button.)
- sieabahlpark 7y agoIf you use Google cloud enough you'll soon realize they're not very fast at anything. Better hope you don't get your account automatically banned because one of your employees does sketchy things on their own personal account
- tpmx 7y agoI think you probably have an unrelated grudge here, at least judging from the contents of your comment before you edited it to make it less offensive.
- ZeroCool2u 7y agoHuh, I've had the opposite experience when setting up DNS on GCP App Engine. Things seemed to be quite snappy to me.
- tpmx 7y agoThe stars were probably aligned for you. Given DNS TTL there's a bunch of uncertainty here. My main feedback to Google is that having them periodically check back at an unanounced schedule, with no abilitity to force an an immediate check.. shows a total lack of understanding of customer needs. I mean, like... Yes, I understand that by default Google does things at scale, but sometimes you need to do things by precision/on demand, too.
- briffle 7y agoFor GKE, in beta, you can tell the ingress to get a TLS certificate automatically. Google will manage the whole process. The weird thing is, it uses letsencrypt. Since Google has their own Root CA, that seemed like an interesting choice. [0] https://cloud.google.com/kubernetes-engine/docs/how-to/managed-certs https://cloud.google.com/kubernetes-engine/docs/how-to/manag...
- sschueller 7y agoThis kind of centralization is not good. Even thought let's encrypt is non profit and has a very good service record. We desperately need more like it spread around the globe.
- FDSGSG 7y agoWhat problems would decentralization solve here?
- markstos 7y agoImproved security. So many sites are trusting Let's Encrypt and have cron jobs set to refresh data from them. If Let's encrypt were comprised or went offline, they are now a huge single-point-of-failure (or worse, single-point-of-exploit?) for all these domains. It's become a kind of monoculture. A more diverse ecosystem of offerings would be resilient to any single attack or failure.
- beardog 7y agoOn the flip side, more certificate authorities (who, remember, also have the ability to delegate intermediate authorities) also means more attack surface, because except in the case of key pinning (which is rare to my knowledge) any malicious authority or compromised authority's certs could be used to effectively intercept web TLS traffic. If let's encrypt was the only authority, yes that would be bad in many ways (and i'm not arguing for that) but it would mean less authorities to worry about. Anyone remember the bluecoat scandal? https://www.vice.com/en_us/article/78kkwd/a-controversial-surveillance-firm-was-granted-a-powerful-encryption-certifica https://www.vice.com/en_us/article/78kkwd/a-controversial-su...
- organsnyder 7y agoHow would adding additional CAs improve security? By the very nature of the CA trust system, each CA is itself a single-point-of-failure/exploit (though certificate pinning and other measures improve this somewhat).
- 7y ago
- hannob 7y agoA few of these things, while not necessarily wrong, should be put into context. E.g. "Hundreds of thousands of domains' certs expire after 2099". Yeah, but no publicly trusted certs. They're capped at a bit more than 2 years and there's a discussion to cap them even more. The certs they're seeing are almost certainly mostly: "let's create a test selfsigned cert for this host. how long should it last? let's type in a large number so we aren't bothered by it any time soon."
- tialaramex 7y agoYes, but... Historically there were some certs that kept getting grandfathered in after lifetimes were restricted because they'd been issued before there were any rules - maybe ten years to expire or even more? I think the last of those probably went away because of the Symantec distrust (not that they were issued by Symantec, but they were issued by a CA which was bought by a CA which in turn was bought by Symantec before it was distrusted) and also of course they'd have either MD5 or SHA-1 signatures, which are not accepted today anyway. There were still certs issued right up until the end of March 2018 with the old 39 month lifetime maximum. You can see them most easily in the annualised CT logs for 2021. A while back CT log operators realised that logs just get longer (of course) and so they would need to periodically make new ones and archive the old ones. Very quickly they struck upon the idea of annualising them, instead of running FooBar Log, run FooBar Log 2019, FooBar Log 2020 and FooBar Log 2021, and then require any submissions to use the log matching the year of expiry of the certificate they were logging. This way you can archive FooBar Log 2019 when people get back from holidays after celebrating New Year 2020, all the certs in that log are expired anyway now. I guess that today the last of those 39 month certs will actually expire before a brand new 825 day cert, but they are still out there, so don't write software that assumes leaf certs can't last more than 825 days just yet.
- quink 7y agoMinor point - SHA1 root CA certs are trusted by identity, so SHA1 is of no consequence.
- tikiman163 7y ago
- manishsharan 7y agocan someone please share how they deploy/distribute Let's encrypt certificates with auto renewal on load balanced multiple EC2 servers for the same dns name. I had tried this a while but had to give up and just bought SSL certs which I then include in my EC2 image.
- GuyPostington 7y agoYou can store the cert and key in a key/val store and each EC2 server would only need to renew the cert.
- aloknnikhil 7y agoHave you tried using Caddy? It handles automatic HTTPS (a.k.a Let's Encrypt) renewal across a fleet. https://caddyserver.com/docs/automatic-https#fleet https://caddyserver.com/docs/automatic-https#fleet
- linsomniac 7y agoI have, I set it up around 6 months ago on a couple of my own personal sites, and it seems to work pretty well. It took a while to figure out the right way to configure it for multiple site hosting, but it has been pretty trouble-free. The cert registration and renewal was really slick. If you want to see it "in action" on a single EC2 instance: https://pythoneers.org/ https://pythoneers.org/ I used an Ansible role to provision it, antonier77/caddy-ansible and it has worked nicely. But, as another comment mentioned: If you are in an AWS load balancer, you probably want to use the AWS certificates.
- manishsharan 7y agoCaddy seems nice but I am way too invested in Nginx
- mholt 7y agoThis reminds me... we have an nginx config adapter started. Would you be willing to help try it when we get it closer to being done? It will let you bring your nginx config and converts it to a Caddy config.
- mpaxd 7y agoMost hosting businesses have moved to LE. Hell even admin panels like Plesk have it out of the box.
- buboard 7y agoSSL certs sound like something that should be in a blockchain. Why isnt it?
- patmorgan23 7y agoBecause block chain is still new tech. Certs have been around for decades.
- hitpointdrew 7y agoBecause where is the incentive? Why would anyone be a "miner"? What reward would there be?
- buboard 7y agocould be a nonprofit, like letsencrypt
- Biganon 7y agoThat's not the point. In a decentralized system, every actor needs an incentive to mine new blocks in the chain. In cryptocurrencies, the incentive is the creation of new money attached to your name. But what if we're not dealing with a currency, but something else?
- buboard 7y agoyou are thinking of bitcoin. there are many different blockchain setups . and there is already namecoin
- MertsA 7y agoThe whole point of providing an incentive is to give a bunch of decentralized miners a reason to devote a reasonable amount of processing power to securing the blockchain. If there's only a single non-profit mining the chain, because why on earth would a bunch of other people throw money away for no reward, then for an attacker it's substantially more feasible to perform a 51% attack. For Bitcoin there's currently around $132,000 of incentive for mining given out every 10 minutes. In a race to the bottom that basically equates to a bit under $132,000 worth of compute resources expended for mining every 10 minutes. An attacker with enough resources to perform an attack on Bitcoin would have to spend more than that $132,000 every 10 minutes and keep it up for the duration of their attack. "Blockchain" for random hip projects more often than not is just buzzword nonsense that does nothing to improve security. A blockchain without mining is just silly, mining only works when it provides sufficient incentive such that attacking that blockchain is much more expensive than any payoff of attacking it is worth.
- FreeHugs 7y agoOne thing I don't understand about Let's Encrypt: Why do the certificates expire after 90 days? What would be the downside of giving them a longer expiration time?
- ceejayoz 7y agohttps://letsencrypt.org/2015/11/09/why-90-days.html https://letsencrypt.org/2015/11/09/why-90-days.html > They limit damage from key compromise and mis-issuance. Stolen keys and mis-issued certificates are valid for a shorter period of time. > They encourage automation, which is absolutely essential for ease-of-use. If we’re going to move the entire Web to HTTPS, we can’t continue to expect system administrators to manually handle renewals. Once issuance and renewal are automated, shorter lifetimes won’t be any less convenient than longer ones.
- tantalic 7y agoIf you loose control of the private key it limits the time an attacker could use it.
- Spivak 7y agoNobody actually checks certificate revocation lists so a compromised cert that’s valid for 5 years can be used maliciously for the full duration. 90 days was what they decided the best compromise for usability and security. Taken to the extreme ‘immediate’ certificate expiration starts to look a lot like Kerberos which is maybe what we always wanted.
- canofbars 7y agoThe security aspects have been covered but there is another advantage. When people get a 2 year certificate they very often forget to renew it until their website becomes broken. With a 90 day expiry you are pretty much forced to add a task to crontab that renews automatically.
- sideshowmel 7y agoCertbot is awesome! It really gives you no excuse not to provide https on your website.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- daveheq 7y agoThe article says "Current SSL cert lifetime best practices put lifetimes at 90 days" but SSL is deprecated... so its lifetime best practice is 0 days.
- sigmonsays 7y agodoes anyone care that letsencrypt and other CAs are sharing their certificate requests to indexers? It allows someone to discover every one of your HTTPS certificates that you've requested. For instance, here is some free rabbitmq clusters to use... https://censys.io/certificates?q=parsed.extensions.subject_alt_name.dns_names%3A+rabbitmq https://censys.io/certificates?q=parsed.extensions.subject_a... Default password of guest/guest works on http://rabbitmq.avtomain-crypto.com/#/ http://rabbitmq.avtomain-crypto.com/#/
- gsich 7y agoYou can use a wildcard cert too. With other possible issues.
- Operyl 7y agoYes I do care, and I agree that they should be doing so: I expect that CAs share these to Certificate Transparency logs, it’s a requirement to so that we can accurately find misissued certificates.
- tialaramex 7y agoI have some tremendously bad news if you thought that publicly accessible services on the Internet are secret. Several distinct outfits sell what they call "passive DNS" which is a feed of snooped DNS queries and their answers, minus any identifying information. So you don't need a certificate, if anybody, anywhere, looks up the name and it has an answer then these systems will tell you what it is. The records come through roughly like this: name: 'news.ycombinator.com' type: 'A' value: '209.216.230.240'
- fireattack 7y ago>Almost 1.6M domains had a cert that had recently expired (in July, the month of the scan). Almost 3.7M domains had a cert that expired in 2019 (the year of the scan). Over 9.6M domains had a cert that expired in the 2010s! This doesn't make sense. Even assuming you included the ones that had expired certs in "had a cert that expired in the 2010s", it would only be 1.6+3.7~=5.3M. Where does the rest 4.3M come from?
- hcs 7y agoThose are certs that not-so-recently expired, the heading is "Millions of certs served have expired".
- fireattack 7y agoAh, you're right.
- gator-io 7y agoWhen LetsEncrypt came out, I wrote a service (free) that monitors LetsEncrypt certs externally and sends alerts when they are close to expiring. It can be used as a backup to the automatic emails that are sent: https://letsmonitor.org https://letsmonitor.org
- kumarm 7y agoNice. Couple of things: 1. Why not integrate and let user monitor all their SSL certs for a domain in a single shot? Like retrieve all certs for a domain (similar to https://crt.sh https://crt.sh identity like search result) 2. When registered, I did not receive an email confirmation/validation. So I am not sure if I will get an email before my certs are up for renewal.
- hanoz 7y agoGood. Now who's going to do the same for domain names? And why hasn't this happened yet?
- prirun 7y agoThe thing that irks me about domain names is that registrars hold onto expired domain names and put them in their domain auctions. ICANN needs a new rule that registrars can't hang onto expired domain names for more than 30-90 days. From https://www.godaddy.com/help/when-can-i-register-an-expired-domain-name-572 https://www.godaddy.com/help/when-can-i-register-an-expired-...: "If the domain name is not renewed, redeemed, or purchased through an auction, it is returned to its registry. The registry determines when the domain name is released again for registration."
- nickpsecurity 7y agoThey give away paid products for free. Products that Google penalizes you for not having. Then, many people needing or wanting that product used their free alternative. I still don’t know if that vs version with more paying customers is a good thing in long run. Good for now, though.
- tracker1 7y agoIn practice, most CAs are over-charging for what should be highly automated (like LE). Other CAs also push EV and other certs that cost more, but don't really add much value in practice. In the end, the "free" version is good enough for most people. I would suggest if you're using it in a commercial environment that you consider setting up a scheduled donation. Which likely does help a lot for what they are doing.
- bane 7y agoCould be concerning, see https://blog.talosintelligence.com/2019/04/seaturtle.html https://blog.talosintelligence.com/2019/04/seaturtle.html
- lucb1e 7y agoIf you just want to post a link, I'd rather you submit a story with a title than put a "see, this is concerning:" in the comments. Moreover, I don't see how this article is relevant to Let's Encrypt's popularity. There are only two mentions in the article about LE, this is one: "These actors use Let's Encrypts, Comodo, Sectigo, and self-signed certificates in their MitM servers to gain the initial round of credentials." So they use normal public infrastructure to get certificates? That is concerning, how?
- asjid 7y ago124