5 ms·
Because revoking them will cause interruption to legitimate users, but doesn’t stop an attack. I’m just starting to think LE is more aimed at large organizatio
by wbond 7y ago
Because revoking them will cause interruption to legitimate users, but doesn’t stop an attack.
I’m just starting to think LE is more aimed at large organizations than people running smaller configurations. Which is fine, thankfully we still have traditional CAs. I just hope we don’t devolve into a monoculture of ACME-only SSL.
- M2Ys4U 7y agoACME-only isn't the problem, it's a Let's Encrypt mono-culture I'm concerned about. We could do with another LE-style service (or two) operated independently (both organisationally and geopolitically).
- wbond 7y agoMy point there was more about automation in the cert space could lead to traditional CAs leaving the space, in which case small operators like myself (handful of minor servers) would be forced down the automation route, which isn't necessarily a net positive.
- wbl 7y agoAbsence of automation is why the CA death penalty is applied so late due to the consequent disruption.
- ff317 7y agoYeah I'd love to see one or more additional free ACME issuers that are largely functionally-equivalent to LE, but in a different jurisdiction and under different management, with separate infrastructure, etc. One of the less-obvious reasons: for "serious" usage where you're also stapling OCSP responses, there's a dependency on the cert vendor's OCSP service. You can cache the OCSP outputs to get through short windows of unavailability, but if the vendor's OCSP goes offline for days or suffers some serious incident, it pays to have multiple vendors on-hand. There was such an incident with GlobalSign back in October 2016 (who's otherwise a pretty decent vendor!), so it is a legitimate concern. For "serious" use-cases, you basically need redundant live certs from redundant vendors, and not having a second LE-like option means one of those is still a legacy CA for now...
- sigio 7y agoThere's buypass.no / buypass.com ... they are a norwegian CA that also implements ACME. I have only used them for some testing certificates so far, that have not been deployed in the wild, but their server works, the certs are valid in all browsers, and they do upto 6 month valid certs iirc. link: https://community.buypass.com/ https://community.buypass.com/
- folmar 7y agoI'm using it in production with no trouble at all - I have one place where it's only possible to add SSL certs through a GUI so longer validity is a dealbreaker.
- Avamander 7y agoBlame other CAs for resting on their laurels and allowing LE to steal their marketshare.
- M2Ys4U 7y agoOh I'm not shedding any tears for legacy-style CAs. But just because the previous situation was bad doesn't mean that a LE monoculture won't also be bad (for varying definitions of "bad").
- Santosh83 7y agoI think it is more aimed at technically competent users, regardless of organisation size. It is not, as it stands, suitable for direct use by non-technical people who can nevertheless follow step-by-step instructions to purchase and install a certificate from the traditional CAs. Similar 'hold my hand' tooling isn't there yet for LE. Nothing about the protocol itself mandates such short validity periods though I presume? Nevertheless technical people bemoan average users clustering towards centralised web-hosts but forget the reality that hosting a website from your own desktop or a VPS is far from trivial even in 2020!
- deleted 7y ago[deleted]
- namibj 7y ago>Nothing about the protocol itself mandates such short validity periods though I presume? Actually, revocation is broken. Which is a large part of why LE uses 90 days.
- michaelbuckbee 7y agoLetsEncrypt has made the strongest headway in large organizations with thousands of domains like Shopify, Heroku, website builders, etc. as it hits a really sweet spot of usability (controlling the host lets them approve issuance), cost (free) and control (they can trigger mass refreshes).
- devrand 7y agoLE is actually following the rules outlined by the Baseline Requirements. "Traditional CAs" have a tendency to just ignore them when convenient. For example, Sectigo has misissued nearly every certificate since 2002, including ~11 million unexpired ones (as December) and decided to just ignore their duty to revoke misissued certifcates [1]. Should the rules be changed? Maybe. However, when you're giving an immense responsibility to CAs then public trust is paramount. Ignoring agreed upon rules whenever you find it convenient does not inspire much confidence. [1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1593776 https://bugzilla.mozilla.org/show_bug.cgi?id=1593776