4 ms·
I wish Let's Encrypt had a plan to get cross-signed by a CA those older devices still trust.
by crazypython 5y ago
I wish Let's Encrypt had a plan to get cross-signed by a CA those older devices still trust.
- Aissen 5y agoWhich devices ? They did find a solution for most Android devices, and it is now the default chain provided via ACME.
- mrtesthah 5y agoHow about macOS for example? After September, Let’s Encrypt will become untrusted on all versions prior to 10.12.
- TonyTrapp 5y agoDoesn't macOS allow you to add new root certificates to its certificate store? If not, you could still use a browser that brings its own certificate store (e.g. Firefox). This is significantly different from locked-down or embedded IoT devices you have no control over.
- mrtesthah 5y agoOh, I keep my computer up to date. It's everyone else's computer that needs to work with my Let's-Encrypt-certificate-using software that's the problem.
- tialaramex 5y agoOne small piece of good news for Let's Encrypt is that it's so common chances are even your most hardcore fans, who presumably first notice this issue on your site because they visit so often, will then also get the same problem on half a dozen other sites they visit. This applies especially for the case where what goes wrong is exactly that the visitor doesn't trust ISRG and ceases to trust DST Root CA X3 when its self-signed root expires. A lot of other problems will bite those who get new certificates first, but this problem will bite every site with a Let's Encrypt certificate at essentially the same moment regardless. So at least the blame will be spread around thinly and for most users there will be an overwhelming impression they need to actually do something on their side and not just moan and hope the problem goes away.
- crazypython 5y agoiPhone 4.