5 ms·
Head of Let's Encrypt here. The question of whether or not revocation should happen has to be asked whenever a certificate compliance issue is being discussed,
by jaas 5y ago
Head of Let's Encrypt here.
The question of whether or not revocation should happen has to be asked whenever a certificate compliance issue is being discussed, regardless of how serious the issue is. That is a normal part of the process of evaluating an incident thoroughly.
We do not plan to revoke any certificates as a result of this issue.
An aside - I love how informed many of the commenters here are, thanks to you all for helping to explain what's happening!
- sigzero 5y agoThat you for the clarification and the letsencrypt service.
- u8mybrownies 5y agoThank you for let’s encrypt. Very grateful for your role in society.
- zaxomi 5y agoHi! Is your time servers synchronized to GMT (mean solar time at the Royal Observatory in Greenwich) or UTC (Coordinated Universal Time)? The RFC requires GMT, but most time servers synchronizes to UTC. It could be a difference of up to 0.9 seconds between GMT and UTC.
- wahern 5y ago> It could be a difference of up to 0.9 seconds between GMT and UTC. Not in this context. In the context of ASN.1, NTP, POSIX, etc, GMT is a timezone equivalent to UTC+00:00. UT1 and DUT1 don't figure into it.
- fanf2 5y agoGMT was abolished at the end of 1971, when the Greenwich observatory started distributing UTC as its official timescale. At that time the observatory was based in Herstmonceux, so GMT was calculated from a model rather than being based on observations made from the transit instruments in Greenwich.
- akersten 5y agoThanks for Let's Encrypt, it's truly an admirable service. I'm curious regarding "certificate compliance" - I thought the 90-day expiration was merely a Let's Encrypt policy to encourage good automation. Is this just a matter of holding yourselves to high standards, or is there a greater authority to which LE promised 90-days-exactly?
- jaas 5y ago90 days is our choice, 90 days and one second validity isn’t necessarily an issue. The issue is that we said in our CPS that the lifetime was exactly 90 days, and then we did something different, even if just by one second. The problem here is behavioral consistency with our own published policies. We now just say “less than 100 days.” An unfortunate side effect of being more specific and informative in these documents (e.g. saying our certs have 90 days validity) is that it ups our chances of noncompliance if we are off on something by a bit, even if it is a meaningless bit. There is an incentive to not be so specific so as to avoid situations like this.
- jiggawatts 5y agoI love your work! Any chance you could convince Microsoft to add Let's Encrypt as an "integrated" CA in Azure Key Vault? It's absolutely bonkers how much money I have to pay to get a certificate in 2021 for cloud services! E.g.: the App Service certificates are $70/year each or $300/year for a wildcard certificate. That's nuts. Reference: https://azure.microsoft.com/en-us/pricing/details/app-service/windows/ https://azure.microsoft.com/en-us/pricing/details/app-servic... I strongly suspect the reason Let's Encrypt isn't adopted more widely in cloud services is because there's no margin on a free service. This is why Microsoft, AWS, and GCP all carefully pretend that there are no free options, and make sure that it's a difficult uphill battle to use Let's Encrypt. E.g.: https://docs.microsoft.com/en-us/azure/key-vault/certificates/how-to-integrate-certificate-authority https://docs.microsoft.com/en-us/azure/key-vault/certificate... Notice how the document title is literally "Integrating Key Vault with DigiCert certificate authority". Not "Certificate Authority", it's the "DigiCert certificate authority". Apparently, HTTPS is now DigiCert's protocol, they're the gatekeepers, and you have to pay them money to use it. It boils my blood that 1KB files of random numbers still cost money, and the trolls under the bridge are still taxing everyone for what is now essentially mandatory for all web sites. If anyone here has a significant account with Azure, please apply some pressure to your Microsoft account manager next time you have coffee with them. This rent seeking for what should be free for everyone has to stop.
- mattmanser 5y agoAFAIK Azure do free ones now, I'm certainly using some free certs on Azure.
- jiggawatts 5y agoThey're not really free: "This feature is available for customers on an App Service Plan of Basic and above (free and shared tiers are not supported)." They're GoDaddy certificates, and their price is charged back through the App Service pricing. Similarly, Azure Front Door also has "free" certificates, but they just integrate it into the relatively high cost of the service. If you want certificates for some other unrelated IaaS or PaaS service... Microsoft says no. They want their margin. Back to GoDaddy: their attitude is very 1990s, so they sometimes use manual approval for certificates. This makes ARM Templates that normally take minutes to deploy just hang and take hours, or even fail. Worse, they don't use the DNS address in your request for validation of domain ownership. Instead, they determine the "TLD+1" with some heuristics. Unfortunately, there is no such concept in the Domain Name System itself, so this is unreliable at best. This approach is broken by design and cannot be made to work for many domains. For example, in Australia, App Service Certificates cannot ever be used for subdomains of act.gov.au, nsw.gov.au, and nt.gov.au! PS: For people who are unaware, the concept of the TLD is at best a fuzzy one, and is decided by the informally maintained Public Suffix list, which is currently managed by Mozilla. It's not an RFC, it's not a standard, and isn't suitable for certificate validation. See: https://publicsuffix.org/ https://publicsuffix.org/ This is one of the key philosophical differences between Let's Encrypt and GoDaddy. When issuing automated, free certificates, manual labour for validation is not a viable approach and hence Let's Encrypt eliminated all such sources of informal, error-prone, manually verified sources. GoDaddy hasn't changed their validation approach in decades, because for $70/year, this kind of inefficiency is acceptable. To put things in perspective: GoDaddy has a support phone number. For certificates! They're literally 1KB files with two numbers and some text in them. Why do they need support!?
- failwhaleshark 5y agoWon't it basically fix itself in 90 days and 1 second after all the certs are rolled anyhow now that it's on the radar?