3 ms·
No, he's specifically referencing the initial setup step of Let's Encrypt, where you don't have a valid HTTPS cert so Let's Encrypt has to connect to your serve
by ipsi 3y ago
No, he's specifically referencing the initial setup step of Let's Encrypt, where you don't have a valid HTTPS cert so Let's Encrypt has to connect to your server over HTTP, see here: https://letsencrypt.org/docs/challenge-types/ https://letsencrypt.org/docs/challenge-types/
And yes, technically he's not wrong. Well, technically he is wrong, in that it wouldn't be a MITM attack, exactly, but if an attacker can intercept requests sent to your domain by LE and respond however they want, they can generate an LE cert for your domain, even if you're not using Let's Encrypt. That said, they can't intercept generation of the LE certificate - the HTTP request is just to prove that you've got enough control over the domain to justify issuing one.
Using HTTPS wouldn't prevent that. I'm actually not sure how you would prevent that, short of removing HTTP-01 from the spec and requiring DNSSEC and so on. EDIT: I see a sibling comment pointed out that Let's Encrypt are aware of this, and are using "multi-perspective validation" to make requests from multiple regions, making this attack much harder to pull off (but never impossible, I suspect): https://letsencrypt.org/2020/02/19/multi-perspective-validation.html https://letsencrypt.org/2020/02/19/multi-perspective-validat...