5 ms·
We ensure Cloudflare customers aren't affected by LE's certificate chain change
- encom 2y ago>MITM-as-a-Service switches CA.
- jerjerjer 2y agoI'm honestly surprised they didn't roll out their own CA.
- nixgeek 2y agoThey said “today, we’re not a Certificate Authority” — seems to strongly suggest they might be working to become one.
- hedora 2y agoIf you’re worried about MITM, then TLS with unpinned certificates / third party roots of trust is a poor choice.
- superkuh 2y agoIt's hard to criticize them for this in this context and I think that's the point. Otherwise, "We are dumping Lets Encrypt and switching to some CA" doesn't sound quite as nice.
- behringer 2y agoSomeone should tell cloudlare that certificates expire for a reason.
- kdtsh 2y agoWhat reason is that in this context?
- rpigab 2y agoOld Androids and other systems where you don't get to update your root CAs mean that you can never add new CAs because too few devices trust them, or enfore new TLS versions because you have to assume that too many people use very old devices, maybe, I don't know, I'm not an expert, if someone can explain what really is at stake here.
- dividuum 2y agoI'm surprised they basically choose to ignore explicitly made CAA records, if they don’t match any of their CAs. Why bother with setting up CAA records at all if they will be silently ignored?
- kardos 2y agoIndeed. That seems wrong unless the clients have explicitly agreed to let CF manage CAA records
- skybrian 2y agoMost big changes like this get rolled out gradually, but an expiration date causes things to break everywhere at once. They can minimize that impact with this change. Other websites will break first. But I wonder if they will start using Let's Encrypt again later, in a more gradual way? For example, on any new websites that launch after the expiration date?
- floodedburner 2y agoRead this as LE = Law Enforcement What a poor title change.
- kingspact 2y agoMe too and I was confused.
- blissofbeing 2y agoWhich CAs will they be using instead?