9 ms·
Six day and IP address certificate options in 2025
- likeabatterycar 2y ago> Our six-day certificates will not include OCSP or CRL URLs. If someone else did this, Mozilla would be threatening to remove them from their trusted roots. IP address certs sound like a security nightmare that could be subverted by BGP hijacking. Which is why most CAs don't issue them. Does accessing the ACME challenge from multiple endpoints adequately prevent this type of attack?
- dextercd 2y agoNot true. CA's are explicitly allowed to omit CRL support for certificates with a lifetime <= 10 days.
- throw0101c 2y ago> §1.6.1 Definitions > Short-lived Subscriber Certificate: For Certificates issued on or after 15 March 2024 and prior to 15 March 2026, a Subscriber Certificate with a Validity Period less than or equal to 10 days (864,000 seconds). For Certificates issued on or after 15 March 2026, a Subscriber Certificate with a Validity Period less than or equal to 7 days (604,800 seconds). […] > §7.1.2.11.2 CRL Distribution Points > The CRL Distribution Points extension MUST be present in: Subordinate CA Certificates; and Subscriber Certificates that 1) do not qualify as “Short-lived Subscriber Certificates” and 2) do not include an Authority Information Access extension with an id-ad-ocspaccessMethod. * https://cabforum.org/working-groups/server/baseline-requirements/documents/CA-Browser-Forum-TLS-BR-2.1.2.pdf https://cabforum.org/working-groups/server/baseline-requirem... OCSP does not seem to be mandated in the latest Base Requirements.
- samcat116 2y agoI wonder if they could mandate that IP address certs could only be issued for IPs owned by an AS that has RPKI enabled.
- crote 2y ago> IP address certs sound like a security nightmare that could be subverted by BGP hijacking. The attack scenario is exactly the same as hostname certificates, which are often validated by HTTP or TLS ACME challenges. > Does accessing the ACME challenge from multiple endpoints adequately prevent this type of attack? Yes. You'd essentially have to MitM all traffic towards the IP for it to work, and with more and more networks rolling out BGP origin validation a global BGP hijack becomes harder and harder to pull off. You'd still be in trouble if you expect your own ISP to be hostile, of course. Don't single-home with an ISP you don't trust, or stick with domain name certs and force DNS challenges.
- hedora 2y agoGiven this weakness in ACME, I don't understand why cloud providers don't provide transparent 443 proxying by default. I guess it's security theater.
- dextercd 2y agoI'm very interested in trying this. acme.sh is planning to support certificate profiles, so hopefully that'll be ready when LE's short-lived certificates become available. (Or I'll switch to a different ACME client I suppose)
- mholt 2y agoCaddy/CertMagic/ACMEz already support this in the latest commits. Should be ready in time for the production rollout!
- blakesterz 2y agoI don't disagree with anything they say here: https://letsencrypt.org/2025/01/16/6-day-and-ip-certs/#shorter-certificate-lifetimes-are-good-for-security https://letsencrypt.org/2025/01/16/6-day-and-ip-certs/#short... But... How often do these types of compromises happen? I can't say I've ever seen or heard of it happening.
- H8crilA 2y agoImpossible to say, as most people probably don't even know that their private key is stolen. I've personally seen it only once on a real certificate revocation. Yet another reason to have shorter lifespan.
- Spivak 2y agoIt's a pretty narrow threat model for Alice to get her cert stolen by Bob, be completely unaware that this has happened, and the means Bob used only works once.
- yjftsjthsd-h 2y agoIf they don't know they were breached, don't the odds favor the replaced key likewise getting re-stolen immediately?
- H8crilA 2y agoYes, but the odds are less than infinite, i.e. the probability is less than 1.0. At least some of such attacks take effort.
- ikiris 2y agoOften enough a protocol was made to deal with it. The compromises have mostly been kept quiet though or at least didn’t get much news traction.
- mholt 2y agoThat's the thing. We don't always know. Hence the need to reduce the attack lifetime.
- captn3m0 2y agoI remember being surprised when Cloudflare launched https://1.1.1.1 https://1.1.1.1 with a valid cert and I immediately wanted one, but couldn’t find an easy way to get one. I am gonna try to run a DoH resolver on this and see how it goes.
- yegle 2y agoFor others who don't know how certificate for IP addresses relates to a DNS-over-HTTPS server: https://blog.cloudflare.com/announcing-ddr-support/ https://blog.cloudflare.com/announcing-ddr-support/
- prdonahue 2y agoThis was a fun conversation. I remember calling Clint and Jeremy at DigiCert and asking: "hey we have this cool IP address—what are the odds you guys can issue a certificate for it?" I'm not sure if they had to dust off some code or process to do it, but they got it done really quickly once the demonstration of control was handled.
- DonHopkins 2y agoThe coolest easiest to remember ip address I ever used was mimsy.cs.umd.edu: 128.8.128.8
- snailmailman 2y agoI’m really glad they have a page on that IP. I use it decently often for “is the problem DNS?” troubleshooting. Because if zero pages load, but that one does, the issue is DNS. Ping is easy too of course, but I can ask people to type four ones with periods between into their search bar over the phone. No command line required.
- deleted 2y ago[deleted]
- crtasm 2y ago>We expect to issue the first valid short-lived certificates to ourselves in February of this year. Around April we will enable short-lived certificates for a small set of early adopting subscribers. We hope to make short-lived certificates generally available by the end of 2025.
- throw0101c 2y agoNote that ACME profiles are new, to the extent that the draft spec is (a) personal (and not prefixed with draft-ietf…), and (b) currently versioned -00: * https://datatracker.ietf.org/doc/draft-aaron-acme-profiles/ https://datatracker.ietf.org/doc/draft-aaron-acme-profiles/ The ACME spec is: * https://datatracker.ietf.org/doc/html/rfc8555 https://datatracker.ietf.org/doc/html/rfc8555
- mholt 2y agoYeah... thankfully, it's "pretty simple" for clients to implement. Just add a JSON field to your payload and that's it. (There's a little bit of error checking logic and input validation, like making sure the value is valid, but overall it's not too complex, unlike ARI, which is much more work.)
- mmastrac 2y agoWill this work for IPv6?
- ZiiS 2y agoYes, a forward looking org like Let's Encrypt would have said IPv4 if needed. Here is an example from Cloudflare https://[2606:4700:4700::1111] https://[2606:4700:4700::1111]
- wil421 2y agoWhy does the url say one.one.one.one in my browser?
- deleted 2y ago[deleted]
- mparlane 2y agoBecause it returns a 301 moved permanently with a header of location: https://one.one.one.one/ https://one.one.one.one/
- Crosseye_Jack 2y agoBecause your are redirected to one.one.one.one via the location header and 301 status code from the ip address. http://1.1.1.1 http://1.1.1.1 redirects to https://1.1.1.1 https://1.1.1.1 which then redirects to https://one.one.one.one https://one.one.one.one but the TLS cert on https://1.1.1.1 https://1.1.1.1 (or https://[2606:4700:4700::1111] https://[2606:4700:4700::1111] on ipv6) is still valid for the ipaddress otherwise your browser would put up a warning during the tls handshake.
- ape4 2y agoIts too bad it does the last redirect.
- Crosseye_Jack 2y ago
- rickette 2y agoKinda funny to call the current 90 day certs "long lived". When Let's Encrypted started out more than 10 years ago most certs from major vendors had a 1 year life span. Let's Encrypt was (one of) the first to use drastically shorter life spans, hence all the ACME automation effort.
- ryandrake 2y agoTo someone like me with hobby-level serving needs, the 90 day certificate life is pretty inconvenient, despite having automation set up. I run a tiny VPS that hosts basic household stuff like e-mail and a few tiny web sites for people, and letsencrypt/certbot automation around certificate renewal is the only thing that I seem to need to regularly babysit and log in to manually run/fix. Everything else just hums along, but I know it's been 90 days because I suddenly can't connect to my E-mail or one of the web virtual hosts went down again. And sure enough, I just need to run certbot renew manually or restart lighttpd or whatever.
- rfoo 2y ago... which means automation was not setup correctly and 90 days is still too long that you just tolerated it. If it was 6 days after a few turns you would have decided "fuck it I'm going to spend time fixing it once and for all".
- jonas21 2y agoOr perhaps, "I'm going to give up and switch to gmail once and for all"
- dingnuts 2y agothere are other email providers, you know. the choices are not "do it all myself" and "be Google's product."
- bolognafairy 2y ago
- Eikon 2y agoThis will get interesting for many CT transparency monitors which for many are already seeing scalability issues. I am operating https://www.merklemap.com/ https://www.merklemap.com/ and the current scale is already impressive.
- sebmellen 2y agoWhat a cool site. For a long time I've been looking for something exactly like this for discovery purposes.
- Eikon 2y agoThank you!
- mholt 2y agoI don't know much about CT requirements, but can't they prune data out of their logs after some time? Since the certs only last 6 days, the growth of the logs can be capped at some point right? If not now, provisions for such operations could surely be implemented, I imagine. PS. Neat site!
- Eikon 2y ago> I don't know much about CT requirements, but can't they prune data out of their logs after some time? Since the certs only last 6 days, the growth of the logs can be capped at some point right? That's what happens - logs are "expired" after a few years. But if you want to have an exhaustive monitor, you probably don't want to discard the records of expired certificates. > PS. Neat site! Thank you!
- o11c 2y agoHmm, I wonder if it's possible to do dedicated intermediate certificates that promise to only sign short-lived certificates for a single site? That way the CT-log could be taught to only keep the intermediate?
- deleted 2y ago[deleted]
- jabart 2y agoSix days? I can't even set the cron job to weekly. Maybe that is the point of this though from being on call I really hate thing restarting every day. Caddy, Nginx, HAProxy, and IIS all seem to handle certs without a full restart. MS SQL Server, nope.
- mholt 2y agoAFAIK, Caddy is the only integrated ACME client that is tuned for short-lived certificates. All its own self-signed certs are already 24-hour certificates, so 6-day certs will be no problem.
- yjftsjthsd-h 2y agoWhy would that matter? Replacing the cert and sighup'ing nginx or whatever isn't functionally different from doing it in-process.
- mholt 2y agoOh, my, yes it is :) (I don't have time to elaborate on this again right now, unfortunately.)
- jabart 2y agoYou have a link to a previous discussion on this? I'm curious if there is some hidden thing occurring or if just connection resets are happening or something else you are aware of.
- apitman 2y agoAs someone who has rolled my own cert updates and used Caddy, I much prefer the Caddy way.
- yjftsjthsd-h 2y agoI'm happy to agree that caddy is easier, but the claim here is that it's "tuned for short-lived certificates", which... I guess could be true, but I seriously doubt that it's meaningful (on the basis that reloading certs isn't exactly expensive on any other major web server, so even if the most obvious interpretation is true and the made it take, say, 100 ms instead of 1000 ms, but we're talking about reloading every few days, who cares?).
- everfrustrated 2y agoIt feels like there's something of an attack vector here with cloud providers who lease IPs for hours at a time. 1. Lease IP 2. Obtain cert (verify can receive traffic to IP on port 80) 3. Give IP back 4. Cloud provider gives IP to another customer 5. Bgp attack IP with 6 days. While I support the idea of IP certs I do wonder how thought through this is and what the future consequences for security are. I agree with another commenter here who said this should be limited to IPs behind RPKI. Possibly also needs a mechanism for IP owners to clamp the cert time to be below their IP re-lease policy. As an example a provider like AWS could require max certs of (say) 6 hours and ensure any returned IPs stay unleased for 6 hours before reissuing them)
- Retr0id 2y agoYou can do the same BGP attacks with regular domain certs, though. If you hijack the IP that a domain resolves to, you can answer HTTP-01 challenges.
- deleted 2y ago[deleted]
- toast0 2y agoIf you control the IP or domain via a BGP hack, you can get a certificate issued while you control it, as long as you control it from the perspective of their CA. You've got to be pretty lucky, or do a lot of IP cycling for your vector to be terribly useful. A paranoid user of IP certs would let their new public facing assignments settle for a week before using them; but I suspect few people will start using IP address certs, because of usability.
- athrowaway3z 2y agoI wouldn't write off the use of IP certs just yet. AFAIK IP address certs would provide a way to create a secure browsing context in your browser, which is required for service worker ('offline' background threads) and some File API, which could open up a new class of programs that host for friends and family.
- Retr0id 2y agoIf I wanted to get a cert for an IP address today, what the cheapest CA?
- mholt 2y agoZeroSSL I think will get you IP certificates with their cheapest plan. (Disclaimer: I work on Caddy, which is a ZeroSSL project; but I do so independently.)
- Retr0id 2y ago"cheapest" being the free plan, or the cheapest non-free plan?
- DonHopkins 2y agoCareful, sometimes free plans are more expensive than money! ;)
- apitman 2y agoIP certs improve a niche but interesting use case for me. I run a domain registrar that implements a simple OAuth2 protocol[0] for delegating domains/subdomains. I also have an open source tunneling tool called boringproxy that implements the client side of this protocol[1]. boringproxy needs to provide a callback redirect_uri to the oauth server in order to retrieve it's token, which it can then use for setting DNS records. However, it can't provide an HTTPS endpoint until it can set up those DNS records and get a cert. Chicken/egg. Currently the spec requires the server to implement a `GET /temp-domain` endpoint which creates a DNS record like 157-245-231-242.example.com which points at the client's IP. This lets boringproxy bootstrap a secure OAuth2 callback endpoint. IP certs would remove an entire step from this process. [0]: https://github.com/takingnames/namedrop-protocol-spec https://github.com/takingnames/namedrop-protocol-spec [1]: This is actually broken in boringproxy at the moment, but there's a demo video here: https://www.youtube.com/watch?v=9hf72-fYTts https://www.youtube.com/watch?v=9hf72-fYTts
- ray_v 2y agoThis feels like a disaster waiting to happen -- like what happens if (when?) Let's Encrypt suffers a significant outage and sites can't refresh certificates? Do we just tolerate a significant portion of the Internet being down or broken due to expired certificates? And for what tradeoff? A very small amount of extra security? Is this because certificate revocation is a harder problem to solve / implement at Internet scale?
- arianvanp 2y agoA 7 day outage seems rather unlikely no?
- pilif 2y agoIn average half of the certs would expire in half of the time. A 3.5 days sustained DDoS attack would cause half of the sites using a 6 day certificate to be offline.
- zzyzxd 2y agoI am not saying 6 days is long enough, but if your automation always wait until the last minute to renew certs, you may have more issues to worry about than the CA's availability. If I am going to use a cert with 6 days lifetime I will be renewing it at least once a day.
- ncruces 2y agoYeah, that conflicts with their rate limits, which I hope they'll revise under this scheme. https://letsencrypt.org/docs/rate-limits/ https://letsencrypt.org/docs/rate-limits/ For the “exact same set of hostnames” (aka. renewals) the rate limit is 5 certificates every 7 days. So you could do it every other day, if you can make sure there's only one client doing it. And they're very clear this is a global limit: creating multiple accounts doesn't subvert it. So you'll need to manage this centrally, if you have multiple hosts sharing a hostname.
- zie 2y agoMeanwhile Qualsys has a “vulnerability scanner” that says a certificate that expires in under a month is a level 1 vulnerability(ID #38174): https://docs.qualys.com/en/certview/latest/get_started/certview_qids.htm https://docs.qualys.com/en/certview/latest/get_started/certv...
- TacticalCoder 2y agoCuriosity killed the cat: is it possible to get a valid cert for IPs on private LANs, like for example 192.168.1.42 or 10.0.0.84?
- outworlder 2y agoGenerally I just get DNS names for those. It does 'leak' your internal host addresses but that shouldn't be an issue.
- tialaramex 2y agoNo. The certificates are for a claim that this is your IP, but it's not your IP, it isn't anybody's IP. Same way you can't get a cert for some.name.in-an-internal-domain-we-use-internally
- marginalia_nu 2y ago> Same way you can't get a cert for some.name.in-an-internal-domain-we-use-internally Sure you can, you just have to issue it yourself.
- remram 2y agoWhat are reasons to use a certificate for an IP? Why wouldn't you use a name? Someone already mentioned that it's needed for Discovery of Designated Resolvers (DDR) for DNS-over-HTTPS. Anything else?
- abrookewood 2y agoNames cost cash; maybe you don't need/want one.
- extraduder_ire 2y agoxip and https://nip.io https://nip.io are common workarounds for this. I can't remember if one or both are in the mozilla list of public domain prefixes though.
- extraduder_ire 2y agoIf you need https, but whatever device you want to serve to doesn't let you use hostnames.
- remram 2y agoLike what?
- JSTrading 2y agoHow are IP certs any good in the days of cloud? I presume they are used in instances where it’s tied to a “well known” ip?
- lowsong 2y agoIt's often very difficult to get domain names in large orgs, but very easy to get public IPs. An IP can be as easy as a couple of buttons to get a static IP and assign it to a cloud LB in AWS or Google Cloud. Domain Names usually require choosing a domain name (without picking a name that reveals internal project details), then convincing someone with budget to buy the domain, then someone has to manage the domain name forevermore. For quick demos, or simple environments, it'd easier to just get a static IP and use that.
- JSTrading 2y agoYeah so what happens when that IP is recycled in the Cloud?
- marginalia_nu 2y agoNot everything is catering to the cloud. Still plenty of people who rock their own servers.
- lmz 2y agoWhile we're on the subject of cert lifetimes. Is there a longer lived, public CA-issued cert for TLS client purposes? I sometimes deal with a relying party that insists on public CA issued certs for TLS client use, and then makes rotation very painful behind a portal with 2FA etc. This would be fine if public CAs issued certs for 5 years but they seem to be limited to 1 year now because of browser policy.
- nickf 2y agoServer certs will be losing the clientAuth EKU this year, so those will be out. SMIME certs may start to drop it too. I don’t know many CAs that will do a clientAuth only cert from a public CA, largely because it’s unnecessary. If it’s for auth, use a private CA.
- lmz 2y ago> Server certs will be losing the clientAuth EKU this year, so those will be out. Is this documented anywhere?
- chrismorgan 2y ago> The dns-01 challenge type will not be available because the DNS is not involved in validating IP addresses. Additionally, there is no mechanism to check CAA records for IP addresses. Is in-addr.arpa. not usable for these purposes? Given how you can do PTR records to map IP address to domain name, I had just assumed it would be at least theoretically usable for more, even if few or no hosts exposed it so at present.
- baby_souffle 2y agoThat just proves you have a way to manipulate DNS. Doesn’t prove you own the thing the IP routes to.
- mixdup 2y agoI mean that applies to DNS authentication for non-IP certificates, too
- baby_souffle 2y ago> I mean that applies to DNS authentication for non-IP certificates, too Right, but "show me you own foo.com" is a pretty reasonable bar to clear for issuing a certificate with a CN of "foo.com". Show me you own `1.1.1.1` by manipulating the DNS for "foo.com" is ... not quite the same.
- chrismorgan 2y agoYou seem to be misunderstanding. We're taking about https://en.m.wikipedia.org/wiki/Reverse_DNS_lookup https://en.m.wikipedia.org/wiki/Reverse_DNS_lookup. Either putting records directly on the in-addr.arpa. domain (what I originally had in mind), or if that's not possible, on the domain it points to (which seems a pretty watertight proof method).
- ranger207 2y agoWhat's the end goal here? A new cert per connection? I think if, hypothetically, that were the case, where Let's Encrypt validates the domain owner on every connection, then that'd move the attack surface from trying to get private cert keys to... other attacks, in general. Is there reason to believe that "other attacks" are less likely? Have there been many cases of should-have-been-revoked certs being used improperly?
- mholt 2y ago"Other attacks" are much more expensive and for much less gain.