4 ms·
Let's Encrypt had a higher error rate for 90 minutes today
- saagarjha 4mo agoSeems not ideal for an entity who seems to be pushing for shorter expiration periods all the time
- tonyhart7 4mo agoisn't this the other way around ??? because shorter expiration time resulting on more issuing cert and therefore make it more prone to downtime
- RetroTechie 4mo agoAnd perhaps more opportunities to insert bad certificate somehow.
- xp84 4mo agoI think it’s mostly Apple and maybe Google who have the hard-ons for the shortest expiries possible.
- fragmede 4mo agoTo be fair, if someone managed to steal a set of keys to Gmail.com and icloud.com, I would want them to expire as short a time as possible too.
- notrealyme123 4mo agoI think revoking them would be better in such a case.
- hdgvhicv 4mo agoRevoking doesn’t really work. https://garantir.io/certificate-revocation-challenges-and-best-practices/ https://garantir.io/certificate-revocation-challenges-and-be...
- jzl 4mo agoStale news. Mozilla introduced a new solution for certificate revocation that solves nearly all the problems with old methods. While it hasn't really taken off outside of Firefox, that's mostly because Google and Apple haven't embraced it because they are too busy trying to shorten certificate life unnecessarily. https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/ https://hacks.mozilla.org/2025/08/crlite-fast-private-and-co...
- naturalmovement 4mo agoRevocation doesn't work because a cabal of arrogant Googlenos and friends decided it's too hard to fix so we won't do it at all. The last browser where revocation worked properly is Internet Fucking Explorer.
- flakes 4mo agoOne is not really better, you want both. Certificate revocation lists are loaded out of band and depending on the client can be poorly enforced. Questions come up: do you block a request if you fail to download the latest CRL? How often do you refresh it? When the cert expires, it can be removed from the CRL, so shorter lived certs will allow CRLs to be smaller and faster to transfer.
- naturalmovement 4mo ago> Questions come up: do you block a request if you fail to download the latest CRL? How often do you refresh it? In the before times we left settings like this up to competent system administrators to decide based on risk and not hardcoded by a handful of people at Google.
- spragl 4mo agoThat is right, but one thing is not like the other. You have always been free to set expiry low on your own certificates, but that is not the same as enforcing it on everyones ceritificate.
- Dylan16807 4mo agoIf it goes past 24 hours, that becomes a real worry. If anyone is renewing certificates with less than a day remaining, that's an issue on their end far more than anything else.
- hermeticlock 4mo ago:(
- drsalt 4mo agothats too bad
- Kesseki 4mo agoTo be clear, “Degraded Performance” means just that, not “down.” Let’s Encrypt’s issuance is mostly working fine.
- gib444 4mo agoWhat % of requests succeeded vs failed? How many certificates were issued during the outage vs the average? That might actually clear things up
- widdakay 4mo agoI have tried many times to renew my certs and have had 0 successes throughout today. It seems to be 100% degraded to me.
- Kesseki 4mo agoThat’s unexpected. Please post details on the “Help” topic of the Let’s Encrypt community forum so that folks can take a look.
- deleted 4mo ago[deleted]
- saagarjha 4mo agoI see you are unfamiliar with status page-ese. “Degraded performance” is a term which means some form of “the entire datacenter is probably on fire”.
- pibaker 4mo agoWhat are the viable alternatives to LE? And in case none exists, what does it take to build one? Requirements: free, available to everyone, automation friendly, issues certificates that are actually considered trustworthy by other parties.
- evbogue 4mo agoLike peers could sign sites?
- treesknees 4mo agoZeroSSL – free 90-day certs via ACME, also has a web UI for cert management Google Trust Services – free ACME certs, requires a Google account for registration SSL.com Free DV SSL – offers free 90-day certs through ACME
- polpo 4mo agoI use acme.sh for certs on my personal server and was a little surprised when it started using ZeroSSL by default. Despite being more "corporate" I decided to roll with it and it's worked just fine.
- curben 4mo agoacme.sh is maintained by ZeroSSL. https://github.com/acmesh-official/acme.sh#2%EF%B8%8F%E2%83%A32%EF%B8%8F%E2%83%A3-about-this-repository https://github.com/acmesh-official/acme.sh#2%EF%B8%8F%E2%83%...
- deleted 4mo ago[deleted]
- ksimukka 4mo ago[dead]
- otabdeveloper4 4mo ago> What are the viable alternatives to LE? None. Big tech intentionally made Let's Encrypt a single point of giant failure. > And in case none exists, what does it take to build one? A new Internet and Web standards stack. The whole problem is self-imposed -- we could have published self-signed Ed25519 keys on the DNS instead, and the result would be more secure than whatever it is we have now.
- tomalbrc 4mo ago[flagged]
- bruce511 4mo agoYou are getting down-voted for this, which I think is a bit unfair. (I expect I'll get the same.) Although you don't expand your thesis, as a general feeling, I agree. But, to be fair, it has always been thus, and it has been this way in every forum ever. I'm old enough to remember the irony in "I read about it on the internet so it must be true" statements, which have existed since the internet was News (NNTP) not web. In truth, any time you get a random group of people together, of different ages and backgrounds, all of whom self-describe as "smart" you're going to get a lot of chaff mixed in with the wheat. To some extent you need to simply ignore the nonsense. There's plenty of it and "correcting people who are wrong" is seldom received well.
- nubinetwork 4mo agoIt's a good thing that acme clients try to renew early, rather than leaving it to the last minute...
- ardeaver 4mo agoI realize this is very much not the point, but the fact that the "Active Incident" banner is green is upsetting.
- NewJazz 4mo agoWe're operating normally, but with reduced redundancy. We continue to work with our upstream ISP to identify and resolve the issue.
- Kesseki 4mo agoThe banner's colour is based on the "Incident Status;" it's green because services are currently operational. It would be yellow or red if the impact were more severe.
- dxdm 4mo agoUsing only color to communicate the status is confusing. If you want to communicate something, it's often best to just say it. The color can be a visual reinforcement of that. Then your explanation would not be needed.
- Kesseki 4mo agoWe do say it. That's what the "Incident Status" field is there for.
- dxdm 4mo agoBut that's not were the confusion is created. I don't even see the status field on mobile without scrolling. You don't have a missing status field, you have too much confusion, because the field and/or the color have a placement mismatch.
- dlcarrier 4mo agoTheir monitors don't seem to be detecting the outage. Sometimes they run directly on the server, and aren't able to detect routing or DNS problems.
- dlcarrier 4mo agoThat explains why one of my IoT vendors is using an expired certificate. I wish Firefox would just give a mild warning for a recently expired certificate, instead of treating it the same as a true man-in-the-middle attach. It's not like someone who couldn't factor the private key in 200 days could in 201 days or even 300 days. I'm convinced that we'd have better security, if we didn't have so much security theater. You'd think TLS is useless, from the warning my phone gives if I connected to a public Wi-Fi AP, but then again there's nothing in TLS (or WPA) that prevents it from being used in a way that is completely useless: https://www.youtube.com/watch?v=M1si1y5lvkk https://www.youtube.com/watch?v=M1si1y5lvkk
- jaas 4mo ago> That explains why one of my IoT vendors is using an expired certificate. I don't think so. There was a dip in success rates for 90 minutes today, but nobody should be renewing their certificate within 90 minutes of expiration. If you're at that point, something went wrong weeks ago.
- LtWorf 4mo ago> weeks ago How long do you think a certificate lives?
- Biganon 4mo agoThey work at letsencrypt, I'm pretty sure they know.
- jaas 4mo agoMostly 90 days, and we recommend renewing at 60 days for 90 day certs. That gives more than four weeks of leeway. If you're one of the few early adopters of short-lived (6-day) certs you should renew at 3 days, giving you 3 days for a successful renewal. A 90 minute outage, even if it was a full outage, would not interfere with a successful renewal.
- 4mo ago
- jaas 4mo agoLet's Encrypt has been working normally for most of the day. There was a ~90 minute period during which some of our users would have received a higher error rate due to upstream networking issues, but the majority of requests were successful even during that period. It seems our status.io notes are being misinterpreted as much more severe than they were intended to reflect. Edit: Note that this was written in response to a previous submission title implying that Let's Encrypt was entirely down most of the day.
- widdakay 4mo agoI'm not sure if your higher error rate is sticky per user or something, but I've tried 10+ times throughout the day and have had 0 successes. They all come back as internal server error. That's why I eventually posted.
- jaas 4mo agoIt would not have been sticky for the entire day. If it was sticky at all, it would have been only during the 90 minute period I referenced. It's most likely that there is some other issue with how you're requesting the cert. Folks can help debug at: https://community.letsencrypt.org/ https://community.letsencrypt.org/
- widdakay 4mo agoI ran the exact same command now and it's working, so it is possible I was unlucky and was hitting all the worst possible cases.
- sgt 4mo agoCould it be that he was simply throttled while retrying? That seems plausible, and it would make it seem like a long outage.
- widdakay 4mo agoI updated the post title to say (Fixed) now.
- po1nt 4mo agoLet's encrypt is a single point of failure for a large percentage of the internet.
- gsliepen 4mo agoNo, it's not. You can always switch to a different SSL provider. There are other free ones (as mentioned in other comments). However, thinking about how to make your own setup more robust without having to manually change configuration when one SSL provider stops working is a good exercise. I wonder if you can just get your server's private key signed by multiple SSL providers, and serve multiple certificates to clients, and whether all browsers handle that correctly.
- doublerabbit 4mo agoNothing is a point of failure if you can switch but that's not really true unless you have fail-over. If LE was to go nope right now, how fast could you move your stack from LE? You can't use multiple SSL certificates as redundancy. You could probably create something bespoke with a Load Balancer and SSL offloading but that's just more overhead for really nothing.
- po1nt 4mo agoJust picture the massive load spikes on other SSL providers in that moment. And the fact that even those might not work, as their backends might rely on LE SSL 3rd party services for ID checking or something.
- po1nt 4mo agoIf you couldn't switch, that would be a monopoly. But single point of failure is when you put all your fruit in one basket. Airplanes have redundant systems, even though you can always buy new components. But it's much harder to change them mid-flight.
- gsliepen 4mo agoOk, but that would just be your own website having a single point of failure, not that Let's Encrypt is a single point of failure. Otherwise you could call every certificate authority a single point of failure.
- ta3029382 4mo ago[dead]