4 ms·
https://letsencrypt.org/howitworks/technology/ https://letsencrypt.org/howitworks/technology/
by goodnights 12y ago
https://letsencrypt.org/howitworks/technology/ https://letsencrypt.org/howitworks/technology/
- protomyth 12y agoOk, so how does that keep a site like paypall.com (or any example of a common off-by-one-letter domain) from getting a certificate?
- Eridrus 12y agoNothing currently stops paypall.com getting a certificate and the technology is not meant to do that. EV-SSL is kind of meant to deal with that if you want to pay the fees. But this seems more in line with a movement towards HTTPS by default and marking HTTP as insecure.
- protomyth 12y agoI'm pretty sure the certificate companies when doing their verification stop obvious attempts at scams. So, all this is to get an encrypted connection?
- runeks 12y ago> So, all this is to get an encrypted connection? This strikes me as odd too. What's the difference between an automated SSL certificate generator and just having the browser accept self-signed certificates? openssl is also an automated SSL certificate generator, but it only produces self-signed certificates. So why not just accept self-signed certs?
- johnsoft 12y agoThe difference is in the certificate chain. One of the conditions for being a CA is verifying domain ownership before signing a certificate. In return for this, browsers will trust their cert. As long as a CA keeps this promise, they get to keep their cert and use it to sign certs for others. If they break this promise, their cert will be revoked and browsers will start showing warnings on sites that used them as a CA. A green padlock indicates this additional level of trust, i.e. authenticity (verified through any method any trusted CA may choose), which a self-signed cert can't provide.