3 ms·
LetsEncrypt works with IPv4. I assume it will work with IPv6. LetsEncrypt is a Mozilla project, it's safe to assume they will launch LetsEncrypt before deprecat
by undefined0 11y ago
LetsEncrypt works with IPv4. I assume it will work with IPv6. LetsEncrypt is a Mozilla project, it's safe to assume they will launch LetsEncrypt before deprecating non-secure websites.
- schoen 11y agoRight now the subject identifier in a Let's Encrypt cert must be a DNS name, not an IP address. From the ACME protocol specification draft: "Note that while ACME is defined with enough flexibility to handle different types of identifiers in principle, the primary use case addressed by this document is the case where domain names are used as identifiers. For example, all of the identifier validation challenges described in Section {identifier-validation-challenges} below address validation of domain names. The use of ACME for other protocols will require further specification, in order to describe how these identifiers are encoded in the protocol, and what types of validation challenges the server might require."
- pfg 11y agoThis is in line with other CAs - no certificates should be issued for IP addresses or internal server names with expiry dates after November 2015. See for example: https://www.digicert.com/internal-names.htm https://www.digicert.com/internal-names.htm
- schoen 11y agoTechnically I think the requirement Digicert is referring to only forbids issuance for "reserved" IP addresses. https://cabforum.org/internal-names/ https://cabforum.org/internal-names/ The PDF document defines "Reserved IP Address" as "An IPv4 or IPv6 address that the IANA has marked as reserved".
- pfg 11y agoMissed that, thanks!