17 ms·
Let's Encrypt Launch Schedule
- jglauche 11y agoDamnit, my existing cert expires September 12. Any free alternatives to that?
- teraflop 11y agohttps://www.startssl.com/ https://www.startssl.com/ provides free domain-validated certificates.
- mey 11y agoThe issue is you have to pay for revocation.
- Karunamon 11y agoPlease don't use startssl. Revocation costs money, and the company's behavior surrounding heartbleed was at the very least very unethical.
- teraflop 11y agoFair enough, but bear in mind that StartSSL's revocation fee is lower than what most certificate providers charge as a starting price. Personally, I'm fine with taking the risk and eating the $25 cost if something unexpected happens.
- clinta 11y agoNo company should be incentivising companies to not revoke compromised certificates. Even if the cost is modest. It's more about not patronizing a company with such a bad business model than it is about the dollar cost.
- currysausage 11y agoStartSSL's business model: making things free that don't cost them measurable money, and charging for transactions that cost them money. An exception from that rule in the wake of Heartbleed would arguably have been appropriate, but the business model as such is in no way bad. If the whole SSL industry worked in a way that put price and cost in proportion, there would be no need for Let's Encrypt.
- Karunamon 11y agoHow does an automated revocation cost them money?
- currysausage 11y agohttps://blog.cloudflare.com/the-hard-costs-of-heartbleed/ https://blog.cloudflare.com/the-hard-costs-of-heartbleed/
- mikeash 11y agoWhat about every other certificate issuer, whose up-front fees incentivize companies to not encrypt data in the first place?
- clinta 11y agoNot encrypting is better than not revoking a compromised certificate. A compromised certificate gives the user the impression that the connection is secure when it's security is compromised. A plaintext connection makes no false claims.
- mikeash 11y agoIn which case if you don't want to pay for revocation, you could just revert back to an unencrypted connection.
- yuhong 11y agoI am thinking that they should adopt short lived certificates.
- hobarrera 11y ago> Revocation costs money[...] I think it's quite understandable that they charge for things that cost them money, but keep the rest free. You can't really expect for them to give out for free something that has a cost for them.
- robertfw 11y agoBe aware that the free cert does not support certificate transparancy. This will lead some browsers - notably chrome but I imagine there are/will be others - to give a user warning about SSL integrity. There are supposedly some workarounds [1] but no official support. [1] http://korusdipl.egloos.com/6152770 http://korusdipl.egloos.com/6152770
- iancarroll 11y agoChrome only downgrades EV to non-EV without SCTs. You can always send them yourself via the TLS extension method.
- yellowapple 11y agoOn top of the revocation issues, StartSSL is only free for personal use; if you intend to obtain a cert for a small business or some other non-personal purpose, they won't give you the cert. I also recall StartSSL being incredibly difficult for those who only have a P.O. box for a mailing address (as was the case for me; my apartment didn't have a mailbox, so I had to receive all mail at a P.O. box, which StartSSL didn't like).
- deleted 11y ago[deleted]
- snowpanda 11y agoComodo has a 90 day free SSL trial that should get you through that window. https://www.comodo.com/e-commerce/ssl-certificates/free-ssl-certificate.php https://www.comodo.com/e-commerce/ssl-certificates/free-ssl-...
- vtlynch 11y agoRapidSSL also offers a free 30-day certificate: https://www.freessl.com/ https://www.freessl.com/
- rmoriz 11y agohttps://buy.wosign.com/free/ https://buy.wosign.com/free/ (Root in Windows, Cross-Signed by StartSSL for others)
- elahd 11y agoNamecheap sells basic Comodo certs for $9.00/yr.
- PaulBurke 11y agoIf you worried much about expiration of your free SSL certificate, I advise you to invest some $ on domain validated SSL certificate. Advantages 1. No Expiration for 3 Years 2. 256-bit strong encryption with 2048-bit SSL certificate 3. Domain validation by trusted Root certificate authority. 4. Lowest price SSL Get Comodo PositiveSSL Certificate at only $4.99/year from CheapSSLSecurity and make your self free from SSL Expiration. Visit here for mode details - https://cheapsslsecurity.com/comodo/positivessl.html https://cheapsslsecurity.com/comodo/positivessl.html.
- tokenizerrr 11y agoVery glad to hear there is a launch schedule, have been curious about how this project has been progressing. It's a fantastic intiative and I almost can't wait until September 14.
- jtchang 11y agoI am really excited about this whole initiative. Mostly because encryption should really be standard at this point if not for the hurdles one has to face in deploying it. What type of help is the Let's Encrypt team still needing?
- joshmoz 11y agoGlad you like the project! Contributing to our software is one way to help: https://github.com/letsencrypt/boulder https://github.com/letsencrypt/boulder https://github.com/letsencrypt/lets-encrypt-preview https://github.com/letsencrypt/lets-encrypt-preview Also, if you work for a company that might be interested in sponsoring us, starting that conversation is another great way to help out.
- diafygi 11y agoWhat are the tiers for corporate sponsors?
- garrettr_ 11y agoThe tiers are Platinum, Gold, and Silver. Check out the current sponsors [0] and info on becoming a sponsor [1]. [0]: https://letsencrypt.org/sponsors/ https://letsencrypt.org/sponsors/ [1]: https://letsencrypt.org/become-a-sponsor/ https://letsencrypt.org/become-a-sponsor/
- EGreg 11y agoCan someone summarize why this is better than, say, StartSSL or AlphaSSL?
- StavrosK 11y agoBecause it includes a script you can just run and will take care of everything for you, and you'll have properly TLS-configured web servers with valid certificates and reissues with a single command.
- dingaling 11y agoNo sane system administrator is going to run a root-privilege program to reconfigure his web server and set-up SSL: The Let’s Encrypt client is essentially an operating system component. Generically, it requires root privileges to bind to port 443 and (if requested) to reconfigure your webserver for certificate installation and renewal That also seems like a perfect compromise vector for bad actors to modify the client software. The Let's Encrypt effort is noble and definitely required but I think they would have been better-focused and quicker to market had they concentrated on establishing themselves as a CA first and leaving the 'auto-configuration magic' to a later stage, for the small subset of users who want that.
- StavrosK 11y agoI don't understand how this is any worse than any other of the thousands of pieces that you run on your server. If you audit the code and it looks fine, and it's coming signed from a trusted source, what's the problem? It's not even a daemon, it just runs for a few seconds and exits.
- aroch 11y agoNo predatory pricing (StartSSL has $25 revocations), free (AlphaSSL) and user-friendly (StartSSL is a UX nightmare). PositiveSSL is probably the cheapest, well supported cert (certs can be had for $3-4/y).
- 11y ago
- diafygi 11y agoI'm suuuper excited for this to launch! However, it's worrisome that the ACME protocol (what Let's Encrypt uses) still has a ton of bugs open[1] and they are still changing the protocol often. Just search for "TODO" on the spec markdown[2]. I want this project to proceed, but they should really focus on getting a much more mature and stable spec before launch. This isn't WebRTC, where you can just continuously tack on additional stuff or change the API constantly. It's TLS certs. The certs issued using this API end up telling people it's safe to input their passwords or credit card numbers. I really hope the ACME spec gets stable before the launch in July. [1]: https://github.com/letsencrypt/acme-spec/issues https://github.com/letsencrypt/acme-spec/issues [2]: https://github.com/letsencrypt/acme-spec/blob/master/draft-barnes-acme.md https://github.com/letsencrypt/acme-spec/blob/master/draft-b...
- cbhl 11y ago> The certs issued using this API end up telling people it's safe to input their passwords or credit card numbers. I'm pretty sure they shouldn't tell users it's safe to type in credit card numbers -- these certs are "domain validation" (DV). The certs that generate a green chip in the address bar are "extended validation" (EV) certs that typically cost hundreds and require a human to manually verify things.
- vtlynch 11y agoValidation has nothing to do with the security of the certificate. There is nothing preventing you from using a DV, OV, or EV certificate to transmit any type of data you want.
- dragonwriter 11y ago> Validation has nothing to do with the security of the certificate. It has to do with the security and accountability of the end-to-end process in which the certificate is used, which is a security concern even if you define "security of the certificate" so narrowly that it isn't relevant to the security of the certificate as such. (Though what you have a trusted third-party vouching for in the certificate -- which is the key distinction in EV -- is, I would think, by any reasonable standard, a factor in the security provided by the certificate.)
- worklogin 11y agoDo Chrome and Mozilla have Let's Encrypt in their Root stores? I don't see them.
- echeese 11y agoThey're cross-signed by DST Root CA X3 which is in the list.
- vtlynch 11y agoNo. The Let's Encrypt root was recently created and will be submitted to root inclusion programs. It will probably be quite a while until its suitable to issue certs solely from the Let's Encrypt Root. For now, the certs are cross signed by "DST Root CA X3" operated by Identrust. This root has very strong inclusion. For specifics, please see: https://groups.google.com/a/letsencrypt.org/forum/#!msg/client-dev/I-iFKihZ4Vo/5g9Xb5SroOsJ https://groups.google.com/a/letsencrypt.org/forum/#!msg/clie...
- worklogin 11y agoDangit, I didn't read the second paragraph. For GA, they will have the cross-sign. It's just for the EA that they don't.
- qrmn 11y agoI gather they're not launching with ECDSA certificates (and obviously not with EdDSA or whatever comes out of CFRG, because that's still being discussed by the IETF/IRTF), but they're going to add it later. Any idea when? What's the hold up; HSMs that'll do secp256r1? Because of the huge performance improvement ECDSA brings over RSA, I know I'm not going to be deploying Let's Encrypt certs until I can get ECDSA ones (as well as RSA ones, presumably).
- masida 11y agoVery nice initiative. But for me the biggest problem with adoption of SSL is still that every domain name needs it's unique IPv4 address, and all problems that come with that, not registering or paying for the SSL certificate. At work, I usually use virtual hosting for about 100 domains on one IP address. I don't see us buying an IPv4 address per domain and adding them to my NIC configuration one by one. Once we can safely ignore IPv4 and use IPv6 only it will probably become easier and cheaper.
- hathawsh 11y agoUse SNI, Server Name Indication: https://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication All modern browsers support it, as do Nginx and Apache.
- masida 11y agoThanks for the info, eirst time I hear about this. I'll look it up. I'm honestly a bit ashamed I haven't heard about this before.
- adisbladis 11y agoSNI has been a thing for a long while now.. Do you seriously need to support older browsers than this? https://en.wikipedia.org/wiki/Server_Name_Indication#Web_browsers.5B6.5D https://en.wikipedia.org/wiki/Server_Name_Indication#Web_bro...
- LinuxBender 11y agoSNI is fine for web browsing, but for end-points that need to be reachable by older versions of python, tomcat, ruby and many proprietary apps, this will not suffice. This becomes a problem on business to business communications, automation, API's, etc. For the general purpose websites, blogs, etc, SNI would be fine.
- hobarrera 11y ago
- general_failure 11y agocan someone clarify if revokation is free with letsencrypt? Also, who pays for all this infrastructure? Mozilla?
- vtlynch 11y agoNot sure about revocation. Sponsorship is provided by multiple companies, including Mozilla. See https://letsencrypt.org/sponsors/ https://letsencrypt.org/sponsors/ and https://letsencrypt.org/2015/04/09/isrg-lf-collaboration.html https://letsencrypt.org/2015/04/09/isrg-lf-collaboration.htm... for more.
- bracewel 11y agoAll the services provided by Let's Encrypt will be completely free, including revocation.