HN user

jaas

5,640 karma

Executive Director @ ISRG. Let's Encrypt, Divvi Up, Prossimo.

Posts27
Comments242
View on HN
letsencrypt.org 6mo ago

6-Day and IP Address Certificates Are Generally Available

jaas
506pts281
letsencrypt.org 1y ago

How we reduced the impact of zombie clients

jaas
184pts39
www.memorysafety.org 1y ago

Rustls Server-Side Performance

jaas
171pts60
www.memorysafety.org 1y ago

Rustls Outperforms OpenSSL and BoringSSL

jaas
154pts44
www.memorysafety.org 2y ago

Rustls Gains OpenSSL and Nginx Compatibility

jaas
4pts0
www.memorysafety.org 2y ago

River: A Reverse Proxy Built on Pingora

jaas
29pts3
www.memorysafety.org 3y ago

Rustls TLS Library 0.21.0 Released with New Features

jaas
34pts7
www.memorysafety.org 3y ago

A Safer High Performance AV1 Decoder

jaas
2pts0
www.memorysafety.org 3y ago

Klint: Compile-Time Detection of Atomic Context Violations for Kernel Rust Code

jaas
1pts0
github.com 4y ago

Mod_TLS: Safer TLS for Apache Httpd

jaas
3pts0
www.memorysafety.org 5y ago

Supporting Miguel Ojeda’s Work on Rust in the Linux Kernel

jaas
14pts0
www.abetterinternet.org 5y ago

ISRG Prio Services for Preserving Privacy in Covid-19 EN Apps

jaas
2pts0
www.abetterinternet.org 5y ago

Preparing Rustls for Wider Adoption

jaas
230pts132
letsencrypt.org 5y ago

Preparing to Issue 200M Certificates in 24 Hours

jaas
215pts101
www.abetterinternet.org 5y ago

A Memory Safe TLS Module for the Apache HTTP Server

jaas
16pts2
letsencrypt.org 5y ago

The database servers powering Let's Encrypt

jaas
529pts226
letsencrypt.org 5y ago

Extending Android Device Compatibility for Let's Encrypt Certificates

jaas
1pts0
www.abetterinternet.org 5y ago

ISRG Prio Services for Privacy Respecting Metrics

jaas
11pts0
letsencrypt.org 6y ago

Let's Encrypt Has Issued a Billion Certificates

jaas
1160pts258
letsencrypt.org 6y ago

Multi-Perspective Validation Improves Domain Validation Security

jaas
7pts0
letsencrypt.org 6y ago

How Let's Encrypt Runs CT Logs

jaas
9pts1
letsencrypt.org 7y ago

The ACME Protocol is an IETF Standard

jaas
29pts0
letsencrypt.org 7y ago

Let's Encrypt: Looking Forward to 2019

jaas
408pts68
www.abetterinternet.org 7y ago

Meet Radiant Award Recipient Jason Donenfeld

jaas
7pts0
letsencrypt.org 8y ago

ACME Support in Apache HTTP Server Project

jaas
230pts75
letsencrypt.org 9y ago

Let's Encrypt Milestone: 100M Certificates Issued

jaas
5pts1
twitter.com 9y ago

More than 50% of page loads were encrypted with HTTPS yesterday

jaas
1pts0

Mostly 90 days, and we recommend renewing at 60 days for 90 day certs. That gives more than four weeks of leeway.

If you're one of the few early adopters of short-lived (6-day) certs you should renew at 3 days, giving you 3 days for a successful renewal. A 90 minute outage, even if it was a full outage, would not interfere with a successful renewal.

That explains why one of my IoT vendors is using an expired certificate.

I don't think so. There was a dip in success rates for 90 minutes today, but nobody should be renewing their certificate within 90 minutes of expiration. If you're at that point, something went wrong weeks ago.

Let's Encrypt has been working normally for most of the day. There was a ~90 minute period during which some of our users would have received a higher error rate due to upstream networking issues, but the majority of requests were successful even during that period.

It seems our status.io notes are being misinterpreted as much more severe than they were intended to reflect.

Edit: Note that this was written in response to a previous submission title implying that Let's Encrypt was entirely down most of the day.

Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this.

Most of our sanctions-related blocks apply only to the governments of certain sanctioned countries, not their general population.

This subscriber agreement update was intended to better reflect our legal requirements. It does not reflect a major change in the service we provide. Our compliance program does evolve over time, and part of that is communicating about it better in our terms of service. It's clear from some of the comments here that we have more work to do to make that text more understandable, we'll work on that.

That said, pretty sure this is stems from the insane US legal requirement to not export SSL technology to enemy countries. I'm sure some of y'all are old enough to remember when web browsers came in "international friendly" versions that supported 40 bit encryption, or "fancy secure" versions with 128 bit encryption.

It doesn't.

Sanctions compliance is unfortunately fairly complex.

Let's Encrypt can issue certificates for non-government entities in Iran and Russia due to statutory exemptions protecting personal communications, alongside specific Office of Foreign Assets Control (OFAC) authorizations designed to promote Internet freedom and human rights.

We will look into whether we can make things more easily understandable in the subscriber agreement.

Stopping all issuance is an pretty standard response if a CA thinks what they are issuing might be non-compliant in any way. It's an action we're required to take. It's not necessarily a sign of a more dramatic failure mode or key compromise. That said, the impact is the same for as long as the downtime lasts so it is unfortunate and we're sorry for the disruption.

I don't think the premise behind short lived (six day) certificates being viable is that CA issuance never goes down. Sure, the runway is shorter, but not that short. Most down time is a few hours or less, which is not a problem for six day certificates that should be renewed every three days.

Short lived certificates are optional though, so if it's not worth it to you there are longer lifetime options.

Their networking is awful in my experience. The WiFi chip is cheap crap, extremely sensitive, cuts out a lot, and doesn’t support WPA3.

I had to set up a dedicated Nanit-only AP in my house in order to stabilize the connection. It would not work any other way, tried many different configurations, even other APs.

We buy them because our experience is that they are extremely reliable and their iDrac management system is better than the alternatives, which saves us time (thus money). Maybe they aren’t the cheapest at initial purchase, but less maintenance and the ease of administration makes up for it.

Go is still not good 11 months ago

Go has a big, high quality standard library with most of what one might need. Means you have to bring in and manage (and trust) far fewer third party dependencies, and you can work faster because you’re not spending a bunch of time figuring out what the crate of the week is for basic functionality.

It's not just about the money:

"Providing expiration notification emails means that we have to retain millions of email addresses connected to issuance records. As an organization that values privacy, removing this requirement is important to us."

A check to cover the cost of the system would not solve this part of the problem.

A free account for sending emails would not have changed the decision because it doesn't solve this:

"Providing expiration notification emails means that we have to retain millions of email addresses connected to issuance records. As an organization that values privacy, removing this requirement is important to us."

Now there is no contact information associated with issuance records.

We (Let's Encrypt) are getting rid of subject common names and moving to just using subject alternative names.

This change has been made in short-lived (6 day) certificate profiles. It has not been made for the "classic" profile (90 day).