Distrust Let's Encrypt Subordinate Certificate
bugzilla.mozilla.org
bugzilla.mozilla.org
I doubt that corporate users will move in any significant numbers to LE, even for basic DV certs.
Two reasons:
1. The certificate renewal process appears to be incompatible with most corporate change-control processes I've encountered: nothing may change on a production server unless an admin is given authorisation to change it. A cron job that could take all customer-facing services offline is just crazy[0].
2. When something goes wrong with a cert issuance or renewal, corporate users ( want | need ) to be able to call a human to have them fix it, regardless of cost. And even that cost is insignificant in context to revenue.
I'm sure LE will be popular with bloggers and hobby users. Beyond that?
[0] yes, the admins could run the LE client manually in non-prod and move the certs over to production. But that's no easier than current cert renewals, and would have to occur every 60-90 days.
As a sysadmin, I don't think Let's Encrypt's 90 day expiration period is too onerous, but if I can sidestep that aggressive expiration period with a $300-600 wildcard cert that expires yearly from a traditional CA, that's the route I'm going to go (when my fully loaded costs to my employer are on the low end of that cost per hour).
Disclaimer: I'm a big proponent of Let's Encrypt, and tweeted at Jeff Barr @ AWS asking if they could integrate its lifecycle into AWS' IAM SSL ecosystem.
Not everyone are teams of 5-20 on EC2 or DigitalOcean.
A PITRA (point-in-time readiness assessment) is sufficient to begin issuing if the formal audit follows in a timely fashion. It's not possible to have a formal audit of the issuance process unless you are issuing; requiring it to begin issuance would lead to a chicken-and-egg problem.
Gerv
Update: Stating that there is no solution without any knowledge of the existing solutions is itself part of the problem. Let's start with this: https://github.com/okTurtles/dnschain
Let's start with this:
http://www.theregister.co.uk/2011/09/06/diginotar_audit_damn...
So it's OK to be paranoid, IMO. The CA system is radically flawed in that it can be gamed by state actors.
You can try and move the corporatist agenda for a two tier security system where the mighty and powerful have all seeing eyes and the consumer is told that all their https communication is secure and private.