LetsEncrypt Certificate Issuance Halted
letsencrypt.status.io
letsencrypt.status.io
1 more month for me to fix stuff (or wait for fix).
But back to counting. In the EU, if you go to the first floor, you’d call that the second floor in the US. It has one floor in the EU, but two in the US. I have no idea if this is the same thing or just a mistake. But there are some interesting assumptions in this thread!
Just because elevators and other things start at a 0 doesn't mean that makes sense anywhere else, it's fairly common for ground level to be 0. There is no instance where it makes sense to say 0 week = 7 days, 1 weeks = 14 days, etc. It does however make sense to say I live on the ground level (aka floor 0), I live on the 1st floor (aka second floor).
https://sectigo.status.io/pages/history/5938a0dbef3e6af26b00...
For context, Sectigo also provides freebies for cPanel customers.
For renewals, this is not a problem unless it's down for an extended period of time - and even then there would be time to switch providers. Should be using scheduled updates, and even if not, the email notifications come in on 20 and 10 days, so plenty of time to go and get it renewed.
They have a rate limit for the amount of renewed certs. This doesn't apply if you don't reach their servers or don't get a cert.
But if you have a problem with a CA just switch to another which supports your bot (e.g. acme compliant CAs).
The private key only you have, so that's the thing you most need to avoid throwing away over and over due to a bug. If you lose the certificate, that's a public document, you can just get another copy manually if necessary.
...not naming names, but I can see one above the bathroom sink.
(yes yes, I know, I know...)
Some other ACME providers I know of:
- ZeroSSL.com
- BuyPass.com
- SSL.com
(most of those provide free certs in some form, but some with limitations and may then ask for money if you want more features).
> ZeroSSL.com
I kinda wish people would stop recommending them. This might have changed, but last time I tried ZeroSSL (~a year ago) it was not RFC 8555 compliant (specifically section 7.3.1), and you were basically supposed to use their own proprietary API to deal with the issue. So you can't always switch transparently.
If you need an alternative use Buypass. Also free, and they're actually RFC 8555 compliant.
https://github.com/acmesh-official/acme.sh#supported-ca
But it seems that acme.sh got bought by zero ssl, which would explain that it's their default now..
Out of honest interest, where did they fail to honor "7.3.1 Finding an Account URL Given a Key"?
Well... it doesn't work. Let me quote the RFC:
> If the server receives a newAccount request signed with a key for which it already has an account registered with the provided account key, then it MUST return a response with status code 200 (OK) and provide the URL of that account in the Location header field.
With ZeroSSL you could only call `newAccount` once; any subsequent call will fail, while according to the RFC it should return the URL of the account. So you have to either a) use their proprietary API to recover the URL (I sent them a bug report for this and that's what they basically told me), or b) save the URL along with the account key (which you don't have to do for any other ACME provider).
Unless you use some sort of certificate (authority) pinning.
I didn't use them but apparently ZeroSSL and SSL.com issue free certs as well.
Clients are encouraged to renew their certificates a couple of days prior to expiration, precisely to make sure that in the case of a disruption there is still some buffer in time to prevent expired certs being served.
There are also other services that offer this sort of thing, they’re just lesser known.
https://news.ycombinator.com/item?id=25213817
Edit:
My main takeaway is that it goes against the human instinct of self preservation (losing one's job, opening the company to lawsuits, status pages being used against you by competitor, etc.)