Let's Encrypt Developer Preview
github.com
github.com
If they already have the CA stuff ready can they just release that? I don't really care about their auto-magical tool which is meant to reconfigure your server for you. Configuring Apache/IIS etc is not that complex, the only reason I don't have a certificate on my private website is because the certificate costs more than the hosting annually (literally).
Plus I'm never going to run this tool even when it is production ready. I don't trust random tools to reconfigure my system, and would prefer to manually follow tutorials so it is easy to undo every change or at least be aware of exactly what changes got made.
While I'm sure they have something ready[0], I'm not sure they have a fully-worked-out policy for running it (required to get into certificate chains), or a production deployment of it, or a third-party vulnerability test of it.
Additionally, ACME verification is a vaguely complicated protocol which will likely need a tool to sign the various messages involved (or you're going to be looking at munging together OpenSSL commands), and you're looking at the developer preview of that.
Agreed. I can already generate and install a certificate (though I wouldn't mind a standalone tool to make that simpler). I'd like some automated process that renews that certificate, or better yet, certificates that don't expire in the first place.
For example on our network every user-laptop-service combination has a unique cert. A user can be dropped from, say, accessing IMAP with a single change on the server and without affecting their webmail access.
MITM is very difficult in that scenario as the attacker had to compromise both ends.
Without the expiration parameter, you could crack an 512 or 1024 bit certificate five years from now and it would be just fine to use. All you would have to do would be attack the CRL/OCSP server and keep it offline for a very short period of time.
With a short enough expiry, you might not even need revocation. (See: DNSSEC.)
So what you are saying is that because you can get an SSL cert free from startcom, that your hosting provider is paying you?
I understand they also have a pretty bad interface and terrible customer service.
They are not without fault, but they've much good for open source project and the like, and don't deserve the bad rap thrown at them in every thread that mentions SSL.
>If the CA or any of its designated RAs become aware that a Subscriber’s Private Key has been communicated to an unauthorized person or an organization not affiliated with the Subscriber, then the CA SHALL revoke all certificates that include the Public Key corresponding to the communicated Private Key.
There is no "if you pay them" condition to that. CAs are not supposed to make, or allow to stand, any signature on a compromised key—period.
Startcom's refusal to revoke all compromised public keys communicated to them after Heartbleed, and in fact their practice of charging for any revocation in general, is not in compliance with the baseline requirements for a CA.
As a result, Startcom should be removed from all browsers as a trusted CA. Let's Encrypt would be a very good replacement, especially if they also offer keys using ECC P-256 (and perhaps a subsequent replacement ECC algorithm).
> A certificate will be revoked when the information it contains is suspected to be incorrect or compromised.
and
> The subscriber’s key is suspected to be compromised;
>The technical content or format of the certificate presents an unacceptable risk;
https://forum.startcom.org/viewforum.php?f=8
After I saw the state of their forums/community I ran, not walked, away from their service. Which is rather scary considering they are a trusted CA...
I think really the only reasonable thing to do is pay $15/yr for any site that other people will use and use your own CA for your personal projects.
Getting CA certs into Android however is whole other issue...
I usually buy certs either through Gandi.net (which has a good "free certificate" program with its own domains), or COMODO through Namecheap as a reseller.
StartCom (or any of CA) doesn't care about IP address.
I do want a tool using which I can do something like:
$ letsencrypt 'foo.bar.example.com'
which would spit out foo.bar.example.com.key, foo.bar.example.com.cert, and foo.bar.example.com.csr.I'd also like to have:
$ letsencrypt --renew foo.bar.example.com
Which would re-generate all these certs. The main problem for me, just like for you, is that domain validation certs are not free (or at least somehow included in the price of the domain registration). This type of tool solves that.If, on top of this tool, we also get something that lets a person new to ops autogenerate or even autodeploy an nginx vhost with TLS/SPDY support, awesome! But the ability to generate and renew certs from the command line, for free, is what I want and probably what you want too.
Depending on exactly what proof the CA wants, that will probably require some kind of tinkering with the webserver's config, or at least inspecting it to figure out how to fulfil the CA's request.
Hopefully there'll be a fallback mechanism that tells the sysad what to configure, if only because not every webserver in the world is Apache or nginx.
Problem solved.
Also, you can reissue certs with added SANs
Couldn't an MITM between the LetsEcnrypt service and the example.com server request a certificate, then respond to the challenge, and then use that certificate later?
Getting a certificate from StartSSL was similar. The only difference was that there was a human involved in the loop (a mail is sent and the user has to copy paste the contents of the email), but in essence, both the services seem vulnerable.
This seems to be an unsolvable bootstrapping problem, unless some sort of physical verification is done.
What am I missing?
This is standard for all domain-validation-only certificate authorities, i.e. the cheapest cert you can get from any given company.