HNHacker News
TopNewBestAskShowJobs

thehairyone

-29 karma · joined January 18, 2016

submissionscomments
thehairyone··on Why isn't HTTPS everywhere yet?
@pfg:

I know exactly how CAs work. I've built several.

Wosign does not issue a cert without an email verification.

You can look on their website. There's a nice big box to enter an email address to verify your domain and get the free cert.

Sorry -- "Let's Encrypt" with file verification is not DV.

It's just not DV. Simple really...

And it's gonna break the web. Like netlify up there a few post... using rackspace and "Let's Encrypt". ehh. The first few months will probably be fine and then everything is gonna tank.

Until the smart realize that ACME is fine -- as long as you remove the "or file verification" text.

thehairyone··on Why isn't HTTPS everywhere yet?
Of course the cross signed cert works!

That not the point.

The cross signature is worthless if the signed cert beneath it is self-signed.

If Identrust cross signed self signed certs, the self signed cert would be trusted too... and it would "work" in all browsers...

Coly Tarry Frap Tarts! you're daft.

Here try this:

1. Setup a domain with an MX record that points off domain and a dmarc p=reject record...

2. Try to get a cert from any CA other than Lets Encrypt without answering any emails sent to the off domain MX.

...

Then... install Lets Encrypt... bam-o! Cert heaven!

It's self-gawd-damn-fing-signed.

thehairyone··on Why isn't HTTPS everywhere yet?
Oh yeah! sure...

what exactly ensures that the DV cert is a DV cert?

thehairyone··on Why isn't HTTPS everywhere yet?
The cross sign is too far up the chain.

If you cross sign a self-signed cert what do you get?

A Let's Encrypt Cert.

Domain Ownership is not the same as file ownership.

thehairyone··on Why isn't HTTPS everywhere yet?
No, it doesn't.

Lets Encrypt certs are equivalent to self-signed certs.

No hassle ==> broken shit.

thehairyone··on Why isn't HTTPS everywhere yet?
a2enmod headers

echo -e "ServerSignature Off\nServerTokens Prod" >> /etc/apache2/apache2.conf

/etc/init.d/apache2 restart

openssl req -new -nodes -keyout webappsec-test.info.key -out webappsec-test.info.csr -newkey rsa:2048

cat webappsec-test.info.csr

Register here:

https://www.startssl.com/

Copy and paste csr...

cat Domain_cert.pem CA_root.pem

https://mozilla.github.io/server-side-tls/ssl-config-generat...

====>

A+ on

https://www.ssllabs.com/

Now? What's so hard about that?

I guess if you're using EC2 and Ubuntu on your server... ehhh...