LemmyChan
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
canpolat@programming.dev to Web Hosting@programming.devEnglish · 3 years ago

Shortening the Let's Encrypt Chain of Trust

letsencrypt.org

external-link
message-square
0
link
fedilink
1
external-link

Shortening the Let's Encrypt Chain of Trust

letsencrypt.org

canpolat@programming.dev to Web Hosting@programming.devEnglish · 3 years ago
message-square
0
link
fedilink
When Let’s Encrypt first launched, we needed to ensure that our certificates were widely trusted. To that end, we arranged to have our intermediate certificates cross-signed by IdenTrust’s DST Root CA X3. This meant that all certificates issued by those intermediates would be trusted, even while our own ISRG Root X1 wasn’t yet. During subsequent years, our Root X1 became widely trusted on its own. Come late 2021, our cross-signed intermediates and DST Root CA X3 itself were expiring. And while all up-to-date browsers at that time trusted our root, over a third of Android devices were still running old versions of the OS which would suddenly stop trusting websites using our certificates. That breakage would have been too widespread, so we arranged for a new cross-sign – this time directly onto our root rather than our intermediates – which would outlive DST Root CA X3 itself. This stopgap allowed those old Android devices to continue trusting our certificates for three more years.
alert-triangle
You must log in or # to comment.

Web Hosting@programming.dev

web_hosting@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !web_hosting@programming.dev

Icon base by Delapouite under CC BY 3.0 with modifications to add a gradient

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 14 users / day
  • 14 users / week
  • 14 users / month
  • 14 users / 6 months
  • 1 local subscriber
  • 410 subscribers
  • 20 Posts
  • 0 Comments
  • Modlog
  • mods:
  • snowe@programming.dev
  • Reson8@programming.dev
  • Ategon@programming.dev
  • BE: 0.19.15
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org