Jump to content

Let’s Encrypt - A free certificate authority from the EFF, Mozilla, Akamai and Cisco


Recommended Posts

  • 2 months later...
Posted

Just wanted to say that this was mentioned in this month's PC Pro - the security chap, Davey Winder seemed to think it was a good idea.

 

Meldrew.

  • 3 months later...
Posted

Not long now!

 

Let's Encrypt Root and Intermediate Certificates

 

The keys and certificates that will underlie Let’s Encrypt have been generated. This was done during a key ceremony at a secure facility today.

 

Let’s Encrypt will issue certificates to subscribers from its intermediate CAs, allowing us to keep our root CA safely offline. IdenTrust will cross-sign our intermediates. This will allow our end certificates to be accepted by all major browsers while we propagate our own root.

 

Under normal circumstances, certificates issued by Let’s Encrypt will come from “Let’s Encrypt Intermediate X1”. The other intermediate, “Let’s Encrypt Intermediate X2”, is associated with our disaster recovery site and will only be used should we lose the ability to issue with “Let’s Encrypt Intermediate X1”.

 

The private keys for the ISRG root CA and the Let’s Encrypt intermediate CAs are stored on hardware security modules (HSMs), which provide a high degree of protection against the keys being stolen.

 

All ISRG keys are currently RSA keys. We are planning to generate ECDSA keys later this year.

 

The generation of these keys and certificates is an important step in getting Let’s Encrypt ready to issue certificates. In the next few weeks, we’ll be saying some more about our plans for going live.

  • 2 weeks later...
Posted

~90 days to go.

 

Let's Encrypt Launch Schedule

 

Let’s Encrypt has reached a point where we’re ready to announce our launch schedule.

 

  • First certificate: Week of 27 July 2015
  • General availability: Week of 14 September 2015

We will issue the first end entity certificates under our root under tightly controlled circumstances. No cross-signature will be in place yet, so the certificates will not validate unless our root is installed in client software. As we approach general availability we will issue more and more certificates, but only for a pre-approved set of domains. This limited issuance period will give us time to further ensure that our systems are secure, compliant, and scalable.

 

When it’s time for general availability, we will open up our systems to certificate requests for any domain. A cross-signature from IdenTrust will be in place for general availability, so that our certificates will validate automatically for the vast majority of consumers.

 

Engineering and policy development for Let’s Encrypt began in earnest in mid-October of 2014. If we stay true to the schedule outlined above we will have built an innovative CA, capable of operating at Internet scale and without cutting corners, in just eleven months. That’s quite a feat, given all that’s involved, and a testament to the skill and dedication of our staff, partners, sponsors, and contributors.

  • 2 months later...
Posted (edited)

Just as a reminder that the first certificate for Let's Encrypt becomes available tomorrow.

 

We can’t wait to see websites turn on TLS with Let’s Encrypt. Trust is our most important asset, however, and we need to take the necessary time to make sure our systems are secure and stable.

We’ve decided to push our launch schedule back a bit to give us time to further improve our systems. Our new schedule is:

 

  • First certificate: Week of September 7, 2015
  • General availability: Week of November 16, 2015

In the ten weeks between these two dates we’ll gradually issue more and more certificates. We’ll start by issuing a small number of certs to whitelisted domains and expand our issuance as we gain confidence in our systems (stay tuned for instructions on getting your domains added to our early-access whitelist). When it’s time for general availability we will open up our systems to all requests.

A cross-signature will be in place before general availability. This will allow certificates from Let’s Encrypt to validate automatically for the vast majority of consumers. Prior to cross-signing, browsers will not accept our certificates as valid unless a user has installed our root as trusted.

I want to thank our staff, partners, sponsors, and contributors. We’re making great progress, despite this delay, and it’s all possible due to their hard work.

 

https://letsencrypt.org/2015/08/07/updated-lets-encrypt-launch-schedule.html

Edited by MrKJLS
Grammer
Posted (edited)
Just as a reminder that the first certificate for Let's Encrypt becomes available tomorrow.

Most people are going to have to wait until mid-November though.

 

https://community.letsencrypt.org/t/frequently-asked-questions-faq/26

 

When can I get a certificate from Let's Encrypt?

According to https://letsencrypt.org/2015/08/07/updated-lets-encrypt-launch-schedule.html, the Let's Encrypt CA is planning for general availability of its services in the week of 16 November 2015. If you use the client before then (except as part of a beta test program), you would receive a test certificate that is not signed by a publicly-trusted CA, and that is not accepted by browsers.

Edited by Arthur
  • 1 month later...
Posted (edited)

https://letsencrypt.org/2015/10/19/lets-encrypt-is-trusted.html

 

Let's Encrypt is Trusted

We’re pleased to announce that we’ve received cross-signatures from IdenTrust, which means that our certificates are now trusted by all major browsers. This is a significant milestone since it means that visitors to websites using Let’s Encrypt certificates can enjoy a secure browsing experience with no special configuration required.

 

Both Let’s Encrypt intermediate certificates, Let’s Encrypt Authority X1 and Let’s Encrypt Authority X2, received cross-signatures. Web servers will need to be configured to serve the appropriate cross-signature certificate as part of the trust chain. The Let’s Encrypt client will handle this automatically.

 

You can see an example of a server using a Let’s Encrypt certificate under a new cross-signed intermedate here.

 

Vital personal and business information is flowing over the Internet more frequently than ever, and it’s time to encrypt all of it. That’s why we created Let’s Encrypt, and we’re excited to be one big step closer to bringing secure connections to every corner of the Web.

 

http://vgy.me/zheYVS.png

Edited by Arthur
  • Thanks 2
  • 3 weeks later...
Posted

Not yet, was just testing. This cert was for an rdweb server on iis. The PowerShell tools are not so well developed yet.

So I used another linux server that resolves on the same ip.

I just generated the cert, used openssl to convert the .pem files to a .pfx and copied to the Windows server.

Hopefully the PowerShell side of things will mature soon, as the documentation for it is a bit cryptic and sometimes incorrect. Simple things like missing an "s" off the end of a cmdlet name.

The certs are only 90 days in beta I think.

I

Posted
The certs are only 90 days in beta I think.

It's going to be 90 days after the beta has finished too.

 

https://community.letsencrypt.org/t/maximum-and-minimum-certificate-lifetimes/264/48

 

At launch all certificates will have a lifetime of exactly 90 days. Post launch we will possibly offer more options, but they will likely be on the shorter side rather than the longer side. Part of the rationale for the 90 day number is that when certs are renewed only once a year, a lot can change. The person in charge might forget how to do it, or leave the organization, or change email addresses, etc. A shorter lifetime will hopefully encourage people to automate the renewal process, and we'll provide tools to help with that.

 

There are a couple of reasons for the short lifetime. Our goal is to increase HTTPS usage on the Internet. Part of that goal is decreasing the incidence of avoidable certificate errors, like expiration. Since expiration errors are very commonly caused by human failure, we want to encourage people to automate renewal of their certificates. A ninety day certificate lifetime is a part of that encouragement.

 

However, for people who still would like to manage certificates manually, I think there is a good argument that a person gets better at a task they have to do six times a year than one they have to do once a year. People are less likely to make mistakes, and more likely to set up reminders and make sure there is backup for when they are on vacation.

 

@questiontradition: The stock Let's Encrypt client is configured to attempt renewal at the sixty day mark, with thirty days left before expiry. If it fails, it will send email and the system operator will have a month in which to intervene and correct any problems.

Posted

I missed that bit. [emoji4] still, as they say, the automation will take care of most of that being any kind of issue.

Cheers.

Posted

https://letsencrypt.org/2015/11/12/public-beta-timing.html

 

Let’s Encrypt will enter Public Beta on 3 December 2015. Once we’ve entered Public Beta our systems will be open to anyone who would like to request a certificate. There will no longer be a requirement to sign up and wait for an invitation.

 

Our Limited Beta started on 12 September 2015. We’ve issued over 11,000 certificates since then, and this operational experience has given us confidence that our systems are ready for an open Public Beta.

 

It’s time for the Web to take a big step forward in terms of security and privacy. We want to see HTTPS become the default. Let’s Encrypt was built to enable that by making it as easy as possible to get and manage certificates.

 

We have more work to do before we’re comfortable dropping the beta label entirely, particularly on the client experience. Automation is a cornerstone of our strategy, and we need to make sure that the client works smoothly and reliably on a wide range of platforms. We’ll be monitoring feedback from users closely, and making improvements as quickly as possible.

  • Thanks 1
Posted

Interesting (if true)...

 

Domain validated SSL will soon be free from the large CAs

 

You might have guessed it would happen, but we'll tell you now: Domain validated SSL is soon going to be free from the large CAs. Domain validated (DV) certificates are produced for next to nothing - they don't require any identity checks - and their price has been heading downwards for years. StartCom have given out free DV SSL for years - officially only for non-profits, but in practice for anyone who asked. More recently Mozilla started Let's Encrypt, which provides domain validated SSL for free.
  • Thanks 2
  • 2 weeks later...
Posted (edited)

The public beta has begun...

 

https://letsencrypt.org/2015/12/03/entering-public-beta.html / https://letsencrypt.status.io/

 

We’re happy to announce that Let’s Encrypt has entered Public Beta. Invitations are no longer needed in order to get free certificates from Let’s Encrypt.

 

It’s time for the Web to take a big step forward in terms of security and privacy. We want to see HTTPS become the default. Let’s Encrypt was built to enable that by making it as easy as possible to get and manage certificates.

 

We’d like to thank everyone who participated in the Limited Beta. Let’s Encrypt issued over 26,000 certificates during the Limited Beta period. This allowed us to gain valuable insight into how our systems perform, and to be confident about moving to Public Beta.

Edited by Arthur
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...