Popular Post Arthur Posted November 18, 2014 Popular Post Posted November 18, 2014 (edited) Free certificates for everyone! Website / Blog / Twitter / EFF Announcement With a launch scheduled for summer 2015, the Let’s Encrypt CA will automatically issue and manage free certificates for any website that needs them. Switching a webserver from HTTP to HTTPS with this CA will be as easy as issuing one command, or clicking one button. Vital personal and business information flows over the Internet more frequently than ever, and we don’t always know when it’s happening. It’s clear at this point that encrypting is something all of us should be doing. Then why don’t we use TLS (the successor to SSL) everywhere? Every browser in every device supports it. Every server in every data center supports it. Why don't we just flip the switch? The challenge is server certificates. The anchor for any TLS-protected communication is a public-key certificate which demonstrates that the server you’re actually talking to is the server you intended to talk to. For many server operators, getting even a basic server certificate is just too much of a hassle. The application process can be confusing. It usually costs money. It’s tricky to install correctly. It’s a pain to update. Let’s Encrypt is a new free certificate authority, built on a foundation of cooperation and openness, that lets everyone be up and running with basic server certificates for their domains through a simple one-click process. Mozilla Corporation, Cisco Systems, Inc., Akamai Technologies, Electronic Frontier Foundation, IdenTrust, Inc., and researchers at the University of Michigan are working through the Internet Security Research Group (“ISRG”), a California public benefit corporation, to deliver this much-needed infrastructure in Q2 2015. The ISRG welcomes other organizations dedicated to the same ideal of ubiquitous, open Internet security. The key principles behind Let’s Encrypt are: Free: Anyone who owns a domain can get a certificate validated for that domain at zero cost. Automatic: The entire enrollment process for certificates occurs painlessly during the server’s native installation or configuration process, while renewal occurs automatically in the background. Secure: Let’s Encrypt will serve as a platform for implementing modern security techniques and best practices. Transparent: All records of certificate issuance and revocation will be available to anyone who wishes to inspect them. Open: The automated issuance and renewal protocol will be an open standard and as much of the software as possible will be open source. Cooperative: Much like the underlying Internet protocols themselves, Let’s Encrypt is a joint effort to benefit the entire community, beyond the control of any one organization. Edited November 18, 2014 by Arthur 6
plexer Posted November 18, 2014 Posted November 18, 2014 Stuck the thread as this is too important to get buried. Ben 2
Arthur Posted November 19, 2014 Author Posted November 19, 2014 Let's Encrypt is only planning to issue DV certificates, since that is the only type that can be issued in a fully automated way. Many organizations will want something other than DV, and they'll have to get such certs from other CAs. Source: https://news.ycombinator.com/item?id=8624634
Meldrew Posted February 5, 2015 Posted February 5, 2015 Just wanted to say that this was mentioned in this month's PC Pro - the security chap, Davey Winder seemed to think it was a good idea. Meldrew.
Arthur Posted June 4, 2015 Author Posted June 4, 2015 Not long now! Let's Encrypt Root and Intermediate Certificates The keys and certificates that will underlie Let’s Encrypt have been generated. This was done during a key ceremony at a secure facility today. Let’s Encrypt will issue certificates to subscribers from its intermediate CAs, allowing us to keep our root CA safely offline. IdenTrust will cross-sign our intermediates. This will allow our end certificates to be accepted by all major browsers while we propagate our own root. Under normal circumstances, certificates issued by Let’s Encrypt will come from “Let’s Encrypt Intermediate X1”. The other intermediate, “Let’s Encrypt Intermediate X2”, is associated with our disaster recovery site and will only be used should we lose the ability to issue with “Let’s Encrypt Intermediate X1”. The private keys for the ISRG root CA and the Let’s Encrypt intermediate CAs are stored on hardware security modules (HSMs), which provide a high degree of protection against the keys being stolen. All ISRG keys are currently RSA keys. We are planning to generate ECDSA keys later this year. The generation of these keys and certificates is an important step in getting Let’s Encrypt ready to issue certificates. In the next few weeks, we’ll be saying some more about our plans for going live.
Arthur Posted June 16, 2015 Author Posted June 16, 2015 ~90 days to go. Let's Encrypt Launch Schedule Let’s Encrypt has reached a point where we’re ready to announce our launch schedule. First certificate: Week of 27 July 2015 General availability: Week of 14 September 2015 We will issue the first end entity certificates under our root under tightly controlled circumstances. No cross-signature will be in place yet, so the certificates will not validate unless our root is installed in client software. As we approach general availability we will issue more and more certificates, but only for a pre-approved set of domains. This limited issuance period will give us time to further ensure that our systems are secure, compliant, and scalable. When it’s time for general availability, we will open up our systems to certificate requests for any domain. A cross-signature from IdenTrust will be in place for general availability, so that our certificates will validate automatically for the vast majority of consumers. Engineering and policy development for Let’s Encrypt began in earnest in mid-October of 2014. If we stay true to the schedule outlined above we will have built an innovative CA, capable of operating at Internet scale and without cutting corners, in just eleven months. That’s quite a feat, given all that’s involved, and a testament to the skill and dedication of our staff, partners, sponsors, and contributors.
MrKJLS Posted September 6, 2015 Posted September 6, 2015 (edited) Just as a reminder that the first certificate for Let's Encrypt becomes available tomorrow. We can’t wait to see websites turn on TLS with Let’s Encrypt. Trust is our most important asset, however, and we need to take the necessary time to make sure our systems are secure and stable. We’ve decided to push our launch schedule back a bit to give us time to further improve our systems. Our new schedule is: First certificate: Week of September 7, 2015 General availability: Week of November 16, 2015 In the ten weeks between these two dates we’ll gradually issue more and more certificates. We’ll start by issuing a small number of certs to whitelisted domains and expand our issuance as we gain confidence in our systems (stay tuned for instructions on getting your domains added to our early-access whitelist). When it’s time for general availability we will open up our systems to all requests. A cross-signature will be in place before general availability. This will allow certificates from Let’s Encrypt to validate automatically for the vast majority of consumers. Prior to cross-signing, browsers will not accept our certificates as valid unless a user has installed our root as trusted. I want to thank our staff, partners, sponsors, and contributors. We’re making great progress, despite this delay, and it’s all possible due to their hard work. https://letsencrypt.org/2015/08/07/updated-lets-encrypt-launch-schedule.html Edited September 6, 2015 by MrKJLS Grammer
Arthur Posted September 6, 2015 Author Posted September 6, 2015 (edited) Just as a reminder that the first certificate for Let's Encrypt becomes available tomorrow. Most people are going to have to wait until mid-November though. https://community.letsencrypt.org/t/frequently-asked-questions-faq/26 When can I get a certificate from Let's Encrypt? According to https://letsencrypt.org/2015/08/07/updated-lets-encrypt-launch-schedule.html, the Let's Encrypt CA is planning for general availability of its services in the week of 16 November 2015. If you use the client before then (except as part of a beta test program), you would receive a test certificate that is not signed by a publicly-trusted CA, and that is not accepted by browsers. Edited September 6, 2015 by Arthur
Arthur Posted October 20, 2015 Author Posted October 20, 2015 (edited) https://letsencrypt.org/2015/10/19/lets-encrypt-is-trusted.html Let's Encrypt is Trusted We’re pleased to announce that we’ve received cross-signatures from IdenTrust, which means that our certificates are now trusted by all major browsers. This is a significant milestone since it means that visitors to websites using Let’s Encrypt certificates can enjoy a secure browsing experience with no special configuration required. Both Let’s Encrypt intermediate certificates, Let’s Encrypt Authority X1 and Let’s Encrypt Authority X2, received cross-signatures. Web servers will need to be configured to serve the appropriate cross-signature certificate as part of the trust chain. The Let’s Encrypt client will handle this automatically. You can see an example of a server using a Let’s Encrypt certificate under a new cross-signed intermedate here. Vital personal and business information is flowing over the Internet more frequently than ever, and it’s time to encrypt all of it. That’s why we created Let’s Encrypt, and we’re excited to be one big step closer to bringing secure connections to every corner of the Web. http://vgy.me/zheYVS.png Edited October 20, 2015 by Arthur 2
LosOjos Posted November 5, 2015 Posted November 5, 2015 I've just been accepted to the beta so will be getting my domain trusted over the weekend
Arthur Posted November 5, 2015 Author Posted November 5, 2015 Just go my first one working! Have you setup your web server so that the certificate gets automatically renewed every 90 days?
DMcCoy Posted November 5, 2015 Posted November 5, 2015 Didn't bother with the beta, 90 days and needing a client is pretty useless for many things :|
box_l Posted November 5, 2015 Posted November 5, 2015 Not yet, was just testing. This cert was for an rdweb server on iis. The PowerShell tools are not so well developed yet. So I used another linux server that resolves on the same ip. I just generated the cert, used openssl to convert the .pem files to a .pfx and copied to the Windows server. Hopefully the PowerShell side of things will mature soon, as the documentation for it is a bit cryptic and sometimes incorrect. Simple things like missing an "s" off the end of a cmdlet name. The certs are only 90 days in beta I think. I
Arthur Posted November 5, 2015 Author Posted November 5, 2015 The certs are only 90 days in beta I think. It's going to be 90 days after the beta has finished too. https://community.letsencrypt.org/t/maximum-and-minimum-certificate-lifetimes/264/48 At launch all certificates will have a lifetime of exactly 90 days. Post launch we will possibly offer more options, but they will likely be on the shorter side rather than the longer side. Part of the rationale for the 90 day number is that when certs are renewed only once a year, a lot can change. The person in charge might forget how to do it, or leave the organization, or change email addresses, etc. A shorter lifetime will hopefully encourage people to automate the renewal process, and we'll provide tools to help with that. There are a couple of reasons for the short lifetime. Our goal is to increase HTTPS usage on the Internet. Part of that goal is decreasing the incidence of avoidable certificate errors, like expiration. Since expiration errors are very commonly caused by human failure, we want to encourage people to automate renewal of their certificates. A ninety day certificate lifetime is a part of that encouragement. However, for people who still would like to manage certificates manually, I think there is a good argument that a person gets better at a task they have to do six times a year than one they have to do once a year. People are less likely to make mistakes, and more likely to set up reminders and make sure there is backup for when they are on vacation. @questiontradition: The stock Let's Encrypt client is configured to attempt renewal at the sixty day mark, with thirty days left before expiry. If it fails, it will send email and the system operator will have a month in which to intervene and correct any problems.
box_l Posted November 5, 2015 Posted November 5, 2015 I missed that bit. [emoji4] still, as they say, the automation will take care of most of that being any kind of issue. Cheers.
Arthur Posted November 13, 2015 Author Posted November 13, 2015 https://letsencrypt.org/2015/11/12/public-beta-timing.html Let’s Encrypt will enter Public Beta on 3 December 2015. Once we’ve entered Public Beta our systems will be open to anyone who would like to request a certificate. There will no longer be a requirement to sign up and wait for an invitation. Our Limited Beta started on 12 September 2015. We’ve issued over 11,000 certificates since then, and this operational experience has given us confidence that our systems are ready for an open Public Beta. It’s time for the Web to take a big step forward in terms of security and privacy. We want to see HTTPS become the default. Let’s Encrypt was built to enable that by making it as easy as possible to get and manage certificates. We have more work to do before we’re comfortable dropping the beta label entirely, particularly on the client experience. Automation is a cornerstone of our strategy, and we need to make sure that the client works smoothly and reliably on a wide range of platforms. We’ll be monitoring feedback from users closely, and making improvements as quickly as possible. 1
Arthur Posted November 20, 2015 Author Posted November 20, 2015 Interesting (if true)... Domain validated SSL will soon be free from the large CAs You might have guessed it would happen, but we'll tell you now: Domain validated SSL is soon going to be free from the large CAs. Domain validated (DV) certificates are produced for next to nothing - they don't require any identity checks - and their price has been heading downwards for years. StartCom have given out free DV SSL for years - officially only for non-profits, but in practice for anyone who asked. More recently Mozilla started Let's Encrypt, which provides domain validated SSL for free. 2
matt40k Posted November 22, 2015 Posted November 22, 2015 Yup, you can get free comando ssl certificates if you use cloudflare for dns
matt40k Posted November 23, 2015 Posted November 23, 2015 Still waiting on schwarzenegger to get back to me on my ssl certificate
DJ-1701 Posted November 23, 2015 Posted November 23, 2015 Still waiting on schwarzenegger to get back to me on my ssl certificate Don't worry, he'll be back . 3
Arthur Posted December 3, 2015 Author Posted December 3, 2015 (edited) The public beta has begun... https://letsencrypt.org/2015/12/03/entering-public-beta.html / https://letsencrypt.status.io/ We’re happy to announce that Let’s Encrypt has entered Public Beta. Invitations are no longer needed in order to get free certificates from Let’s Encrypt. It’s time for the Web to take a big step forward in terms of security and privacy. We want to see HTTPS become the default. Let’s Encrypt was built to enable that by making it as easy as possible to get and manage certificates. We’d like to thank everyone who participated in the Limited Beta. Let’s Encrypt issued over 26,000 certificates during the Limited Beta period. This allowed us to gain valuable insight into how our systems perform, and to be confident about moving to Public Beta. Edited December 3, 2015 by Arthur 1
box_l Posted December 3, 2015 Posted December 3, 2015 This is worth a look for the windows / IIS users https://github.com/Lone-Coder/letsencrypt-win-simple 2
Arthur Posted December 4, 2015 Author Posted December 4, 2015 The following is a web-based ACME client... https://gethttpsforfree.com 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now