Jump to content

Let’s Encrypt - A free certificate authority from the EFF, Mozilla, Akamai and Cisco


Recommended Posts

Posted
Now if they could just extend it to s/mime certs for email, then people could actually start doing secure email, put all those stupid "secure" email companies out of business

LE aren't interested in offering S/MIME certs...

 

https://news.ycombinator.com/item?id=19796853

 

Head of Let's Encrypt here.

 

So far as we can tell, there is no viable plan for mass adoption of S/MIME. It will remain a niche system whether or not we participate. There is no opportunity for impact that would justify the effort and expense on our part, no vision for the future of S/MIME that we're excited about.

 

There was a viable plan for mass adoption of HTTPS in a reasonable time frame, that's why we chose to execute.

 

A fundamental difference between those two ecosystems is that the burden of HTTPS is almost entirely on server administrators, end users don't have to do anything. The HTTPS user-agent ecosystem has been solidly in place for a while. In the S/MIME case individuals need to be more participatory, and it's hard to get end-users to do anything, let alone correctly.

 

That's that, then! S/MIME is basically pointless. :(

Posted
LE aren't interested in offering S/MIME certs...

 

https://news.ycombinator.com/item?id=19796853

 

 

 

That's that, then! S/MIME is basically pointless. :(

 

Always will be until it's free and automatic.

 

The argument that "the owner of the domain could register and have your private key" is a bit daft though, if you don't trust your email provider why are you still using them? Today they can read all your email, afterwards they could in theory read all your email, but you'd know if they tried without asking you.

  • 2 weeks later...
Posted

Introducing Oak, a Free and Open Certificate Transparency Log

 

Today we are announcing a new Certificate Transparency log called Oak. The Oak log will be operated by Let’s Encrypt and all publicly trusted certificate authorities will be welcome to submit certificates.

 

Sectigo generously provided funding to cover a significant portion of our costs to run our CT log. “Sectigo is proud to sponsor the Let’s Encrypt CT Log. We believe this initiative will provide much-needed reinforcement of the CT ecosystem,” said Ed Giaquinto, Sectigo’s CIO. We thank them for their collaboration to improve Internet security.

 

Certificate Transparency (CT) is a system for logging and monitoring certificate issuance. It greatly enhances everyone’s ability to monitor and study certificate issuance, and these capabilities have led to numerous improvements to the CA ecosystem and Web security. As a result, it is rapidly becoming critical Internet infrastructure. Let’s Encrypt accelerated the adoption of CT by logging every certificate since we started issuing in 2015 - approximately half a billion certificates at this point.

 

We decided to create and operate a CT log for a few reasons. First, operating a log is consistent with our mission to create a more secure and privacy-respecting Web. We believe transparency increases security and empowers people to make well-informed decisions. Second, operating a log helps us take control of our destiny. Google Chrome requires all new certificates to be submitted to two separate logs, so multiple log options are imperative to our operation. Finally, Let’s Encrypt often issues more than 1M certificates each day, so we wanted to design a CT log that is optimized for high volume. We’ve designed our log to be able to handle submissions from all other publicly trusted Certificate Authorities so they can use Oak to fulfill their logging requirements as well.

 

Our log uses Google’s Trillian software running on AWS infrastructure. We use Kubernetes for container orchestration and job scheduling and AWS RDS for database management.

 

We are submitting our log for inclusion in the approved log lists for Google Chrome and Apple Safari. Following 90 days of successful monitoring, we anticipate our log will be added to these trusted lists and that change will propagate to people’s browsers with subsequent browser version releases.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...