TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Let's Encrypt Launch Schedule

233 pointsby joshmozalmost 10 years ago

9 comments

diafygialmost 10 years ago
I&#x27;m suuuper excited for this to launch! However, it&#x27;s worrisome that the ACME protocol (what Let&#x27;s Encrypt uses) still has a ton of bugs open[1] and they are still changing the protocol often. Just search for &quot;TODO&quot; on the spec markdown[2].<p>I want this project to proceed, but they should really focus on getting a much more mature and stable spec before launch. This isn&#x27;t WebRTC, where you can just continuously tack on additional stuff or change the API constantly. It&#x27;s TLS certs. The certs issued using this API end up telling people it&#x27;s safe to input their passwords or credit card numbers.<p>I really hope the ACME spec gets stable before the launch in July.<p>[1]: <a href="https:&#x2F;&#x2F;github.com&#x2F;letsencrypt&#x2F;acme-spec&#x2F;issues" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;letsencrypt&#x2F;acme-spec&#x2F;issues</a><p>[2]: <a href="https:&#x2F;&#x2F;github.com&#x2F;letsencrypt&#x2F;acme-spec&#x2F;blob&#x2F;master&#x2F;draft-barnes-acme.md" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;letsencrypt&#x2F;acme-spec&#x2F;blob&#x2F;master&#x2F;draft-b...</a>
评论 #9727205 未加载
qrmnalmost 10 years ago
I gather they&#x27;re not launching with ECDSA certificates (and obviously not with EdDSA or whatever comes out of CFRG, because that&#x27;s still being discussed by the IETF&#x2F;IRTF), but they&#x27;re going to add it later. Any idea when?<p>What&#x27;s the hold up; HSMs that&#x27;ll do secp256r1?<p>Because of the huge performance improvement ECDSA brings over RSA, I know I&#x27;m not going to be deploying Let&#x27;s Encrypt certs until I can get ECDSA ones (as well as RSA ones, presumably).
jtchangalmost 10 years ago
I am really excited about this whole initiative. Mostly because encryption should really be standard at this point if not for the hurdles one has to face in deploying it.<p>What type of help is the Let&#x27;s Encrypt team still needing?
评论 #9726792 未加载
tokenizerrralmost 10 years ago
Very glad to hear there is a launch schedule, have been curious about how this project has been progressing. It&#x27;s a fantastic intiative and I almost can&#x27;t wait until September 14.
EGregalmost 10 years ago
Can someone summarize why this is better than, say, StartSSL or AlphaSSL?
评论 #9726744 未加载
评论 #9726720 未加载
评论 #9727504 未加载
masidaalmost 10 years ago
Very nice initiative.<p>But for me the biggest problem with adoption of SSL is still that every domain name needs it&#x27;s unique IPv4 address, and all problems that come with that, not registering or paying for the SSL certificate.<p>At work, I usually use virtual hosting for about 100 domains on one IP address. I don&#x27;t see us buying an IPv4 address per domain and adding them to my NIC configuration one by one. Once we can safely ignore IPv4 and use IPv6 only it will probably become easier and cheaper.
评论 #9727217 未加载
评论 #9727268 未加载
评论 #9727197 未加载
评论 #9727323 未加载
general_failurealmost 10 years ago
can someone clarify if revokation is free with letsencrypt?<p>Also, who pays for all this infrastructure? Mozilla?
评论 #9727472 未加载
评论 #9727415 未加载
workloginalmost 10 years ago
Do Chrome and Mozilla have Let&#x27;s Encrypt in their Root stores? I don&#x27;t see them.
评论 #9727070 未加载
评论 #9727032 未加载
jglauchealmost 10 years ago
Damnit, my existing cert expires September 12. Any free alternatives to that?
评论 #9726510 未加载
评论 #9726585 未加载
评论 #9726442 未加载
评论 #9727111 未加载
评论 #9727129 未加载
评论 #9730918 未加载
评论 #9726459 未加载