Hacker News new | past | comments | ask | show | jobs | submit login

Let's Encrypt is great.

I would like to see native ECC support and a more stringent validation mode that allows more than 3 months of certificate lifetime.




More stringent validation methods won't help with the ever-present possibility of private key compromise. So long as that's a real possibility and revocation is broken (which it clearly is), longer certificate lifetimes are a liability. Renewal needs to be automated so you don't care how often you have to renew.

Let's Encrypt will sign your ECC keys now, but we'll sign with our RSA keys. We'll likely have our own ECC trust chain some time next year.


March 2018 for native ECC support: https://letsencrypt.org/upcoming-features/




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: