5 ms·
That points to a glaring hole in the modern-day automated web PKI, not Tesla's dangling DNS record. Hell, they issue certificates to IP addresses now. For clou
by sippingabonedry 3d ago
That points to a glaring hole in the modern-day automated web PKI, not Tesla's dangling DNS record.
Hell, they issue certificates to IP addresses now. For cloud systems, ownership of an IP could be a few hours.
This has almost certainly been deemed an acceptable risk.
- xmodem 3d agoThis is why IP certificates are limited to a max lifetime of 6 days. > IP address certificates allow server operators to authenticate TLS connections to IP addresses rather than domain names. Let’s Encrypt supports both IPv4 and IPv6. IP address certificates must be short-lived certificates, a decision we made because IP addresses are more transient than domain names, so validating more frequently is important. https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability https://letsencrypt.org/2026/01/15/6day-and-ip-general-avail...