Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jaas
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
jaas
3mo ago
No worries
2.
▲
by
jaas
3mo ago
Yeah, thanks
3.
▲
by
jaas
3mo ago
Since Let's Encrypt wasn't down most of the day if would be helpful if you could update the title to reflect that.
4.
▲
by
jaas
3mo ago
Mostly 90 days, and we recommend renewing at 60 days for 90 day certs. That gives more than four weeks of leeway. If you're one of the few early adopters of short-lived (6-day) certs you should renew at 3 days, giving you 3 days for a
5.
▲
by
jaas
3mo ago
It would not have been sticky for the entire day. If it was sticky at all, it would have been only during the 90 minute period I referenced. It's most likely that there is some other issue with how you're requesting the cert. Folk
6.
▲
by
jaas
3mo ago
> That explains why one of my IoT vendors is using an expired certificate. I don't think so. There was a dip in success rates for 90 minutes today, but nobody should be renewing their certificate within 90 minutes of expiration. If
7.
▲
by
jaas
3mo ago
Let's Encrypt has been working normally for most of the day. There was a ~90 minute period during which some of our users would have received a higher error rate due to upstream networking issues, but the majority of requests were succ
8.
▲
by
jaas
3mo ago
I'm not sure if you're talking generally about sanctions or specifically about Let's Encrypt, but to avoid any doubt: citizens of Crimea are free to use Let's Encrypt. We do not, however, serve government entities in occ
9.
▲
by
jaas
3mo ago
I was referring to the requirements imposed on us. When it comes to sanctions, we do not block anything more than what is required by law.
10.
▲
by
jaas
3mo ago
Let's Encrypt continues to be available to almost every vulnerable population in the world, including those that need it most. I say almost as I'm hesitant to speak in absolutes regarding a topic as complex as this. Most of our sa
11.
▲
by
jaas
3mo ago
Sanctions compliance is unfortunately fairly complex. Let's Encrypt can issue certificates for non-government entities in Iran and Russia due to statutory exemptions protecting personal communications, alongside specific Office of Fore
12.
▲
by
jaas
3mo ago
Let's Encrypt certificates continue to be available in both Iran and Russia, just not for the Iranian and Russian governments. The terms of service update to clarify what we have always done, comply with relevant law, has not changed t
13.
▲
by
jaas
4mo ago
In that sense, prepare yourself to be bored.
14.
▲
by
jaas
4mo ago
Stopping all issuance is an pretty standard response if a CA thinks what they are issuing might be non-compliant in any way. It's an action we're required to take. It's not necessarily a sign of a more dramatic failure mode o
15.
▲
by
jaas
4mo ago
This is a compliance incident, we should be issuing again shortly. Update: Issuance is back up. Update: Preliminary incident report: https://bugzilla.mozilla.org/show_bug.cgi?id=2038351
16.
▲
6-Day and IP Address Certificates Are Generally Available
(letsencrypt.org)
506 points
by
jaas
8mo ago
|
281 comments
17.
▲
by
jaas
9mo ago
Seat heat is one click in my 2022 Volvo. Or as others have noted, you can use your voice.
18.
▲
by
jaas
11mo ago
It’s hard to be ready for a world you do not understand, and the world is a lot more than engineering or any other single subject.
19.
▲
by
jaas
11mo ago
Their networking is awful in my experience. The WiFi chip is cheap crap, extremely sensitive, cuts out a lot, and doesn’t support WPA3. I had to set up a dedicated Nanit-only AP in my house in order to stabilize the connection. It would not
20.
▲
by
jaas
1y ago
I know lots of parents in NYC (where I live with multiple kids) and their lives have not “broken down.” What an absurd statement/generalization.
21.
▲
by
jaas
1y ago
Rust is generally a much better tool for building software than C. When your software is built with better tools, you will most likely get better software (at least eventually / long term, sometimes a transition period can be temporari
22.
▲
by
jaas
1y ago
If you are using Nginx, then likely yes.
23.
▲
by
jaas
1y ago
We buy them because our experience is that they are extremely reliable and their iDrac management system is better than the alternatives, which saves us time (thus money). Maybe they aren’t the cheapest at initial purchase, but less mainten
24.
▲
by
jaas
1y ago
Section 3.2.2.9 of this document: https://cabforum.org/working-groups/server/baseline-requirem... You can also just search the document for the word "Perspective" to find most references to it.
25.
▲
by
jaas
1y ago
Go has a big, high quality standard library with most of what one might need. Means you have to bring in and manage (and trust) far fewer third party dependencies, and you can work faster because you’re not spending a bunch of time figuring
26.
▲
by
jaas
1y ago
The idea is that some people don’t click - that refers mainly to people using a mouse, and many people are not using a mouse. So it is overstating information about what to do.
27.
▲
by
jaas
1y ago
It's not just about the money: "Providing expiration notification emails means that we have to retain millions of email addresses connected to issuance records. As an organization that values privacy, removing this requirement is
28.
▲
by
jaas
1y ago
A free account for sending emails would not have changed the decision because it doesn't solve this: "Providing expiration notification emails means that we have to retain millions of email addresses connected to issuance records.
29.
▲
by
jaas
1y ago
We (Let's Encrypt) are getting rid of subject common names and moving to just using subject alternative names. This change has been made in short-lived (6 day) certificate profiles. It has not been made for the "classic" prof
30.
▲
by
jaas
1y ago
It will work for both.
More ›