9 comments

  • gnabgib a day ago ago

    (29 points) https://news.ycombinator.com/item?id=47343278

    Related 6-Day and IP Address Certificates Are Generally Available (506 points, 2 months ago, 281 comments) https://news.ycombinator.com/item?id=46647491

  • pocksuppet a day ago ago

    As seen in the BND's attack on jabber.ru, some adversaries have no difficulty taking over your IP address. Will this be a new threat vector?

    • CaliforniaKarl a day ago ago

      If an attacker manages to gain ownership of an IP address, and gets a Let's Encrypt certificate for that IP address, the certificate will show up in Certificate Transparency logs. In that way, if people are watching, the attack will become visible fairly quickly.

  • nubinetwork a day ago ago

    When will they let me generate certificates for IMAP and SMTP?

    • neoCrimeLabs a day ago ago

      They never stopped supporting it, to my knowledge. I first started using their certs for my IMAP and SMTP servers 10ish years ago, at least.

      If you use HTTP-01 challenge method you require an HTTP server on the host.

      If you don't want an HTTP server on your imap/smtp server you need to use the DNS-01 challenge method.

      • nubinetwork 17 hours ago ago

        And what if I want to run DNS and http on separate servers than my mail server?

        • neoCrimeLabs 11 hours ago ago

          The same thing everyone else does. Build automation, use configuration management, use cert manager or other similar solutions.

  • apitman a day ago ago

    Nice. I've been using lego for this the past few weeks.

  • greatgib a day ago ago

    They should at least restricted it to IPv6. Here it will be a kill for everyone using mobile network and 5g hotspots.