Let's Encrypt
Let's Encrypt
Posted Mar 6, 2016 14:41 UTC (Sun) by tialaramex (subscriber, #21167)Parent article: TLS certificate management on Android
This case shouldn't be any trouble or expense now, because we have Let's Encrypt. Indeed having Let's Encrypt allowed me to remove the CA cert I'd manually generated and installed on my personal Android devices to protect my own sites.
For example, I have some sites hosted by Dreamhost, a cheap virtual hosting provider. I can click "Secure Hosting", click on a site, check the box saying I'll use Let's Encrypt thanks, agree to the T&C box and I'm done. Dreamhost sort everything out. It's actually a LOT easier than setting up my own CA was. Maybe 5 seconds per domain once, versus an hour for setup, plus 5 minutes per domain every year.
It's true that _some_ web hosts don't offer Let's Encrypt, preferring instead of hawk an affiliated CA's products. Some still, in 2016, won't let you use SSL with their virtual hosting at all because they're worried your customers on Internet Explorer for Windows XP will be confused (it does seem likely that customers using Windows XP are confused, I'd be confused if I was stuck with Windows XP in 2016) but these are problems with a provider, and I think we can expect them to dwindle away.
CT logs allow us to see that Let's Encrypt is now issuing more certificates than the entire for-profit Certificate Authority market. They also, perhaps not coincidentally allow us to see that Let's Encrypt are one of the few big CAs whose certificates aren't riddled with technical mistakes, CABforum compliance errors and other things you'd like to think a "professional" outfit wouldn't let out the door‡. Turns out that to issue tens of thousands of certificates every day fully automatically you have to get rid of steps like "manually transcribe information from this field into this other field" that cause the for-profit CAs to constantly screw stuff up.
‡ Recently CABforum voted on whether the CAs ought to report "mis-issuance" publicly. This would include both the sort of technical errors I alluded to above, and numerous other types of mistake. The browser vendors voted "Yes", the CAs voted "No" (or in some cases abstained) and so the proposal was dead. Turns out if you constantly screw up it's way easier to just not tell anybody than to investigate why you keep screwing up. Huh.
