The recent @letsencrypt shutdown of TLS-SNI-01 validation (due to idiotic hosting providers) is very disappointing. It was by far the most convenient, hands-off, universal validation mechanism. https://community.letsencrypt.org/t/2018-01-11-update-regarding-acme-tls-sni-and-shared-hosting-infrastructure/50188 …
That sounds reasonable. Another option discussed on m.d.s.p is to use TLS NPN (e.g. 'acme') as an assertion that the server is secure. This requires code changes though.
-
-
Silly idea: a method where the server tells you what IP address it’ll be verifying from, and you add an iptables rule based on source IP
-
I think part of the rationale for not publishing validation IP addresses and potentially having them be unpredictable is to hinder e.g. BGP attacks to partially hijack the routing of a given IP.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.