diziet: (Default)
Ian Jackson ([personal profile] diziet) wrote2020-03-03 02:36 pm
Entry tags:

Let's Encrypt certificate revocation - panic now!

Let's Encrypt have rather quietly announced (sadly, requires discourse JS!) that they are going to revoke a very large number of certificates.

These revocations will start "no earlier than" 00:00 UTC tonight (24:00 on the 3rd of March), a little over 9h from now. Affected websites etc. may stop working.

I discovered this at about lunchtime UK time today; two of my certs were affected. xenproject.org and linuxfoundation.org are listed as affected and I am trying to get in touch with the hosting provider to get it fixed. One of the domains we in the Xen Project run ourselves, with the help of the contractors who do much of our sysadmin, is affected - and those contractors (who are very competent) didn't know until I told them.

tl;dr: If you are responsible for any Let's Encrypt certificates, check it right away and maybe panic now!


edited 2020-03-03 15:35 to fix arithmetic error

JS

[identity profile] mirbsd.org 2020-03-09 01:48 pm (UTC)(link)
Hm, interesting. I have enabled the CDN in RequestPolicy in Firefox, and the page’s still blank, but yes, it does render nicely in Lynx.

(I also just downloaded the huge list and grepped in it. Much easier than trying to figure out connections to some random site.)