ACME TLS-SNI-01 validation disabled due to vulnerability – Incidents – Let’s Encrypt Community Support
Posted by jpluimers on 2018/01/11
Now that so many sites depend on LetsEncrypt: maybe it is time for a second one.
We’ve received a credible report of a problem with ACME TLS-SNI-01 validation which could allow people to get certificates they should not be able to get. While we investigate further we have disabled tls-sni-01 validation. We’ll post more information soon.
Source: [Archive.is] ACME TLS-SNI-01 validation disabled due to vulnerability – Incidents – Let’s Encrypt Community Support
Via:
- [WayBack] Wie viel Internet kippt mittlerweile eigentlich um, wenn letsencrypt weg ist? Ein zweites letsencrypt wäre toll. – Stefan Funke – Google+
- [WayBack] Wie viel Internet kippt mittlerweile eigentlich um, wenn letsencrypt weg ist? Ein zweites letsencrypt wäre toll. – Kristian Köhntopp – Google+
–jeroen






Leave a comment