Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If they already have the CA stuff ready can they just release that?

While I'm sure they have something ready[0], I'm not sure they have a fully-worked-out policy for running it (required to get into certificate chains), or a production deployment of it, or a third-party vulnerability test of it.

Additionally, ACME verification is a vaguely complicated protocol which will likely need a tool to sign the various messages involved (or you're going to be looking at munging together OpenSSL commands), and you're looking at the developer preview of that.

[0] https://github.com/letsencrypt/boulder



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: