[saag] Re: Relative OIDs are the simpler form of OID (Re : A simpler form of OID)
Eric Rescorla <[email protected]>
| Newsgroups | gmane.ietf.saag |
|---|---|
| Message-ID | <CABcZeBO_-FMy1aKc5mT1k=jeYwrE=yMQrSkhjKUh425HDwrcfA@mail.gmail.com> |
On Sun, Sep 21, 2025 at 2:05 PM Salz, Rich <rsalz= [email protected]> wrote: > > > - The cheap TLS certs are cheap because they work with the DNS and > - automatically issue certificates upon proof of control of a DNS name. > > > That’s kind of backwards. A main reason for free certs was because, as a > fundamental principle, the creators of LetsEncrypt wanted them to be free > and automation was seen as one of the best ways to reduce the cost by > removing the human. > Precisely. Demonstrating control of the FQDN was already a standard mechanism of verification at the time LE was launched [0]. It was always in theory possible to automate this,but it was a requirement if you wanted to drive costs down enough to run a free Internet-scale CA. ACME's HTTP-01 and DNS-01 challenges [1] are mostly just standardized ways of doing what people already did by hand in a nonstandardized fashion. -Ekr [0] See https://cabforum.org/uploads/BRv1.2.5.pdf, S 11.1, page 17, items 6 and 7. [1] https://letsencrypt.org/docs/challenge-types/ > > > - They are cheap because Google underwrote the cost of production > because certain ISPs were stealing advertising dollars from Google by > replacing the ads placed by the content provider with ads sold by the ISP. > > > This is completely and totally wrong, and I see that EKR posted some > details about why. > > > _______________________________________________ > saag mailing list -- [email protected] > To unsubscribe send an email to [email protected] > _______________________________________________ saag mailing list -- [email protected] To unsubscribe send an email to [email protected]