Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes. The procedure you describe could also have been done any time prior to expiry, and more easily of course since the web still worked back then.

The time is completely arbitrary by the way, the people who minted the certificate could of course choose something else, but by default it's likely if it happens to be 14:26:39 UTC when you make the certificate, it's also going to expire at 14:26:39 UTC however many years in the future.

It's a little disappointing that sites catering to people who run old stuff (e.g. both old iPads and old Macs) didn't put much work into e.g. low friction ways to make this happen. Perhaps that's something where Let's Encrypt should have reached out to the right people and made sure this was on their agenda back in the summer.

But perhaps most people in your situation don't pay any attention to such things anyway and would still have been blind-sided.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: