Conversation

who up issuing 300K certificates valid for 3 days

1
0
0

@whitequark i think it’s for ip certificates

1
0
0

@charlotte i think so too but i did not expect that there would be so much demand for them

1
0
0

@whitequark would need to see the methodology but perhaps this is the number observed during a time span so it would count those ip certs ~15-30x as much as a typical 45/90 day cert?

1
0
0

@charlotte oh you're right, i've thought about this but still overcounted the true number

... i actually kinda want an IP certificate myself, let's find out how to get one

1
0
0

@whitequark http or tls-alpn acme challenge on letsencrypt staging (supposedly also prod late this year?). interestingly you can’t use rdns for it?

1
0
1

@charlotte how would you even use RDNS for it?

1
0
0

@whitequark at least some providers let you set arbitrary RRs on in-addr.arpa/ip6.arpa and they will also work as expected

so in principle you could prove ip ownership by setting, say, _acme-challenge.1.2.0.192.in-addr.arpa.

1
0
0

@charlotte oh neat. i haven't used one of those yet i think

1
0
0

@whitequark i have mostly used it for email requirements but the rdns provider i had only had ptr records available which is reasonable

there’s even a fedi instance on ip6.arpa: https://1.6.0.0.8.0.0.b.e.d.0.a.2.ip6.arpa/

0
0
0