Forum Moderators: phranque

Message Too Old, No Replies

New Stricter Validation in Effect

Let’s Encrypt Certificate ACME v2 now Live

         

iamlost

8:08 pm on Feb 19, 2020 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Important notice of change from Let’s Encrypt, the certificate authority:

ACME v1/v2: Validating challenges from multiple network vantage points [community.letsencrypt.org]

On Wednesday February 19th, 2020 we’ll turn on stricter validation requirements in production. We’ll make multiple validation requests from different network perspectives.

Most issuance should continue as normal; we believe that a small number of domain names may need fixing. The most common issue will be hosts that use extremely strict firewall rules to allow validation from only specified IP addresses.

Previously only one validation request from one of our primary datacentres was required. After Feb 19th we will make four total validation requests (1 from a primary datacentre, and 3 from remote datacentres). The primary request and at least 2 of the 3 remote requests must receive the correct challenge response value for the domain to be considered authorized.
In the future we will continue to evaluate adding more network perspectives and may change the number and required threshold.


See also:
Multi-Perspective Validation Improves Domain Validation Security [letsencrypt.org]

lammert

9:35 pm on Feb 19, 2020 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



This will probably harm sites that are restricting their web traffic to one or a handful countries or regions. Validation requests may come from countries that are in their block list and they may nor reach the necessary threshold for proper validation. Also, sites on an anycast address may experience problems but I expect most sites on anycast addresses not to use Let's Encrypt certificates.