2022年1月27日のブックマーク (1件)

  • Changes to TLS-ALPN-01 challenge validation

    We have made two changes to the way that our TLS-ALPN-01 challenge validation works. These changes will only affect clients that specifically use TLS-ALPN-01; for example, it is not a default choice in Certbot. First, we now guarantee that our client which reaches out to conduct the “acme-tls/1” handshake will negotiate TLS version 1.2 or higher. If your ACME client or integration only supports a

    Changes to TLS-ALPN-01 challenge validation
    jovi0608
    jovi0608 2022/01/27
    Let's Encryptの大量失効、ACME TLS-ALPN-01チャレンジをTLS1.2以上縛りにしてなかったのね。証明書で使う拡張もドラフト時点のOIDをサポートし続けていたと。certbotは影響なしなので一安心。