Comment by likeabatterycar
Comment by likeabatterycar 2 days ago
> Our six-day certificates will not include OCSP or CRL URLs.
If someone else did this, Mozilla would be threatening to remove them from their trusted roots.
IP address certs sound like a security nightmare that could be subverted by BGP hijacking. Which is why most CAs don't issue them. Does accessing the ACME challenge from multiple endpoints adequately prevent this type of attack?
Not true. CA's are explicitly allowed to omit CRL support for certificates with a lifetime <= 10 days.