Skip to content
This repository has been archived by the owner on Apr 24, 2020. It is now read-only.

Remove TLS-SNI-02 challenge type and associated refs. #390

Merged
merged 4 commits into from Jan 23, 2018

Commits on Jan 12, 2018

  1. Remove TLS-SNI-02 challenge type and associated refs.

    Recent developments[0][1] have identified real-world server/hosting
    configurations that violate the assumptions of TLS-SNI-01 and its
    currently specified replacement, TLS-SNI-02. In light of these issues
    and the feasibility of addressing them across the entire Internet it
    seems prudent that the ACME specification remove the vulnerable
    challenge type pending the development of a better alternative
    (TLS-SNI-03?). This will allow the draft last-call to proceed while
    the details of TLS-SNI-03 are worked out.
    
    The "Default Virtual Hosts" sub-section of the "Operational
    Considerations" section is removed since it spoke exclusively to
    a concern with TLS-SNI-02 validation. When the dust has settled on
    TLS-SNI-03 we should certainly include a section that describes why
    TLS-SNI-01/02 were removed that could replace this information.
    
    [0]: https://community.letsencrypt.org/t/2018-01-09-issue-with-tls-sni-01-and-shared-hosting-infrastructure/49996
    [1]: https://community.letsencrypt.org/t/2018-01-11-update-regarding-acme-tls-sni-and-shared-hosting-infrastructure/50188
    Daniel committed Jan 12, 2018
    Configuration menu
    Copy the full SHA
    5ef946b View commit details
    Browse the repository at this point in the history
  2. Restore urn:ietf:params:acme:error:tls

    Ilari Liusvaara rightly points out that an HTTP-01 validation that is
    redirected to port 443 may encounter an error that justifies the TLS
    error type.
    Daniel committed Jan 12, 2018
    Configuration menu
    Copy the full SHA
    3441d44 View commit details
    Browse the repository at this point in the history

Commits on Jan 22, 2018

  1. Merge remote-tracking branch 'ietf/master' into cpu-tls-sni-02-we-har…

    …dly-knew-ye
    Daniel committed Jan 22, 2018
    Configuration menu
    Copy the full SHA
    1b93b10 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    0bb71a0 View commit details
    Browse the repository at this point in the history