aeris22’s avataraeris22’s Twitter Archive—№ 61,281

      1. …in reply to @aeris22
        For information, I remind community.letsencrypt.org/t/support-for-https-only-with-http-01-challenge/15134 which leads to removal http-01 over HTTPS because of "bad provider behaviour".
    1. …in reply to @aeris22
      After more thought, I bet for a doomed tls-sni-01. "Users have the ability to upload certificates for arbitrary names without proving domain control." But validation is **always** on an invalid domain (*.acme.invalid), so you can't prove ownership of the **validating** domain
  1. …in reply to @aeris22
    when deploying **invalid** SAN certificate…