Let's Encrypt Has Issued a Billion Certificates

pmjcreations

Verified User
Joined
Jul 3, 2019
Messages
67
Who would've guessed that in just four years, a small yet determined group of folks who set out to build a better Web would have issued 1,000,000,000 TLS certificates to do just that?

The Web is now 1 billion certificates stronger than it's ever been.

A Billion Thanks to Let's Encrypt.

 

Peter Laws

Verified User
Joined
Sep 13, 2008
Messages
1,786
Location
London UK

Ironic...... How does this effect DA's system? I mean, how would we know which certs could be affected?
 

glio

Verified User
Joined
Jan 8, 2008
Messages
64
Unfortunately, this means we need to revoke the certificates that were affected
by this bug, which includes one or more of your certificates. To avoid
disruption, you'll need to renew and replace your affected certificate(s) by
Wednesday, March 4, 2020. We sincerely apologize for the issue.
 

activate

Verified User
Joined
May 30, 2017
Messages
34
Location
Terneuzen, Netherlands
The following script should be able to renew all certificates. It is based on a DirectAdmin post: https://help.directadmin.com/item.php?id=2087


Bash:
#!/bin/bash

TASK_QUEUE=/usr/local/directadmin/data/task.queue

cd /usr/local/directadmin/data/users

for i in */domains/*cert.creation_time; do

    DA_DOMAIN=$( echo $i | cut -f 3 -d / | cut -f 1,2 -d .)
    DA_USERNAME=$( echo $i | cut -f 1 -d / )
  
    echo "Adjusting Let's Encrypt certificate renew time for $DA_USERNAME with domain $DA_DOMAIN"
    echo 1577965621 > $i
    echo "Queueing renew of certificate to DirectAdmin for $DA_USERNAME"
    echo 'action=rewrite&value=letsencrypt&domain='"$DA_DOMAIN" >> $TASK_QUEUE

done
Edit: A > was missing from the last line in the for block causing only the last domain to be renewed.

Perhaps this might help some people.
 
Last edited:

ikkeben

Verified User
Joined
May 22, 2014
Messages
714
Location
Netherlands Germany
Ok my double post so you don't mis ;)
Q: How do I know if I’m using an affected certificate?
A:
Here is an online tool that will show you: https://unboundtest.com/caaproblem.html

 
Top