Skip to content

Certificate revocation #11

Description

@jprenken

Unfortunately, this service's design is incompatible with the Let's Encrypt Subscriber Agreement, which does not permit sharing private keys. All publicly trusted Certificate Authorities forbid this type of design; see Section 9.6.3 of the CA/B Forum Baseline Requirements.

Let's Encrypt is obligated to revoke any compromised private keys they become aware of. Accordingly, the certificates corresponding to the private keys leaked via this project have been revoked. Although Let's Encrypt can't offer specific guidance about a redesign, take a look at acme-dns for an example of "middleware" that helps with DNS. The Let's Encrypt community forum may have more detailed suggestions and feedback if you need help.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions