Let's Encrypt is adding two new remote perspectives for domain validation

Let's Encrypt is adding two new remote perspectives for domain validation. This change is motivated by the fact that increased perspectives provide more domain validation security. Increasing the number and coverage of our domain validation perspectives improves visibility and protection against BGP attacks.

During domain validation, this means that we will make 5 total validation requests, 1 from the primary datacenter and 4 from remote perspectives (previously 2). For validation to succeed, the primary server and a quorum of remote perspectives must receive the correct challenge response. This makes it more difficult for attackers to hijack validation requests. To learn more about multi-perspective domain validation, please see our earlier blog post when Let's Encrypt first added new perspectives.

We expect little to no impact to users. Let's Encrypt will begin performing domain validation with the new regions in staging next week on Wednesday March 6. Assuming all goes well, we will rollout to production the following week. Updates will be posted in this thread.

18 Likes
Renewal suddenly stopped two days ago
Let's Encrypt Outbound Traffic
"Timeout during connect" but I do get the challenge request
Renewal of existing certificate fails due to domain authentication failure
Certbot certificate validation failing with timeout when all seems to be correct
Renewal of certs fail
Let's Encrypt in FileZilla
Unexpected renewal failures since April 2024? Please read this!
Any changes to multi-perspective validations lately?
Renew Certificate using DreamHost
HTTP-01 error at renewed nginx
Certificate is not for the chosen domain
New Issuance Chains on Staging Failing
The Certificate Authority failed to download the temporary challenge files created by Certbot
IP or pool ip for get ssl?
Errors renewing certificate, Apache, Win 10
Timeout creating new certificate with mailcow
Authority failed to download the temporary
Instabilidade apontada no lets status io pode ocasionar adição na blask List do Google search?
Moving server and change certificate from Certbot to win-acme
Can't get an extra certificate with NGINX (already have a few working)
Sudden renew failures but not firewall block
Timeout during connect (likely firewall problem)
Failure of Cert via Latest version of Win-Acme
Certbot failed to authenticate some domains (authenticator: nginx)
DNS errors for two 'eg.net' host names
Renewal of existing certificate fails due to domain authentication failure
Renewal says fetch timed out, but logs say fetch succeeds
Certbot failed to authenticate some domains (authenticator: standalone)
Certbot 1.22.0 renew stopped working
Timeout during connect (likely firewall problem)
Can't renew with certbot or Crypt::LE, Timeout during secondary validation (403 resolved)
K8s duplicate certs
Let's Encrypt is not renewing
Timeout during connect (likely firewall problem)
Unable to obtain SSL Certificates Apache
NextCloud Timeout during connect (likely firewall problem)
Some challenges have failed
Secondary validation timeout
openSUSE15.6 apache2-2.4.58-150600 2ndary vaidation
AuthorizationError('Some challenges have failed.')
The CA failed to verify the changes made by Certbot
Qualys SSL Server Test vs. SSLChecker Test Conflicts
Request New Cert always Error Getting Validation Data
ERROR: Could not get certificate from Lets Encrypt. Check domain name and if it is reaching the configured service
Renewing my SSL
Certificate expired? what
Website zeezicht-oostende.be not find by SSL
SSL Certificate Renewal Failing for My Website
Could not issue an SSL/TLS certificate for www.domain.com
Certbot --apache -d failed. status 400. DNS problem: NXDOMAIN looking up A for xxx - check that a DNS record exists for this domain
ACME failure on Expressway-E 15
CertSage Authorization still pending after 10 attempts
Timeout during connect (likely firewall problem)
Rate Limit Issue with cloudapp.azure.com
Multi-Perspective Validation & Geoblocking FAQ
Firewall Geoblocking and LetsEncrypt
Failed some CERT renew
Failed validation limit
Certbot stopped working with nginx
org.shredzone.acme4j.exception.AcmeLazyLoadingException
Failed Renew Certificate Error getting validation data
Acme Challenge 404 with webroot
Renewal Failure Starting 5/24/2024 403 Error
Error getting validation data", "status": 400
Https stopped working
Error updating renewal info: "Must specify a request path"

Let's Encrypt is now validating from 4 remote perspectives in staging.

14 Likes

Let's Encrypt is now validating from 4 remote perspectives in prod.

13 Likes