True, but I did say “sounds like”. Are you here to give me some hope of it happening much sooner then?!
I really haven’t been tracking the progress of how quickly other domains got added or anything much about let’s encrypt. So my comments aren’t probably worth that much and perhaps I should have disclaimed that earlier. I really did appreciate your reply on github though.
Hi, the more and more i get the feeling that there are larger and larger workarounds for and totally broken system.
-> PSL should provide information for cookie handling and missused for rate limit
-> HSTS preload another list that tell the browser what side should force https
-> HPKP preload one more list that tell the browser what side should use what key
-> Tracking/Malware Domain list stop browser from access cerain domains.
-> CA-List nearly 200 certs that should be trusted as CA
Do you know how large this overhead get? Only to avoid using dns(sec) ?
25316 additions what happened with this ? @weppos Was each verified with the domain owner ?
My personal point of view, and I'm speaking personally here, is that most people still can't understand that Let's Encrypt is currently in beta, and they can't expect the same level of service of a full production service. It just doesn't work like that. It takes time to reach maturity and they've been doing a great job to move forward as fast as they can.
I know therefor i asked if each domain was verified. Also i am wondering why no comment was in the issue after the commit failed. For dlinkdns.com you asked for approval from the domain owner. So i am wondering if this rule
changed in the last two months because no one can expect to check such an long list.
So how does the quality mangement with PSL works ?
I don’t want to bring this thread off-topic, nor I want to abuse the LE hospitality talking about the PSL (unless the response is on topic with the discussion). Therefore, I’d be more than happy to continue the conversation in a more appropriate place, either by email or in the PSL repo itself.
I am working on some documentation that will be published on the PSL wiki to make the process more clear given the recent increasing interest into how we maintain the PSL. I think (and I hope) that will answer these and more questions.
Looks like I found a workaround. I’m sure most of you won’t like it, because you will not be generating your private key yourself, but for those who just want a certificate for playing around it will do.
I ordered a free certificate at checkdomain.de and it looks like they can order a certificate without the need to be on that PSL. It took me less than 10 Minutes to get a valid letsencrypt certificate.
I don’t think that is a “workaround”, it’s subject to the same rate limits as anyone else using a Let’s Encrypt certificate.
Note though that the rate limits have changed ( increased) and the current limits are 20 certificates / 7 days. Currently only 19 have been issued for no-ip.biz ( including yours ), so it’s within the current rate limits.
Interesting. Where did you get this information from? I tried generating a certificate just hours before and did get the errormessage saying that too many certificates have been issued for no-ip.biz. So this might be a coincidence and just after me trying to get a certificate, the limit has risen, but since no-ip is trying to get on that PSL for over 5 month and many people that complained about the problem get to hear things like “well BUY a domian to solve your problem” I think that is unlikely - Anyway: I would really like to try that later. So again: where ca I find the information about the remaining certificates for a specific domain?
Alternatively you can use the lectl bash script which tells you all the recent certs issued ( for the given domain) and when the next certificate can be issued. In the case the “20th certificate” was issued just an hour after yours, and the next slot to get a certificate will be in approx 45 mins time ( since then it will be only 19 certs again within the 7 day period).
I tried to use the bash script on OSX. Looks like it does not work correctly:
2016/April/18 20:38:27 - Checking certs for no-ip.biz
usage: date [-jnu] [-d dst] [-r seconds] [-t west] [-v[+|-]val[ymwdHMS]] …
[-f fmt date | [[[mm]dd]HH]MM[[cc]yy][.ss]] [+format]
usage: date [-jnu] [-d dst] [-r seconds] [-t west] [-v[+|-]val[ymwdHMS]] …
[-f fmt date | [[[mm]dd]HH]MM[[cc]yy][.ss]] [+format]
[…]
usage: date [-jnu] [-d dst] [-r seconds] [-t west] [-v[+|-]val[ymwdHMS]] …
[-f fmt date | [[[mm]dd]HH]MM[[cc]yy][.ss]] [+format]
usage: date [-jnu] [-d dst] [-r seconds] [-t west] [-v[+|-]val[ymwdHMS]] …
[-f fmt date | [[[mm]dd]HH]MM[[cc]yy][.ss]] [+format]
I have found 121 non expired certificates for domain no-ip.biz and its subdomains *.no-ip.biz
I haven’t tried that script on OSX, as all my servers are various flavours of Debian or RedHat. On those the script gives input like;
$ lectl no-ip.biz
lectl 0.6 (2016-April-04)
2016/April/18 19:53:01 - Checking certs for no-ip.biz
I have found 121 non expired certificates for domain no-ip.biz and its subdomains *.no-ip.biz
CRT ID DOMAIN (CN) VALID FROM VALID TO EXPIRES IN
16877791 kumzugloom.no-ip.biz 2016-Apr-18 10:04 BST 2016-Jul-17 10:04 BST 89 days
16876915 hubermi.no-ip.biz 2016-Apr-18 09:29 BST 2016-Jul-17 09:29 BST 89 days
16861259 alamobowl.no-ip.biz 2016-Apr-17 20:37 BST 2016-Jul-16 20:37 BST 89 days
16859527 sonic-server.no-ip.biz 2016-Apr-17 19:20 BST 2016-Jul-16 19:20 BST 88 days
16858973 stepardo.no-ip.biz 2016-Apr-17 18:49 BST 2016-Jul-16 18:49 BST 88 days
16851617 skralpha.no-ip.biz 2016-Apr-17 14:46 BST 2016-Jul-16 14:46 BST 88 days
16823741 hodn.no-ip.biz 2016-Apr-17 09:23 BST 2016-Jul-16 09:23 BST 88 days
16823469 blackbird86.no-ip.biz 2016-Apr-17 09:06 BST 2016-Jul-16 09:06 BST 88 days
16822416 thomaskueppers.no-ip.biz 2016-Apr-17 08:09 BST 2016-Jul-16 08:09 BST 88 days
16821102 dvv32.no-ip.biz 2016-Apr-17 06:45 BST 2016-Jul-16 06:45 BST 88 days
16818150 skralpha.no-ip.biz 2016-Apr-17 03:25 BST 2016-Jul-16 03:25 BST 88 days
16817561 skralpha.no-ip.biz 2016-Apr-17 02:38 BST 2016-Jul-16 02:38 BST 88 days
16817533 skralpha.no-ip.biz 2016-Apr-17 02:36 BST 2016-Jul-16 02:36 BST 88 days
16817335 skralpha.no-ip.biz 2016-Apr-17 02:22 BST 2016-Jul-16 02:22 BST 88 days
16771058 betusprime.no-ip.biz 2016-Apr-16 09:51 BST 2016-Jul-15 09:51 BST 87 days
16769255 mrp-shop1.no-ip.biz 2016-Apr-16 08:08 BST 2016-Jul-15 08:08 BST 87 days
16640726 c0m3d1an.no-ip.biz 2016-Apr-14 01:22 BST 2016-Jul-13 01:22 BST 85 days
16549706 dennispa.no-ip.biz 2016-Apr-12 18:54 BST 2016-Jul-11 18:54 BST 83 days
16525178 dnexus.no-ip.biz 2016-Apr-12 09:36 BST 2016-Jul-11 09:36 BST 83 days
16509774 menz-cloud.no-ip.biz 2016-Apr-11 20:09 BST 2016-Jul-10 20:09 BST 83 days
16481041 kumzugloom.no-ip.biz 2016-Apr-11 10:04 BST 2016-Jul-10 10:04 BST 82 days
16480479 sittsko.no-ip.biz 2016-Apr-11 09:44 BST 2016-Jul-10 09:44 BST 82 days
16466637 spookysworld.no-ip.biz 2016-Apr-10 21:35 BST 2016-Jul-09 21:35 BST 82 days
16465727 bully16.no-ip.biz 2016-Apr-10 20:28 BST 2016-Jul-09 20:28 BST 82 days
16464459 jedii.no-ip.biz 2016-Apr-10 19:29 BST 2016-Jul-09 19:29 BST 81 days
16460646 geekshow.no-ip.biz 2016-Apr-10 15:25 BST 2016-Jul-09 15:25 BST 81 days
16432910 kumzugloom.no-ip.biz 2016-Apr-10 10:05 BST 2016-Jul-09 10:05 BST 81 days
16432161 schnidrig.no-ip.biz 2016-Apr-10 08:56 BST 2016-Jul-09 08:56 BST 81 days
16431490 noller.no-ip.biz 2016-Apr-10 07:55 BST 2016-Jul-09 07:55 BST 81 days
16430462 noller.no-ip.biz 2016-Apr-10 05:57 BST 2016-Jul-09 05:57 BST 81 days
16429564 drive.ddns.net 2016-Apr-10 04:21 BST 2016-Jul-09 04:21 BST 81 days
16425528 rlewisuk.no-ip.biz 2016-Apr-09 22:02 BST 2016-Jul-08 22:02 BST 81 days
16422237 markuhn.no-ip.biz 2016-Apr-09 18:24 BST 2016-Jul-08 18:24 BST 80 days
16404855 filedorado.no-ip.biz 2016-Apr-09 12:23 BST 2016-Jul-08 12:23 BST 80 days
16392819 kumzugloom.no-ip.biz 2016-Apr-09 10:06 BST 2016-Jul-08 10:06 BST 80 days
16390650 noller.no-ip.biz 2016-Apr-09 07:37 BST 2016-Jul-08 07:37 BST 80 days
16256165 arutha.no-ip.biz 2016-Apr-06 21:43 BST 2016-Jul-05 21:43 BST 78 days
16200953 baumjohann.no-ip.biz 2016-Apr-05 19:52 BST 2016-Jul-04 19:52 BST 76 days
16173752 kumzugloom.no-ip.biz 2016-Apr-05 10:04 BST 2016-Jul-04 10:04 BST 76 days
16160843 empoknor.no-ip.biz 2016-Apr-04 21:08 BST 2016-Jul-03 21:08 BST 76 days
16112573 kumzugloom.no-ip.biz 2016-Apr-04 10:05 BST 2016-Jul-03 10:05 BST 75 days
16108507 budvisor.no-ip.biz 2016-Apr-04 08:14 BST 2016-Jul-03 08:14 BST 75 days
16099795 emevth.no-ip.biz 2016-Apr-03 20:45 BST 2016-Jul-02 20:45 BST 75 days
16098008 schuelershome.no-ip.biz 2016-Apr-03 18:32 BST 2016-Jul-02 18:32 BST 74 days
16097617 blafoo.no-ip.biz 2016-Apr-03 18:21 BST 2016-Jul-02 18:21 BST 74 days
16095784 jerry344.no-ip.biz 2016-Apr-03 16:09 BST 2016-Jul-02 16:09 BST 74 days
16056128 kumzugloom.no-ip.biz 2016-Apr-03 10:04 BST 2016-Jul-02 10:04 BST 74 days
16055752 lrdbate.no-ip.biz 2016-Apr-03 09:07 BST 2016-Jul-02 09:07 BST 74 days
16055252 reger.no-ip.biz 2016-Apr-03 08:53 BST 2016-Jul-02 08:53 BST 74 days
16052718 shettyland.no-ip.biz 2016-Apr-03 03:42 BST 2016-Jul-02 03:42 BST 74 days
16052194 zorkchang.no-ip.biz 2016-Apr-03 02:12 BST 2016-Jul-02 02:12 BST 74 days
16050448 derdaonline.no-ip.biz 2016-Apr-02 22:52 BST 2016-Jul-01 22:52 BST 74 days
16045318 elpraga.no-ip.biz 2016-Apr-02 18:03 BST 2016-Jul-01 18:03 BST 73 days
16010212 kumzugloom.no-ip.biz 2016-Apr-02 10:04 BST 2016-Jul-01 10:04 BST 73 days
16006556 synonym24.no-ip.biz 2016-Apr-02 02:56 BST 2016-Jul-01 02:56 BST 73 days
16004344 hgn.no-ip.biz 2016-Apr-01 23:13 BST 2016-Jun-30 23:13 BST 73 days
15896000 synonym24.no-ip.biz 2016-Mar-30 17:21 BST 2016-Jun-28 17:21 BST 70 days
15826366 crmaticacloud.no-ip.biz 2016-Mar-29 09:29 BST 2016-Jun-27 09:29 BST 69 days
15819062 hwcibrea.no-ip.biz 2016-Mar-28 23:00 BST 2016-Jun-26 23:00 BST 69 days
15786833 theseg.no-ip.biz 2016-Mar-28 08:39 BST 2016-Jun-26 08:39 BST 68 days
15773286 hofstatt.no-ip.biz 2016-Mar-27 15:14 BST 2016-Jun-25 15:14 BST 67 days
15768916 hofstatt.no-ip.biz 2016-Mar-27 13:15 BST 2016-Jun-25 13:15 BST 67 days
15755799 beef.no-ip.biz 2016-Mar-27 12:14 BST 2016-Jun-25 12:14 BST 67 days
15753457 kumzugloom.no-ip.biz 2016-Mar-27 10:04 BST 2016-Jun-25 10:04 BST 67 days
15751661 gerchri.myftp.biz 2016-Mar-27 06:15 BST 2016-Jun-25 06:15 BST 67 days
15751189 fmosquera.no-ip.biz 2016-Mar-27 05:23 BST 2016-Jun-25 05:23 BST 67 days
15751011 benitoss.no-ip.biz 2016-Mar-27 04:45 BST 2016-Jun-25 04:45 BST 67 days
15747025 nas.annejannes.com 2016-Mar-26 21:22 GMT 2016-Jun-24 22:22 BST 67 days
15745445 szikora.no-ip.biz 2016-Mar-26 19:36 GMT 2016-Jun-24 20:36 BST 67 days
15744927 tsinao.no-ip.biz 2016-Mar-26 19:24 GMT 2016-Jun-24 20:24 BST 67 days
15744861 robuyo.no-ip.biz 2016-Mar-26 19:16 GMT 2016-Jun-24 20:16 BST 67 days
15744502 cdirks.no-ip.biz 2016-Mar-26 18:53 GMT 2016-Jun-24 19:53 BST 66 days
15742237 fabaks.no-ip.biz 2016-Mar-26 15:52 GMT 2016-Jun-24 16:52 BST 66 days
15717920 kumzugloom.no-ip.biz 2016-Mar-26 09:04 GMT 2016-Jun-24 10:04 BST 66 days
15712306 markusm89.no-ip.biz 2016-Mar-25 23:24 GMT 2016-Jun-24 00:24 BST 66 days
15711982 asgatoril.no-ip.biz 2016-Mar-25 23:00 GMT 2016-Jun-24 00:00 BST 66 days
15613178 geoeng.no-ip.biz 2016-Mar-23 16:51 GMT 2016-Jun-21 17:51 BST 63 days
15525791 kumzugloom.no-ip.biz 2016-Mar-22 09:12 GMT 2016-Jun-20 10:12 BST 62 days
15502611 jdkbx.no-ip.biz 2016-Mar-21 19:33 GMT 2016-Jun-19 20:33 BST 62 days
15444929 websta.no-ip.biz 2016-Mar-21 08:13 GMT 2016-Jun-19 09:13 BST 61 days
15392398 kumzugloom.no-ip.biz 2016-Mar-20 09:04 GMT 2016-Jun-18 10:04 BST 60 days
15224591 kumzugloom.no-ip.biz 2016-Mar-16 09:04 GMT 2016-Jun-14 10:04 BST 56 days
15188830 sutthisak.no-ip.biz 2016-Mar-15 08:21 GMT 2016-Jun-13 09:21 BST 55 days
15180065 cyberalberto.no-ip.biz 2016-Mar-14 20:11 GMT 2016-Jun-12 21:11 BST 55 days
15153225 kumzugloom.no-ip.biz 2016-Mar-14 09:04 GMT 2016-Jun-12 10:04 BST 54 days
15110163 nygaardlarsen.no-ip.biz 2016-Mar-12 17:25 GMT 2016-Jun-10 18:25 BST 52 days
14878310 markvamp.no-ip.biz 2016-Mar-08 19:21 GMT 2016-Jun-06 20:21 BST 49 days
14393451 kumzugloom.no-ip.biz 2016-Mar-08 09:05 GMT 2016-Jun-06 10:05 BST 48 days
13875345 pv-moos.no-ip.biz 2016-Mar-07 21:01 GMT 2016-Jun-05 22:01 BST 48 days
13730566 kumzugloom.no-ip.biz 2016-Mar-07 09:04 GMT 2016-Jun-05 10:04 BST 47 days
13667292 nemnapos.no-ip.biz 2016-Mar-05 17:41 GMT 2016-Jun-03 18:41 BST 45 days
13451254 nobbihome.no-ip.biz 2016-Mar-01 20:07 GMT 2016-May-30 21:07 BST 42 days
13426146 kumzugloom.no-ip.biz 2016-Mar-01 09:04 GMT 2016-May-30 10:04 BST 41 days
13413700 martchus.no-ip.biz 2016-Feb-29 22:00 GMT 2016-May-29 23:00 BST 41 days
13379972 kumzugloom.no-ip.biz 2016-Feb-29 09:04 GMT 2016-May-29 10:04 BST 40 days
13341466 smoooms.no-ip.biz 2016-Feb-27 18:34 GMT 2016-May-27 19:34 BST 38 days
13209217 dasmarx.no-ip.biz 2016-Feb-23 20:58 GMT 2016-May-23 21:58 BST 35 days
13188357 kumzugloom.no-ip.biz 2016-Feb-23 09:04 GMT 2016-May-23 10:04 BST 34 days
13182549 home.makeitremote.de 2016-Feb-22 21:14 GMT 2016-May-22 22:14 BST 34 days
13162991 kumzugloom.no-ip.biz 2016-Feb-22 09:04 GMT 2016-May-22 10:04 BST 33 days
13125748 stahl-hd.no-ip.biz 2016-Feb-20 16:29 GMT 2016-May-20 17:29 BST 31 days
12980070 kumzugloom.no-ip.biz 2016-Feb-16 12:01 GMT 2016-May-16 13:01 BST 27 days
12971895 samurei.no-ip.biz 2016-Feb-16 09:15 GMT 2016-May-16 10:15 BST 27 days
12943597 its-gs.no-ip.biz 2016-Feb-15 09:29 GMT 2016-May-15 10:29 BST 26 days
12931074 jerry344rehborn.no-ip.biz 2016-Feb-14 15:52 GMT 2016-May-14 16:52 BST 25 days
12900184 linux64rocks.no-ip.biz 2016-Feb-13 16:43 GMT 2016-May-13 17:43 BST 24 days
12741737 feinbein.no-ip.biz 2016-Feb-09 11:11 GMT 2016-May-09 12:11 BST 20 days
12733958 sjd4.no-ip.biz 2016-Feb-08 17:52 GMT 2016-May-08 18:52 BST 19 days
12711769 schnidrig.no-ip.biz 2016-Feb-08 08:14 GMT 2016-May-08 09:14 BST 19 days
12698502 dangrtje.no-ip.biz 2016-Feb-07 16:31 GMT 2016-May-07 17:31 BST 18 days
12640629 tecci2gom.no-ip.biz 2016-Feb-06 10:11 GMT 2016-May-06 11:11 BST 17 days
12498773 drnoetigenfalls.no-ip.biz 2016-Feb-01 20:33 GMT 2016-May-01 21:33 BST 13 days
12486186 budvisor.no-ip.biz 2016-Feb-01 14:40 GMT 2016-May-01 15:40 BST 12 days
12471720 zeushq.no-ip.biz 2016-Jan-31 21:47 GMT 2016-Apr-30 22:47 BST 12 days
12447192 stepardo.no-ip.biz 2016-Jan-30 20:31 GMT 2016-Apr-29 21:31 BST 11 days
12420375 shettyland.no-ip.biz 2016-Jan-30 10:28 GMT 2016-Apr-29 11:28 BST 10 days
12275715 elpraga.no-ip.biz 2016-Jan-25 21:28 GMT 2016-Apr-24 22:28 BST 6 days
12272568 empoknor.no-ip.biz 2016-Jan-25 15:32 GMT 2016-Apr-24 16:32 BST 5 days
12247038 slentner.no-ip.biz 2016-Jan-24 14:01 GMT 2016-Apr-23 15:01 BST 4 days
12211264 jerry344.no-ip.biz 2016-Jan-23 15:17 GMT 2016-Apr-22 16:17 BST 3 days
12163751 smhmfb.no-ip.biz 2016-Jan-22 11:36 GMT 2016-Apr-21 12:36 BST 2 days
Sorry, you ca not issue any certificate, you already issued 20 certificates on last 7 days
You could issue next certificate on Monday 2016-Apr-18 20:10:00 BST
Since you already have your certificate, and the new rate limits allow you to renew that certificate, what specific information do you need to know about how to use crt.sh ?
Thank you!
I would prefer to have a certificate, that was created using a private key that has never left my machine.
The certificate I am using, was created by Checkdomain.de. I got my private key by E-mail.
I am temted to say thats fine for me, but technically this wouldn’t be 100% safe.
I think I will just leave it this way, but just in case: I would have to revoke the current certificate to generate a new one right?
edit: I tried using the Script on my QNAP:
[/bin] # ./lectl no-ip.biz
lectl 0.6 (2016-April-04)
2016/April/18 21:15:36 - Checking certs for no-iw.biz
Info: I’ve not found any certificate for the domain no-iw.biz
Since you already have a certificate, you should be able to create a new private key, and generate a certificate from your own machine without hitting the rate limit ( as long as the new certificate is for exactly the same domain as you currently have - since a "renewal" is not subject to the same limits)
Thanks again, I will try to do this on my Qnap. Looks like I will have to read a little bit more ;-).
My first try was using this Web-Interface: https://gethttpsforfree.com/.
I guess there is no such step-by-step guide for dummys for the renewal-process .
I would follow the instructions for generating a certificate in the first place, rather than renewal.
What server / device are you generating the certificate for ? the Qnap ? if so I’d suggest one of the bash scripts in the alternate clients ( I don’t think the official client will run on a Qnap)
It’s a TS-563… It should be capable of running the normal client (since it has a x86 CPU and runs some linux) Maybe I need to install some additional stuff.
Seems OSX is not using GNU date. Check if you have gdate installed which is the GNU date for OSX. If you don't have it installed you can install it using command brew install coreutils
If you can use gdate (it is installed and in your $PATH), then you can download a modified lectl script that uses gdate instead of usual date https://sahsanu.com/sonic/lectl_osx
That is pretty funny, I don't know what is QTS doing (QTS is the OS used in QNAP devices) but seems it doesn't like the standard GNU tools
Send me a private message with the results of command bash -x lectl no-ip.biz so I could check if I can try to solve it.
By the way, just to test, try to launch the script with the domain inside quotes: ./lectl 'no-ip.biz'
Hey there! Just wanted to inform everybody that https://github.com/publicsuffix/list/pull/64 finally got merged today I hope letsencrypt will pull the PSL update into their code soon, then we should finally be able to get certificates for no-ip subdomains