Conversation
|
Asking for content review first, once we're happy with that I'll commit all the other language files for this. That'll keep the diff UI here cleaner during content review. |
aarongable
left a comment
There was a problem hiding this comment.
Content generally LGTM, especially the justifications around why we offer the lifetimes that we do. Some of the more factual information seems redundant with what's already explained on the Profiles page (https://letsencrypt.org/docs/profiles/), so we should at the very least link to that, if not replace some of this language with just a link to that to prevent duplication.
|
Another benefit is that shorter lifetimes limit the damage from properly-issued certificates whose contents become incorrect during their lifetimes. For DV, that's largely the case of "control of the underlying subject identifier changed". For other forms of certificates that Let's Encrypt doesn't issue it could be that some other detail about the subject changed. A real-world offline example for me is that I had an internship in college and was issued an employee ID with no expiration date. As a result, I used my (unexpired!) employee ID a couple of times after my internship had ended to visit the employer's campus again and enjoy the nice view there. The ID document was no longer accurate, in the sense that the employee relationship it described no longer existed. I didn't do anything harmful or malicious to my former employer or its premises, but their security policy would probably have preferred that former interns be more readily distinguished from current interns! |
|
Note to self: Add a header on the 90 days blog post from 2015 pointing to this documentation. |
This PR is a follow-up on #1983, which was reverted. With this PR in place, the link in the main main menu to the [blog](https://deploy-preview-1994--letsencrypt.netlify.app/blog/) is now preserved.
# Latest from Crowdin - Updates in Czech, Danish, Hebrew, Chinese (China)
# Latest from Crowdin - Updates in Chinese (China)
* Improve wording * Add reference to CertSage (@GriffinSoftware)
This updates the stale subscriber agreement redirects, which exist as a convenience for anyone who clicks a link that includes a trailing period. This adds new redirects from "https://cp-test.letsencrypt.org/" and "https://cps-test.letsencrypt.org/" to the current version of the CPS. Once we validate this works properly, we can stop using a standalone webserver that hosts those URLs, and update this to use the real domains. DNS entries will be required for these to work, which will be handled independently.
Ensure they take priority over page content
# Latest from Crowdin - Updates in Danish, Chinese (China)
November 30 is shortly after we expect our new Sunlight logs to be Usable. February 28 is 90 days later.
> [!NOTE] > Also need to update the isrg-hierarchy.png photo. > [!WARNING] > Don't merge until August 20, after intermediates have been rotated --------- Co-authored-by: Aaron Gable <aaron@letsencrypt.org>
# Latest from Crowdin - Updates in Hebrew, Chinese (China)
Leave a reference here for anyone who may be searching for it, which we can remove in the future.
On the certificates page, move the Gen X intermediates to the "retired" section. Create a new "expired" section to hold the very oldest Gen X intermediates, to prevent the "retired" expando from getting unwieldy. Update the diagram to match. On the profiles page, remove the tlsclient profile and all mentions of the TLS Client Auth EKU. Wordsmith the description of the tlsserver profile somewhat, to paper over the removal and better reflect reality.
There have been at least two posts in the forum from people who expected their short-lived certificates to contain no revocation information.
# Latest from Crowdin - Updates in Chinese (China)
# Latest from Crowdin - Updates in Danish, German, Hebrew, Chinese (China)
## Summary - Adds [Chill SSL](https://www.chillssl.com/) to the monitoring options list on `/docs/monitoring-options/` - Updates `lastmod` in `content/en/docs/monitoring-options.md` Note: I'm the founder/owner of Chill SSL. Chill SSL helps users track SSL certificate expiration dates and receive timely notifications. This follows up on #1926, which was merged and then reverted pending team review. I've been advised the listing can be resubmitted. ## Test plan - [x] Verified locally with `hugo server -F` at `/docs/monitoring-options/` - [x] Link format matches existing entries on the page - [x] `lastmod` updated per repo guidelines Made with [Cursor](https://cursor.com) Co-authored-by: Cursor <cursoragent@cursor.com>
Preparing 2026 Donation Campaign page
The docs currently says that authorization reuse is limited to 398 days which is no longer correct.
# Latest from Crowdin - Updates in Czech, Chinese (Taiwan)
# Latest from Crowdin - Updates in Czech, Danish, German, Chinese (China), Chinese (Taiwan)
# Latest from Crowdin - Updates in Czech, Danish
# Latest from Crowdin - Updates in Czech, Hebrew, Japanese
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.12 to 1.1.16. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/juliangruber/brace-expansion/releases">brace-expansion's releases</a>.</em></p> <blockquote> <h2>v1.1.15</h2> <ul> <li>Backport v5.0.6 change to v1 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>) 0b09384</li> </ul> <hr /> <p><a href="https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15">https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97"><code>447763a</code></a> 1.1.16</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95"><code>d74e630</code></a> fix: v1 backport for CVE-2026-13149 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/122">#122</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24"><code>2203f4f</code></a> 1.1.15</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd"><code>0b09384</code></a> Backport v5.0.6 change to v1 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/111">#111</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3"><code>10c05fc</code></a> 1.1.14</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/1afa1b22ead12f6a7a02f25bf0f7d64c2439b007"><code>1afa1b2</code></a> Add opt-in { max } mitigation to v1 legacy line (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/103">#103</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/2fbb6a2aa0f984bb2fb5f60252ca6cba3e1368ec"><code>2fbb6a2</code></a> Revert "Backport fix for GHSA-7h2j-956f-4vf2 to v1 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/101">#101</a>)" (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/102">#102</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/0d7652e3093d3273151729812f9b0b79a17ecba6"><code>0d7652e</code></a> Backport fix for GHSA-7h2j-956f-4vf2 to v1 (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/101">#101</a>)</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/6c353caf23beb9644f858eb3fe38d43a68b82898"><code>6c353ca</code></a> 1.1.13</li> <li><a href="https://github.com/juliangruber/brace-expansion/commit/7fd684f89fdde3549563d0a6522226a9189472a2"><code>7fd684f</code></a> Backport fix for GHSA-f886-m6hf-6m8v (<a href="https://redirect.github.com/juliangruber/brace-expansion/issues/95">#95</a>)</li> <li>See full diff in <a href="https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.16">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/letsencrypt/website/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Removed [breard-r/acmed](https://github.com/breard-r/acmed) and [icing/mod_md](https://github.com/icing/mod_md) entries from clients.json (repos archived by their owners on Feb 22, 2026 and Jun 9, 2026 respectively)
Several years ago we [changed from the plural Certification Practices Statement to the singular Certification Practice Statement](letsencrypt/cp-cps#174). This PR makes us consistent with _that_. I've only updated the keyword in the translation files, not the actual translated text. That will need further review but I'm not sure of the process because there's no lastmod date in those files. For posterity: ``` grep -rl Practices | xargs sed -i 's/Practices /Practice /g' grep -rl practices | xargs sed -i 's/practices_s/practice_s/g ```
update the zappa url in `clients.json` since its moved. Co-authored-by: Josh Aas <jaas@kflag.net>
|
Doing this work in #2276 instead since I messed up this PR. |
Opening a new PR since I messed up PR #1993
Resolves #1214