Skip to content

Comment on Ask HN: Books/guides/resources about running a public, web CA?parent

Comments

How did LetsEncrypt get acceptance everywhere?

In the beginning they partnered with an existing CA so that they could issue certificates that where chained to roots already trusted by the major browsers.

“Getting a new root trusted and propagated broadly can take 3-6 years. In order to start issuing widely trusted certificates as soon as possible, we partnered with another CA, IdenTrust, which has a number of existing trusted roots. As part of that partnership, an IdenTrust root ‘vouches for’ the certificates that we issue, thus making our certificates trusted.”

https://letsencrypt.org/2015/10/19/lets-encrypt-is-trusted/

https://letsencrypt.org/2016/08/05/le-root-to-be-trusted-by-...

https://letsencrypt.org/2023/07/10/cross-sign-expiration/

They were Mozilla's child.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.