Non-commercial certification authority , community-controlled and providing certificates free of charge to all who wish, on the implementation of a new confirmation scheme for obtaining a certificate for a domain. Accessing the server where the verification catalog "/.well-known/acme-challenge/" is hosted will now be done using several HTTP requests sent from 4 different IP addresses located in different data centers and belonging to different autonomous systems. A verification is considered successful only if at least 3 out of 4 requests from different IPs were successful.
Verification from multiple subnets will minimize the risks of obtaining certificates for others' domains through targeted attacks that redirect traffic by substituting false routes using BGP. Using a multipoint verification system, an attacker will need to simultaneously achieve route redirection for multiple provider autonomous systems with different uplinks, which is significantly more complex than redirecting a single route. Additionally, sending requests from different IPs will enhance the reliability of the verification in case any single Let’s Encrypt hosts are blacklisted (for example, in the RF, some IPs of letsencrypt.org have been blacklisted by Roskomnadzor).
Until June 1, there will be a transitional period allowing for the generation of certificates upon successful verification from the primary data center, in the event of the host's unavailability from other subnets (for instance, this could happen if the host’s administrator allowed requests only from Let’s Encrypt's main data center or due to DNS zone synchronization issues). Based on the logs, a whitelist will be prepared for domains experiencing verification issues from 3 additional data centers. Only domains with completed contact information will be added to the whitelist. If a domain is not automatically included in the whitelist, a request for inclusion can also be submitted through .
As of now, the Let’s Encrypt project has issued 113 million certificates covering about 190 million domains (compared to 150 million domains a year ago, and 61 million two years ago). According to Firefox Telemetry statistics, the global share of page requests over HTTPS is 81% (up from 77% last year and 69% two years ago), while in the USA it is 91%.
Additionally, it is worth noting, Apple Inc.
stop trusting certificates in the Safari browser whose lifespan exceeds 398 days (13 months). This restriction will only apply to certificates issued starting September 1, 2020. For certificates issued before September 1, those with a long lifespan will continue to be trusted, but limited to 825 days (2.2 years).
This change may negatively impact the business of certificate authorities that sell cheap certificates with long validity periods of up to 5 years. Apple believes that generating such certificates poses additional security threats, hinders the prompt adoption of new cryptographic standards, and allows attackers to control victim traffic for extended periods or use it for phishing in the event of an unnoticed certificate leak due to hacking.
Source: opennet.ru
