{"id":33503,"date":"2019-10-31T21:52:58","date_gmt":"2019-10-31T18:52:58","guid":{"rendered":"https:\/\/prohoster.info\/blog\/kak-dnscrypt-reshil-problemu-prosrochennyh-sertifikatov-vvedya-srok-dejstviya-24-chasa\/"},"modified":"2019-10-31T21:52:58","modified_gmt":"2019-10-31T18:52:58","slug":"kak-dnscrypt-reshil-problemu-prosrochennyh-sertifikatov-vvedya-srok-dejstviya-24-chasa","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-dnscrypt-reshil-problemu-prosrochennyh-sertifikatov-vvedya-srok-dejstviya-24-chasa","title":{"rendered":"How DNSCrypt Solved the Problem of Expired Certificates by Introducing a 24-Hour Validity Period","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"How DNSCrypt Solved the Problem of Expired Certificates by Introducing a 24-Hour Validity Period\" src=\"\/wp-content\/uploads\/2019\/05\/29ae4c0e42182af8b53ae619c67e2387.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIn the past, certificates often expired because they had to be updated manually. People simply forgot to do this. With the advent of Let's Encrypt and automated renewal procedures, this issue seemed to be resolved. However, a recent <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/450478\/\">story with Firefox<\/a><\/noindex> shows that it is still a relevant problem. Unfortunately, certificates continue to expire.<\/p>\n<p>If anyone missed this story, at midnight on May 4, 2019, nearly all Firefox extensions suddenly stopped working.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nAs it turned out, this massive failure occurred because Mozilla's <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1548973\">certificate had expired<\/a><\/noindex>, which was used to sign the extensions. Therefore, they were marked as \"invalid\" and failed the verification (<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/451220\/\">technical details<\/a><\/noindex>). On forums, a workaround suggested disabling extension signature verification in <i>about:config<\/i> or changing the system clock.<\/p>\n<p>Mozilla quickly released a patch for Firefox 66.0.4 that resolves the issue with the invalid certificate, and all extensions return to normal. Developers recommend installing it and <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.mozilla.org\/addons\/2019\/05\/04\/update-regarding-add-ons-in-firefox\/\">not using<\/a><\/noindex> any workarounds for bypassing signature verification as they may conflict with the patch.<\/p>\n<p>Nevertheless, this story once again shows that the expiration of certificates remains a relevant issue today.<\/p>\n<p>In light of this, it's interesting to look at the rather original approach that the developers of the <noindex><a rel=\"nofollow\" href=\"https:\/\/dnscrypt.info\/\">DNSCrypt<\/a><\/noindex>protocol took to address this task. Their solution can be divided into two parts. First, there are short-term certificates. Second, users are warned about the expiration of long-term ones.<\/p>\n<h1>DNSCrypt<\/h1>\n<p>\n<img decoding=\"async\" alt=\"How DNSCrypt Solved the Problem of Expired Certificates by Introducing a 24-Hour Validity Period\" src=\"\/wp-content\/uploads\/2019\/05\/f488766f2747f097c85a95842a9b8010.jpeg\" style=\"display:block;margin: 0 auto;\" \/>DNSCrypt is a protocol for encrypting DNS traffic. It protects DNS communications from interception and MiTM, and also allows bypassing blocks at the DNS query level.<\/p>\n<p>The protocol wraps DNS traffic between the client and server in a cryptographic structure, operating over UDP and TCP transport protocols. To use it, both the client and the DNS resolver must support DNSCrypt. For instance, since March 2016, Yandex has enabled it on its DNS servers and in its browser. Support has also been announced by some other providers, including Google and Cloudflare. Unfortunately, there are not many of them (the official site lists 152 public DNS servers). But the program <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/jedisct1\/dnscrypt-proxy\">dnscrypt-proxy<\/a><\/noindex> can be installed manually on clients running Linux, Windows, and MacOS. There are also <noindex><a rel=\"nofollow\" href=\"https:\/\/dnscrypt.info\/implementations\">server implementations<\/a><\/noindex>.<\/p>\n<p><img decoding=\"async\" alt=\"How DNSCrypt Solved the Problem of Expired Certificates by Introducing a 24-Hour Validity Period\" src=\"\/wp-content\/uploads\/2019\/05\/35e062558be302df07114c0ad7691657.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHow does DNSCrypt work? In brief, the client takes the public key from the chosen provider and uses it to verify its certificates. Within these, there are short-term public keys for the session and a cipher suite identifier. Clients are recommended to generate a new key for every request, while servers should rotate keys <b>every 24 hours<\/b>. The key exchange employs the X25519 algorithm, uses EdDSA for signatures, and utilizes XSalsa20-Poly1305 or XChaCha20-Poly1305 for block encryption.<\/p>\n<p>One of the protocol developers, Frank Denis <noindex><a rel=\"nofollow\" href=\"https:\/\/00f.net\/2019\/05\/04\/fixing-expired-certificates\/\">writes<\/a><\/noindex>, noted that automatic key rotation every 24 hours addressed the issue of expired certificates. In principle, the standard client dnscrypt-proxy accepts certificates with any validity period but issues a warning \"The dnscrypt-proxy key period for this server is too long,\" if it is valid for more than 24 hours. Additionally, a Docker image was released that provides quick key (and certificate) rotation.<\/p>\n<p>First of all, this is extremely beneficial for security: if the server is compromised or the key is leaked, yesterday's traffic cannot be decrypted. The key has already changed. This may pose a problem for the implementation of the \"Yarovaya Law,\" which forces providers to store all traffic, including encrypted ones. It is implied that later this traffic can be decrypted if necessary by requesting the key from the site. However, in this case, the site simply cannot provide it, as it uses short-term keys, discarding the old ones.<\/p>\n<p>But importantly, Denis writes, short-term keys force servers to set up automation from day one. If a server connects to the network and the key rotation scripts are not configured or malfunctioning, this will be immediately detected.<\/p>\n<p>When automation rotates keys every few years, it cannot be relied upon, and people may forget about the expiration of certificates. With daily key rotation, this will be detected instantaneously.<\/p>\n<p>At the same time, if the automation is set up correctly, it doesn't matter how often the keys are changed: once a year, once a quarter, or three times a day. If it works for more than 24 hours, it will work forever, writes Frank Denis. According to him, the recommendation to change keys daily in the second version of the protocol, along with a ready-made Docker image implementing this, effectively reduced the number of servers with expired certificates while improving security.<\/p>\n<p>However, some providers still decided, for some technical reasons, to set the certificate expiry period to more than 24 hours. This issue has mainly been addressed with a few lines of code in dnscrypt-proxy: users receive an informational warning 30 days before the certificate expires, another message of higher severity 7 days before expiry, and a critical message if there are less than 24 hours left on the certificate. This only applies to certificates that originally have a long lifespan.<\/p>\n<p>Such messages give users the opportunity to inform DNS operators about the impending certificate expiry before it becomes too late. <\/p>\n<p>Perhaps if all Firefox users received such a message, someone would surely inform the developers, and they would not allow the certificate to expire. \"I don't recall any DNSCrypt server from the list of public DNS servers having its certificate expire in the last two or three years,\" writes Frank Denis. In any case, it's probably better to warn users first rather than disable extensions without notice.<\/p>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/clck.ru\/FiAb5\"><img decoding=\"async\" alt=\"How DNSCrypt Solved the Problem of Expired Certificates by Introducing a 24-Hour Validity Period\" src=\"\/wp-content\/uploads\/2019\/05\/5f14141bd47e171aca59ba8efb8a2845.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/a><\/noindex><br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/globalsign\/blog\/451506\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u043d\u044c\u0448\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u044b \u0447\u0430\u0441\u0442\u043e \u0438\u0441\u0442\u0435\u043a\u0430\u043b\u0438 \u0438\u0437-\u0437\u0430 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u0438\u0445 \u043d\u0443\u0436\u043d\u043e \u0431\u044b\u043b\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u044f\u0442\u044c \u0432\u0440\u0443\u0447\u043d\u0443\u044e. \u041b\u044e\u0434\u0438 \u043f\u0440\u043e\u0441\u0442\u043e \u0437\u0430\u0431\u044b\u0432\u0430\u043b\u0438 \u044d\u0442\u043e \u0441\u0434\u0435\u043b\u0430\u0442\u044c. \u0421 \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u0435\u043c Let\u2019s Encrypt \u0438 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u043f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u044b \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0432\u0440\u043e\u0434\u0435 \u0431\u044b \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0434\u043e\u043b\u0436\u043d\u0430 \u0431\u044b\u0442\u044c \u0440\u0435\u0448\u0435\u043d\u0430. \u041d\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u044f\u044f \u0438\u0441\u0442\u043e\u0440\u0438\u044f \u0441 Firefox \u043f\u043e\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442, \u0447\u0442\u043e \u043d\u0430 \u0441\u0430\u043c\u043e\u043c \u0434\u0435\u043b\u0435 \u043e\u043d\u0430 \u043f\u043e-\u043f\u0440\u0435\u0436\u043d\u0435\u043c\u0443 \u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u0430. \u041a \u0441\u043e\u0436\u0430\u043b\u0435\u043d\u0438\u044e, \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u044b \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u044e\u0442 \u0438\u0441\u0442\u0435\u043a\u0430\u0442\u044c. \u0415\u0441\u043b\u0438 \u043a\u0442\u043e-\u0442\u043e \u043f\u0440\u043e\u043f\u0443\u0441\u0442\u0438\u043b \u044d\u0442\u0443 \u0438\u0441\u0442\u043e\u0440\u0438\u044e, \u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":25203,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-33503","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u043d\u044c\u0448\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-dnscrypt-reshil-problemu-prosrochennyh-sertifikatov-vvedya-srok-dejstviya-24-chasa\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u043a DNSCrypt \u0440\u0435\u0448\u0438\u043b \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u043f\u0440\u043e\u0441\u0440\u043e\u0447\u0435\u043d\u043d\u044b\u0445 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432, \u0432\u0432\u0435\u0434\u044f \u0441\u0440\u043e\u043a \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f 24 \u0447\u0430\u0441\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u043d\u044c\u0448\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-dnscrypt-reshil-problemu-prosrochennyh-sertifikatov-vvedya-srok-dejstviya-24-chasa\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:52:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:52:58+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47How DNSCrypt Solved the Expired Certificate Issue by Introducing a 24-Hour Expiry | ProHoster","description":"Previously.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-dnscrypt-reshil-problemu-prosrochennyh-sertifikatov-vvedya-srok-dejstviya-24-chasa","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u043a DNSCrypt \u0440\u0435\u0448\u0438\u043b \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u043f\u0440\u043e\u0441\u0440\u043e\u0447\u0435\u043d\u043d\u044b\u0445 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432, \u0432\u0432\u0435\u0434\u044f \u0441\u0440\u043e\u043a \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f 24 \u0447\u0430\u0441\u0430 | ProHoster","og:description":"\u0420\u0430\u043d\u044c\u0448\u0435.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-dnscrypt-reshil-problemu-prosrochennyh-sertifikatov-vvedya-srok-dejstviya-24-chasa","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:52:58+00:00","article:modified_time":"2019-10-31T18:52:58+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"33503","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 15:31:39","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:39:23","updated":"2026-01-21 15:31:39","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/33503","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=33503"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/33503\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/25203"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=33503"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=33503"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=33503"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}