-
Notifications
You must be signed in to change notification settings - Fork 371
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Consider making ecdsa (p-256) the default certificate type #417
Comments
When creating a 3.x release with ACMEv2 included I can definitely imagine to do this. Not sure if we should change the default behaviour for the current stable releases |
Hi, Yours, |
@tsufz Technically, Certbot is changing its default. Certbot is just one of many ACME clients (including getssl) Let's Encrypt Certificate Authority does not create ACME clients - only the ACME Server. Certbot is created by the EFF. That said, I agree getssl should consider that. Perhaps after Certbot makes that change to highlight any problems that might arise. |
I'm not sure if this is the ideal place to post this, but I just wanted to give people a heads-up that Mozilla's future "Server Side TLS" guidelines will recommend ECDSA certificates for the Intermediate configuration level. This is one of the most commonly used TLS configurations for servers across the internet.
mozilla/server-side-tls#178
mozilla/server-side-tls#254
https://ssl-config.mozilla.org/
In our research, we found that ECDSA and RSA certificates were equally compatible with the vast majority of clients across the internet, comprising this set of clients:
The reason why we are recommending ECDSA certificates over RSA certificates is that they give IE11 clients on Windows 7 access to ECDHE for key exchange; with RSA they are limited to classic DHE. My apologies if this project already uses ECDSA by default.
Please let me know if you have any questions! Thanks!
The text was updated successfully, but these errors were encountered: