Thanking the @letsencrypt folks for the excellent work they do, and especially for their upcoming support for security certificates for IP addresses which is nothing short of revolutionary for the future of the (Small) Web.

https://community.letsencrypt.org/t/getting-ready-to-issue-ip-address-certificates/238777/22

#SmallWeb #security #IPAddresses #WebNumbers #LetsEncrypt #SmallTech #decentralisation #peerToPeerWeb #findability

@aral the return of HOSTS files :)

@petrillic @aral but worse

Personally I'm still mad at the #Cockblocking #GAFAMs who sabotaged @cacert which IMHO was a better concept that @letsencrypt per very design!

@aral That's super interesting - love your blog post :-)

Any thoughts on how the Web Number should fit in the vCard format? A specific type of URL? Or maybe a SERVICE TYPE of a SOCIAL PROFILE?

(I just read a bit about this standard https://www.rfc-editor.org/rfc/rfc9554.html#name-socialprofile)

RFC 9554: vCard Format Extensions for JSContact

This document defines a set of new properties for vCard and extends the use of existing ones. Their primary purpose is to align the same set of features between the JSContact and vCard formats, but the new definitions also aim to be useful within just the vCard format. This document updates RFC 6350 ("vCard Format Specification").

@keunes Given it’s just a URI, no changes should be necessary.
@keunes And thank you for the kind words :) 💕

@aral @letsencrypt Perhaps to avoid misunderstanding of commutation..

A web number is a IP address.

An IP address is not a web number.

@telmi @letsencrypt Good point.

Maybe I’ll add something along the lines of “Every Web Number is an IP Address but not every IP address is a Web Number.” :)

@aral @letsencrypt

Interesting. No wonder that they will stop the email warnings for certs close to expiry.

Probably will be useless if you have to deal with CGNAT.

@SpaceLifeForm @letsencrypt I believe that’s more to do with the short-lived certs (IP address certs will be short-lived) and getting people off of manual renewal processes altogether.

@aral @letsencrypt

Exactly. I can not imagine many are still doing the manual process any longer.

Imagine if certs only lasted a day.

Actually, don't imagine it. It is a horrible idea even if automated.