Hurricane Electric's IPv6 Tunnel Broker Forums

DNS.HE.NET Topics => General Questions & Suggestions => Topic started by: realdreams on October 05, 2016, 05:00:36 PM

Title: dyn.dns.he.net certificate
Post by: realdreams on October 05, 2016, 05:00:36 PM
Would you guys switch from CACert to Let's Encrypt so no more need for `--no-check-certificate`?
Title: Re: dyn.dns.he.net certificate
Post by: 11rcombs on April 15, 2017, 07:26:35 AM
+1 on this. Additionally, ipv4.dyn.dns.he.net currently uses a cert for dyn.dns.he.net, which is clearly incorrect.
Title: Re: dyn.dns.he.net certificate
Post by: stolen on June 22, 2017, 09:55:50 AM
+1. Anything so that we're not bypassing security checks.
Title: Re: dyn.dns.he.net certificate
Post by: divad27182 on June 23, 2017, 08:44:17 PM
-1 on this.  If you want to check the certificate, install CACert's root certificate.

(Personally, I don't understand how "Let's Encrypt" got into the lists... but then that could apply to most of the listed CAs.)

By the way... it looks like Let's Encrypt does not use a Let's Encrypt certificate.  Should anyone?