DV, Domain validated and letsencrypt.org

 Domain Validated;

Organization validated;

Extended validation;

 

Let's Encrypt Getting Started - Let's Encrypt (letsencrypt.org) is a free, automated, and open certificateauthority brought to you by the nonprofit Internet Security Research Group(ISRG).

To enable HTTPS on your website, you need to get a certificate (a type of file) from a Certificate Authority (CA). Let’s Encrypt is a CA. In order to get a certificate for your website’s domain from Let’s Encrypt, you have to demonstrate control over the domain. With Let’s Encrypt, you do this using software that uses the ACME protocol which typically runs on your web host.

      

OCSP Stapling inside the Server. 

ZeroSSL;

OS always trusts identrust DST Root CA *3.  

LetsEncrypt gets Let's Encrypt R3 from DST Root CA *3 that was expired on 9/30/2021.

ISRG Root X1 is Let's Encrypt root, which join the trust list of OS in 2021.

Android >=2.3.6<7.1.1 has Let's Encrypt R3, does not have ISRG Root X1. 

Let's Encrypt wants to improve speed of HTTPS, so they push ECDSA that is smaller .

Certbot | Certbot (eff.org)

评论

此博客中的热门博文

XML, XSL, HTML

Input in element.eleme.io

Data URI是由RFC 2397 ACE