Hacker News new | ask | show | jobs
by dane-pgp 2991 days ago
What if you trust them at the time, but then move your domain over to different hosting. Is it possible to revoke the previous certificate, or could your old host theoretically keep hold of the old cert and use it in a MitM attack against you?

Fortunately LE are moving towards shorter and shorter validity periods for certs, which at least limits your risk somewhat.

1 comments

Certificate revocation only really works in theory. Fortunately Let's Encrypt certificates are rather short-lived.