Hacker News new | ask | show | jobs
by aroman 34 days ago
Just speculating, but I don't think it's unrelated. Discord heavily utilizes Cloudflare, and Cloudflare uses Let's Encrypt for a certificate issuance. If they happened to have a certificate signing dependency in some operational rollout today, I think it could explain it. Certainly the timing is very correlated.
5 comments

For domains where they handle the certificates, Cloudflare utilizes multiple CAs, to avoid such a single point of failure: I’ve seen Cloudflare managed certificates issued by Let’s Encrypt, Google Cloud, Sectigo, and SSL.com.

Cloudflare does provide the option for customers to manage their own certificates, which would make it the customer’s responsibility to have alternatives issuers when needed.

I guess we'll find out but it would be surprising if they use Let's Encrypt for their backend services. The front door is issued by Google Trust Services.
On my account they always serve Google issued certificates. There is also Let’s encrypt certificate but it is not used though. I guess that’s a fail-safe.
In Cloudflare Enterprise you can pick either or leave it on auto. Iirc there's a 3rd option but I don't know if it's still supported (Terraform and SDKs used to have it in the enum)

https://developers.cloudflare.com/ssl/reference/certificate-...

Cloudflare doesn't issue let's encrypt certs
Just speculating

Then why post? HN is for informed discussion, not every random thought in someone's head.

Certainly the timing is very correlated.

I had chocolate ice cream for breakfast. Certainly the timing is very corrolated [sic].