All posts by Let's Encrypt

ISRG and The Linux Foundation to Collaborate

Post Syndicated from Let's Encrypt original https://letsencrypt.org/2015/04/09/isrg-lf-collaboration.html

Internet Security Research Group (ISRG), the non-profit entity behind Let’s Encrypt, is pleased to announce our collaboration with The Linux Foundation. The Linux Foundation will provide general and administrative support services, as well as services related to fundraising, financial management, contract and vendor management, and human resources.

The Linux Foundation is a non-profit organization dedicated to advancing Linux and collaborative development. Founded in 2000, The Linux Foundation sponsors the work of Linux creator Linus Torvalds and is supported by leading Linux and open source companies and developers from around the world.

While ISRG and Let’s Encrypt are not specifically oriented towards Linux, we share an enthusiasm for solving problems with open and collaborative initiatives. The Linux Foundation hosts a variety of projects that embrace open source and collaborative development practices and principles, ranging from Yocto Project (embedded Linux) to AllSeen Alliance (Internet of Things) and Cloud Foundry (Platform-as-a-Service). It also hosts the Core Infrastructure Initiative, which identifies and funds critical open source projects that support the world’s infrastructure. This was established in response to Heartbleed a year ago and is today funding important work to ensure a secure Internet.

ISRG’s collaboration with The Linux Foundation will allow our staff and management to focus on carrying out our mission. While we do so, we’ll be supported by a team at The Linux Foundation with a wealth of experience helping similar organizations. Furthermore, sharing support infrastructure with other projects allows us to put more of our donors’ money directly towards carrying out our mission.

Draft ISRG Certificate Policy (CP)

Post Syndicated from Let's Encrypt original https://letsencrypt.org/2015/02/19/draft-isrg-cp.html

Update 2015-10-12: These documents are now out of date. Please visit our Policy and Legal Repository for
up-to-date documents.

Today we’re publishing a draft of our Certificate Policy (CP). This is an important document for any Certificate Authority (CA), and we want to give people a chance to review it before we start issuing certificates. Please let us know if you have any questions or comments.

We’re also working on our Certification Practice Statement (CPS), which describes how we’re going to issue certificates under the policies outlined in our CP, but it isn’t quite ready for public review yet. We’re hoping to publish a draft within the next month.

Let’s Encrypt: Delivering SSL/TLS Everywhere

Post Syndicated from Let's Encrypt original https://letsencrypt.org/2014/11/18/announcing-lets-encrypt.html

Vital personal and business information flows over the Internet more frequently than ever, and we don’t always know when it’s happening. It’s clear at this point that encrypting is something all of us should be doing. Then why don’t we use TLS (the successor to SSL) everywhere? Every browser in every device supports it. Every server in every data center supports it. Why don’t we just flip the switch?

The challenge is server certificates. The anchor for any TLS-protected communication is a public-key certificate which demonstrates that the server you’re actually talking to is the server you intended to talk to. For many server operators, getting even a basic server certificate is just too much of a hassle. The application process can be confusing. It usually costs money. It’s tricky to install correctly. It’s a pain to update.

Let’s Encrypt is a new free certificate authority, built on a foundation of cooperation and openness, that lets everyone be up and running with basic server certificates for their domains through a simple one-click process.

Mozilla Corporation, Cisco Systems, Inc., Akamai Technologies, Electronic Frontier Foundation, IdenTrust, Inc., and researchers at the University of Michigan are working through the Internet Security Research Group (“ISRG”), a California public benefit corporation, to deliver this much-needed infrastructure in Q2 2015. The ISRG welcomes other organizations dedicated to the same ideal of ubiquitous, open Internet security.

The key principles behind Let’s Encrypt are:

  • Free: Anyone who owns a domain can get a certificate validated for that domain at zero cost.
  • Automatic: The entire enrollment process for certificates occurs painlessly during the server’s native installation or configuration process, while renewal occurs automatically in the background.
  • Secure: Let’s Encrypt will serve as a platform for implementing modern security techniques and best practices.
  • Transparent: All records of certificate issuance and revocation will be available to anyone who wishes to inspect them.
  • Open: The automated issuance and renewal protocol will be an open standard and as much of the software as possible will be open source.
  • Cooperative: Much like the underlying Internet protocols themselves, Let’s Encrypt is a joint effort to benefit the entire community, beyond the control of any one organization.

If you want to help these organizations in making TLS Everywhere a reality, here’s how you can get involved:

To learn more about the ISRG and our partners, check out our About page.