Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SSL certs for .onions exist for years now, here are two examples: https://www.facebookcorewwwi.onion and https://protonirockerxow.onion

Also v3 onion services are available now with Tor 0.3.2.x-alpha.



But DigiCert says they are no longer issuing them. Probably because the .onion is an 80-bit truncation of a SHA1 hash so it doesn't meet baseline reqs?


Ah, so yeah that's probably why they were waiting for v3 onion services which are 56 characters long now (which are available now as mentioned above).


I don't know what DigiCert's motivation was for suspending issuance of .onion certificates, but the CA/Browser Forum had given a special dispensation (by ballot) for issuance of EV certs despite the criticism about cryptographic strength mismatch. This dispensation didn't extend to DV, but it's never been revoked, so DigiCert would still apparently be able to continue its EV issuance if it wanted to! (But it looks like they've even let the facebookcorewwwi.onion certificate expire.)

I've recently become an observer at the CA/Browser Forum and plan to bring up the subject of DV certificates for next-generation onion services imminently, just as soon as I'm done with my relaxing vacation!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: