Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Author here - I plan on switching to Let’s Encrypt once they support ECC certificates.


I think they do support ECC certificates: https://cromwell-intl.com/open-source/google-freebsd-tls/tls...


While I share your ECC preference, for today I see no reason to refuse free, reasonably secure LE support by default. ECDSA signing with LE's RSA intermediates is supported from Feb 2016, and full ECDSA cert chain will be added on July 2018[1].

[1] https://letsencrypt.org/upcoming-features/


Why do you need ECC certificates?


I don't need them, I just prefer them. They are arguably more secure and require much lower CPU usage.


Any reasonably modern x86_64 CPU can do more than 1000 RSA2048 signs (~ TLS handshakes) a second, per core. Performance considerations really aren't a good reason to not use RSA for TLS KEX.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: