frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

6-Day and IP Address Certificates Are Generally Available

https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability
107•jaas•1h ago

Comments

gruez•1h ago
For people who want IP certificates, keep in mind that certbot doesn't support it yet, with a PR still open to implement it: https://github.com/certbot/certbot/pull/10495

I think acme.sh supports it though.

mcpherrinm•54m ago
Some ACME clients that I think currently support IP addresses are acme.sh, lego, traefik, acmez, caddy, and cert-manager. Certbot support should hopefully land pretty soon.
sgtcodfish•6m ago
cert-manager maintainter chiming in to say that yes, cert-manager should support IP address certs - if anyone finds any bugs, we'd love to hear from you!

We also support ACME profiles (required for short lived certs) as of v1.18 which is our oldest currently supported[1] version.

We've got some basic docs[2] available. Profiles are set on a per-issuer basis, so it's easy to have two separate ACME issuers, one issuing longer lived certs and one issuing shorter, allowing for a gradual migration to shorter certs.

[1]: https://cert-manager.io/docs/releases/ [2]: https://cert-manager.io/docs/configuration/acme/#acme-certif...

ivanr•1h ago
As already noted on this thread, you can't use certbot today to get an IP address certificate. You can use lego [1], but figuring out the exact command line took me some effort yesterday. Here's what worked for me:

    lego --domains 206.189.27.68 --accept-tos --http --disable-cn run --profile shortlived
[1] https://go-acme.github.io/lego/
Svoka•54m ago
I wonder if the support made it to Caddy yet

(seems to be WIP https://github.com/caddyserver/caddy/issues/7399)

jsheard•44m ago
IPv4 certs are already working fine for me in Caddy, but I think there's some kinks to work out with IPv6.
mholt•12m ago
It works, but as another comment mentioned there may be quirks with IP certs, specifically IPv6, that I hope will be fixed by v2.11.
iamrobertismo•1h ago
This is interesting, I am guessing the use case for ip address certs is so your ephemeral services can do TLS communication, but now you don't need to depend on provisioning a record on the name server as well for something that you might be start hundreds or thousands of, that will only last for like an hour or day.
iamrobertismo•1h ago
Yeah actually seems pretty useful to not rely on the name server for something that isn't human facing.
axus•1h ago
No dependency on a registrar sounds nice. More anonymous.
organsnyder•1h ago
IP addresses also are assigned by registrars (ARIN in the US and Canada, for instance).
buckle8017•35m ago
Arguably neither is particularly secure, but you must have an IP so only needing to trust one of them seems better.
traceroute66•22m ago
> IP addresses also are assigned by registrars (ARIN in the US and Canada, for instance).

To be pedantic for a moment, ARIN etc. are registries.

The registrar is your ISP, cloud provider etc.

You can get a PI (Provider Independent) allocation for yourself, usually with the assistance of a sponsoring registrar. Which is a nice compromise way of cutting out the middleman without becoming a registrar yourself.

immibis•13m ago
You can also become a registrar yourself - at least, RIPE allows it. However, fees are significantly higher and it's not clear why you'd want to, unless you were actually providing ISP services to customers (in which case it's mandatory - you're not allowed to use a PI allocation for that)
traceroute66•18m ago
> No dependency on a registrar sounds nice.

Actually the main benefit is no dependency on DNS (booth direct and root).

IP is a simple primitive, i.e. "is it routable or not ?".

pdntspa•33m ago
Maybe you want TLS but getting a proper subdomain for your project requires talking to a bunch of people who move slowly?
iamrobertismo•29m ago
Very very true, never thought about orgs like that. However, I don't think someone should use this like a bandaid like that. If the idea is that you want to have a domain associated with a service, then organizationally you probably need to have systems in place to make that easier.
traceroute66•26m ago
> I am guessing the use case for ip address certs is so your ephemeral services can do TLS communication

There's also this little thing called DNS over TLS and DNS over HTTPS that you might have heard of ? ;)

zamadatix•54m ago
Does anyone know when Caddy plans on supporting this?
1a527dd5•50m ago
https://caddy.community/t/doubt-about-the-new-lets-encrypt-c...
mholt•11m ago
We've supported it for about a year!
meling•39m ago
If I can use my DHCP assigned IP, will this allow me to drop having to use self-signed certificates for localhost development?
michaelt•32m ago
No, they will only give out certificates if you can prove ownership of the IP, which means it being publicly routable.
inetknght•22m ago
A lot of publicly routable IP addresses are assigned by DHCP...
wongarsu•9m ago
Finally a reason to adopt IPv6 for your local development
wolttam•18m ago
Browsers consider ‘localhost’ a secure context without needing https

For local /network/ development, maybe, but you’d probably be doing awkward hairpin natting at your router.

treve•15m ago
it's nice to be able to use https locally if you're doing things with HTTP/2 specifically.
hojofpodge•30m ago
Something about a 6 day long IP address based token brings me back to the question of why we are wasting so much time on utterly wrong TOFU authorization?

If you are supposed to have an establishable identity I think there is DNSSEC back to the registrar for a name and (I'm not quite sure what?) back to the AS.for the IP.

ycombinatrix•25m ago
Domains map one-to-one with registrars, but multiple AS can be using the same IP address.
hojofpodge•17m ago
Then it would be a grave error to issue an IP cert without active insight into BGP. (Or it doesn't matter which chain you have.. But calling a website from a sampling of locations can't be a more correct answer.)
bflesch•7m ago
This sounds like a very good thing, like a lot of stuff coming from letsencrypt.

But what risks are attached with such a short refresh?

Is there someone at the top of the certificate chain who can refuse to give out further certificates within the blink of an eye?

If yes, would this mean that within 6 days all affected certificates would expire, like a very big Denial of Service attack?

And after 6 days everybody goes back to using HTTP?

Maybe someone with more knowledge about certificate chains can explain it to me.

Painted Halafian Pottery of Mesopotamia and Prehistoric Mathematical Thinking

https://link.springer.com/article/10.1007/s10963-025-09200-9
1•Schiphol•35s ago•0 comments

Disproof of Large Language Model Consciousness

https://web3.arxiv.org/pdf/2512.12802
1•jbotz•1m ago•0 comments

American Invasion of Greenland (2029)

https://falloutfanfic.fandom.com/wiki/American_Invasion_of_Greenland
1•thastings•3m ago•1 comments

Show HN: You can run real PyTorch in a browser

https://browser-torch.maczan.pl/
2•yu3zhou4•5m ago•0 comments

Future-as-Label: Scalable Supervision from Real-World Outcomes

https://arxiv.org/abs/2601.06336
2•bturtel•5m ago•0 comments

ICE takes back into custody man released for violation of rights

https://apnews.com/article/minnesota-immigration-crackdown-25e46910fcc62fbf5ab341905af9891c
3•willmarch•5m ago•3 comments

Distrobox but with Support for macOS

https://github.com/89luca89/distrobox/pull/1966
1•gigatexal•7m ago•1 comments

Tennessee Man Pleads Guilty to Hacking Supreme Court System

https://news.bloomberglaw.com/us-law-week/tennessee-man-pleads-guilty-to-hacking-supreme-court-sy...
2•perihelions•7m ago•0 comments

Microsoft is closing its employee library and cutting back on subscriptions

https://www.theverge.com/tech/862531/microsoft-library-closure-transition-changes-notepad
3•taubek•7m ago•0 comments

Game Poems

https://www.gamepoems.com/issue01/
1•vvoruganti•9m ago•0 comments

Fake cases, real consequences: The AI crisis facing UK law firms

https://vinciworks.com/blog/fake-cases-real-consequences-the-ai-crisis-facing-uk-law-firms/
2•chrisjj•9m ago•0 comments

Crystal 1.19.0 Is Released

https://crystal-lang.org/2026/01/15/1.19.0-released/
1•Kerrick•9m ago•0 comments

East Germany balloon escape

https://en.wikipedia.org/wiki/East_Germany_balloon_escape
1•robertvc•10m ago•0 comments

Ask HN: Claude Opus performance affected by time of day?

1•scaredreally•11m ago•0 comments

The rise of 'micro' apps: non-developers are writing apps instead of buying them

https://techcrunch.com/2026/01/16/the-rise-of-micro-apps-non-developers-are-writing-apps-instead-...
3•gpi•11m ago•0 comments

Algol (2009)

http://www.duckoftheday.co.uk/search/label/Algol
1•jjgreen•12m ago•0 comments

Dell UltraSharp 52 Thunderbolt Hub Monitor

https://www.dell.com/en-us/shop/dell-ultrasharp-52-thunderbolt-hub-monitor-u5226kw/apd/210-bthw/m...
3•cebert•12m ago•1 comments

ClickHouse Acquires Langfuse

https://clickhouse.com/blog/clickhouse-raises-400-million-series-d-acquires-langfuse-launches-pos...
6•ramonga•12m ago•0 comments

Show HN: Web Bot Auth SDKs (IETF Draft) for Node, Python, WordPress

https://github.com/OpenBotAuth/openbotauth
1•hammadtariq•14m ago•1 comments

Show HN: I'm giving LLM's and agents access to all of your favorite content

https://scrollwise.ai
1•valhalladev•14m ago•0 comments

A (Really) Brief History of Knowledge

https://colinmcginn.net/a-really-brief-history-of-knowledge/
1•bookofjoe•15m ago•0 comments

Building an access framework using Cedar

https://blog.atlas9.design/p/building-an-access-framework-using
1•buchanae•16m ago•0 comments

Bloom Filters

https://arpitbhayani.me/blogs/bloom-filters/
2•tcharan•17m ago•0 comments

AI and Copyright Law

https://www.sfchronicle.com/opinion/openforum/article/ai-copyright-research-law-21282101.php
1•jvilalta•17m ago•0 comments

Is This Billionaire a Financial Genius or a Fraudster?

https://www.nytimes.com/2026/01/16/business/michael-saylor-strategy-bitcoin.html
1•dkobia•18m ago•0 comments

Succinate Modulation Associated with Intermittent Fasting in Obesity

https://onlinelibrary.wiley.com/doi/10.1111/apha.70143
1•simonebrunozzi•18m ago•0 comments

Show HN: YC Advisor – AI grounded in 434 YC essays, interviews, and lectures

https://www.agent37.com/yc
2•vishnukool•19m ago•1 comments

Building a World of Warcraft Server in Elixir: 2025 Update

https://pikdum.dev/posts/thistle-tea-2025-update/
3•pikdum•20m ago•0 comments

Terminalai – Turn natural language into shell commands

https://www.terminalai.app/
1•eibrahim•20m ago•0 comments

Unofficial Friday Beer Event

http://unofficial-fosdem-beer-event.org/
1•edward•21m ago•0 comments