-
Notifications
You must be signed in to change notification settings - Fork 8
Open
Labels
P3Low: Not priority right nowLow: Not priority right now
Description
Right now one can reuse same peerid for requesting certs from Let's Encrypt. Bad actors could be spammy.
We should have limits at registration.libp2p.direct/v1/_acme-challenge broker to ensure there is semi-linear cost (creating new peers and peerids) attached to batch-asking certs.
Unsure what is sensible limit, but as conversation starter:
- Nobody should need more than 10 certs per hour per peerid
Thoughts?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
P3Low: Not priority right nowLow: Not priority right now