Dear colleagues,
Some time ago, there was discussion on this list about deploying
Letsencrypt certificates on anchors. We had said we would investigate
the possibility of doing this.
We are pleased to report that we have worked out how to do this
seamlessly. Early next week, all RIPE Atlas anchors will switch to
Letsencrypt certificates. Note that we will re-use the existing keys on
the anchors to request the Letsencrypt certificates. The TLSA records of
all anchors are pinned to these private keys, and so they will not change.
Regards,
Anand Buddhdev
RIPE NCC