"There is an ongoing incident that will force issuance to be halted."
Feels like they were alerted to some current problem severe enough that "turn it off now" was the right move. Breaking the baseline requirements somehow maybe?
People went ballistic on me a few months ago for bringing this up, but this is exactly the kind of outage that makes me really, really worried about extremely short lived certificates. https://news.ycombinator.com/item?id=46118371
I'm not sure I follow. This outage seems like it occurred for less than 1 day. The post you link to is about having certificates expire after 45 days. What's the connection you see?
Yeah, if Heroku's cert rotation depends on Google's CA and it tried to renew during the outage window, that'd definitely cause problems. The 8-hour ETA is rough. This is why multi-CA fallback configs exist, but most platforms don't bother until they get burned by something like this. Worth checking if your apps are actually affected or if it's just the dashboard/API having issues.
I worked at RSADSI when I was a kid and supported the custom spin of TIPEM Hayden and Sophia used at Verisign. This brings back some very bad memories.
But... hopefully... people created overlapping windows of cert validity so there's always a valid cert available for their services and can tolerate the CA being out of action for 8(?) hours. Imagine if your TGS/Kerberos or AWS IAM IdP was down for 8 hours.
For persistent services using the affected ACME API, the window is usually 30 days.
But that didn’t stop Youtube and Youtube TV from going down hard. I imagine they’re provisioning ephemeral VMs or service instances and relying on them being able to get certs immediately, or something like that.
It is a well-known fact that the moment YouTube goes down, the collective productivity of Earth increases by approximately 4,000%, which is immediately squandered by everyone going to Hacker News to read comments about YouTube being down. I myself have taken to podcasts… an ancient medium in which people simply talk at you for ninety minutes without a single sponsorship for a mobile game, and this is considered a failure
Well one must also argue the opposite. I myself have gained immense knowledge from YouTube. I have learned things like phone screen replacements or phone battery replacements. I call myself a mechanic from the school of YouTube and have saved myself at minimum $10k in repairs doing the work myself. I have learned to make endless food recipes or create things like giant bubbles or slime for my kids. My point is that I bet sure for some YouTube is a massive time sink waste of time. But I also wonder how much it has improved the knowledge, skills and ability of others.
My dad often mentions how had he had YouTube when he was younger how much it would have done for him. He talks about having to go to the library and if lucky there was a book that could show you the knowledge you were looking for. He says but now you can find not just the knowledge but for example specific knowledge like car make model and year and how exactly to do job xyz.
Ultimately I just can not imagine life without the wealth of knowledge YouTube has given me.
I watched a movie, same late night talk show host, something like "welcome night owls".
I "loved" the style but I haven't found any actual radio on the internet of that style or a podcast. Not sure about name of movie but I do remember it being in the last 10-15 years.
Yeah, this could end up as the actual root cause of The Great Oops that I've been raving about for years. And Google probably would be the right company to fuck it up in the worst way possible since Google Knows Best In All Situations.
I was thinking about the time some software influencer said that if you are afraid to deploy on Friday then there's something wrong with you. Eff that! Murphy's Law! (allen holub - https://x.com/allenholub/status/1637111242610610182)
There's at least five free ACME CAs, with failover it doesn't matter all that much if one of them falls over. If all of them fall over at once there's probably a more pressing issue like nuclear holocaust or alien invasion going on.
Oh I am more than happy to tell people how I took down entire Google Cloud 11 years ago. I mean, of course to the level of details Google is comfortable with to share externally :)
OCSP is deprecated and basically dead at this point. Some clients still use it but I don't think many (any?) have actually enforced OCSP for years since it was notoriously fickle anyways.
Interesting. If you go to youtube.com it's all messed up; missing all the videos in the listings. But if you follow a video embedded in another site to youtube, it'll show and play fine. It'll break if you try to browse away from it.
Isn't that the thing that a bunch of YouTube creators pitch inside their channels along with VPNs and supplements? I would never consider it because the ads rub me the wrong way. Or is it some alternative frontend for YouTube that happens to have a similar sounding name?
The CA outage is hitting a lot of services, but yeah, Heroku's been on a slow decline since the Salesforce acquisition. Free tier killed, pricing creep, stagnant innovation. Even when it's not their fault, you start wondering if it's worth the risk of being on a platform that feels like it's in maintenance mode.
bathtub365|13 days ago
> 17 Feb 2026 11:32 PST A rollout is going to prevent issuance from occurring. We will provide an estimate on when issuance will stop.
> 17 Feb 2026 12:14 PST Issuance is beginning to stop. A fix to resolve the issue will roll out in about 8 hours
agwa|13 days ago
zerocrates|13 days ago
"There is an ongoing incident that will force issuance to be halted."
Feels like they were alerted to some current problem severe enough that "turn it off now" was the right move. Breaking the baseline requirements somehow maybe?
kyledrake|13 days ago
codys|13 days ago
aaomidi|13 days ago
TwoNineFive|13 days ago
h4ch1|13 days ago
ddtaylor|13 days ago
ktaraszk|12 days ago
OhMeadhbh|13 days ago
But... hopefully... people created overlapping windows of cert validity so there's always a valid cert available for their services and can tolerate the CA being out of action for 8(?) hours. Imagine if your TGS/Kerberos or AWS IAM IdP was down for 8 hours.
antonvs|13 days ago
But that didn’t stop Youtube and Youtube TV from going down hard. I imagine they’re provisioning ephemeral VMs or service instances and relying on them being able to get certs immediately, or something like that.
TMEHpodcast|13 days ago
14|13 days ago
PostOnce|13 days ago
I don't want to buy tires, I want to learn about ______. The ads don't even make sense because they're irrelevant.
staticassertion|13 days ago
bdavbdav|13 days ago
2Gkashmiri|13 days ago
I "loved" the style but I haven't found any actual radio on the internet of that style or a podcast. Not sure about name of movie but I do remember it being in the last 10-15 years.
kidfiji|13 days ago
gzread|13 days ago
ekr____|13 days ago
dijit|13 days ago
dyauspitr|13 days ago
tokyobreakfast|13 days ago
[deleted]
sciencesama|13 days ago
nitinreddy88|13 days ago
unknown|12 days ago
[deleted]
rconti|13 days ago
issuance flow has been undrained?
aaomidi|13 days ago
dilyevsky|12 days ago
PLenz|13 days ago
edwaldojunior|13 days ago
pkulak|13 days ago
https://www.youtube.com/watch?v=cMx139eTxoc
jtokoph|13 days ago
oof
catsquirrel28|13 days ago
bawolff|13 days ago
altairprime|13 days ago
themafia|13 days ago
tokyobreakfast|13 days ago
bigbuppo|13 days ago
msie|13 days ago
jsheard|13 days ago
rvz|13 days ago
Looking forward to the post-mortem.
wbsun|13 days ago
LPisGood|13 days ago
Thaxll|13 days ago
Now I'm wondering if you rely on OCSP in a TLS client and the pki is Google does it still works?
arcfour|13 days ago
kbelder|13 days ago
aaronmiler|13 days ago
flaxxer|13 days ago
unknown|13 days ago
[deleted]
rolph|13 days ago
spyrja|13 days ago
chiengineer|13 days ago
RobRivera|13 days ago
arduanika|13 days ago
Kapura|13 days ago
benatkin|13 days ago
1970-01-01|13 days ago
Shellban|13 days ago
ONE MILLION DOLLARS!
lawgimenez|13 days ago
microm|13 days ago
philprx|12 days ago
manupati|13 days ago
ktaraszk|12 days ago