Live data from Hacker News

Ask HN: Looking for someone to help create a trusted CA

news.ycombinator.com

21–30 of 43 posts

Re: Ask HN: Looking for someone to help create a trusted CA

#21
post #14

Shitpost: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 Running a CA is not easy, and getting your root certificates included in trusted roots is even harder. For the technical aspects of it, you will need an HSM for the root certificates generated, OCSP servers, a CRL mechanism, and the signing server. Many enterprises already run their own private CA, and there are plenty of free and open source software. The…

> LetsEncrypt is free and issues certificates to everyone

When using free providers, you will notice that the issued to -> organization field will be empty. Free providers do not compete with company validating trust authorities. They are just developer tools.

Re: Ask HN: Looking for someone to help create a trusted CA

#22
post #14

Shitpost: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 Running a CA is not easy, and getting your root certificates included in trusted roots is even harder. For the technical aspects of it, you will need an HSM for the root certificates generated, OCSP servers, a CRL mechanism, and the signing server. Many enterprises already run their own private CA, and there are plenty of free and open source software. The…

> LetsEncrypt is free and issues certificates to everyone When using free providers, you will notice that the issued to -> organization field will be empty. Free providers do not compete with company validating trust authorities. They are just developer tools.

You might notice that, but very few other people do.

Re: Ask HN: Looking for someone to help create a trusted CA

#23
post #14

Shitpost: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 Running a CA is not easy, and getting your root certificates included in trusted roots is even harder. For the technical aspects of it, you will need an HSM for the root certificates generated, OCSP servers, a CRL mechanism, and the signing server. Many enterprises already run their own private CA, and there are plenty of free and open source software. The…

> LetsEncrypt is free and issues certificates to everyone When using free providers, you will notice that the issued to -> organization field will be empty. Free providers do not compete with company validating trust authorities. They are just developer tools.

What nonsense. Extended validation schemes are snake oil peddled by CAs to make more money.

Re: Ask HN: Looking for someone to help create a trusted CA

#24

Earlier quoted context omitted.

> LetsEncrypt is free and issues certificates to everyone When using free providers, you will notice that the issued to -> organization field will be empty. Free providers do not compete with company validating trust authorities. They are just developer tools.

What nonsense. Extended validation schemes are snake oil peddled by CAs to make more money.

It is all nonsense until money is involved and customers want to know that the advertised website actually belongs to your legal entity.

Re: Ask HN: Looking for someone to help create a trusted CA

#25
post #6

Two things: 1) You have no contact info in your profile. 2) As throwaway pointed out, this is an expensive task to undertake and, at least based on your post, it's not clear what you hope to gain from building another CA that's sufficiently trustworthy to be accepted into the Web PKI root stores. Beyond free certs (Let's Encrypt), your needs might also be satisfied by something like Digicert's Dedicated Intermediate…

Thanks for the DigiCert link. Are there other CAs that offer the same service that you know of? As DigiCert is very very very expensive as they target the top end enterprise.

You haven't told us why you want to be a CA?

What is it that you want to do, that you think you can do as a CA, but not as a customer/reseller of a CA?

In my experience as a CA customer, DigiCert is certainly expensive, but with that expense comes quite a bit of flexibility. Flexibility that might be able to meet your needs. Anyway, I would be amazed if the sub CA from Digicert program is more expensive than running a full blown CA, including the time and effort to get the CA into trust stores.

Plus, you're going to need to get a CA to sign your root / your intermediates while you wait for all the trust stores your customers care about to get updated; and by get updated, I really mean for your customers' customers to throw away their old devices. Your average Android device gets zero software updates, and lasts up to 7 years in your customers' customers hands, and who knows how many years behind upstream the manufacturer was when they built the thing.

Re: Ask HN: Looking for someone to help create a trusted CA

#26
post #14

Shitpost: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 Running a CA is not easy, and getting your root certificates included in trusted roots is even harder. For the technical aspects of it, you will need an HSM for the root certificates generated, OCSP servers, a CRL mechanism, and the signing server. Many enterprises already run their own private CA, and there are plenty of free and open source software. The…

> LetsEncrypt is free and issues certificates to everyone When using free providers, you will notice that the issued to -> organization field will be empty. Free providers do not compete with company validating trust authorities. They are just developer tools.

No one, other than us, cares about that.

Re: Ask HN: Looking for someone to help create a trusted CA

#27
post #14

Shitpost: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 Running a CA is not easy, and getting your root certificates included in trusted roots is even harder. For the technical aspects of it, you will need an HSM for the root certificates generated, OCSP servers, a CRL mechanism, and the signing server. Many enterprises already run their own private CA, and there are plenty of free and open source software. The…

> Shitpost: https://bugzilla.mozilla.org/show_bug.cgi?id=647959

> The purpose of this certificate is to allow Honest Achmed to sell bucketloads of other certificates and make a lot of money.

Well, they're more honest than any current certificate authority.

Re: Ask HN: Looking for someone to help create a trusted CA

#28
post #14

Shitpost: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 Running a CA is not easy, and getting your root certificates included in trusted roots is even harder. For the technical aspects of it, you will need an HSM for the root certificates generated, OCSP servers, a CRL mechanism, and the signing server. Many enterprises already run their own private CA, and there are plenty of free and open source software. The…

> LetsEncrypt is free and issues certificates to everyone When using free providers, you will notice that the issued to -> organization field will be empty. Free providers do not compete with company validating trust authorities. They are just developer tools.

> They are just developer tools

A CA is a CA. A developer tool would be you signing certificates with your own private CA. LetsEncrypt is often better as they support must-staple, CT timestamps in certificates themselves, and ECDSA leaf certificates support.

The snakeoil pitch would have worked 3-4 years back when browsers shows a big yellow label in address bar, but as of now, they all look the same regardless if its a DV, OV, or EV certificate unless you click your way through the certificate information.

Re: Ask HN: Looking for someone to help create a trusted CA

#29
post #12

Start by being a reseller. https://www.namecheap.com/resellers/ssl-certificates/how-it-...

Not exactly what I asked or what is wanted sorry. Plus namecheap are terrible as a reseller

Being a reseller puts you in the path to being a trusted CA.

Re: Ask HN: Looking for someone to help create a trusted CA

#30

Earlier quoted context omitted.

What nonsense. Extended validation schemes are snake oil peddled by CAs to make more money.

It is all nonsense until money is involved and customers want to know that the advertised website actually belongs to your legal entity.

Does not help in any real way. See https://arstechnica.com/information-technology/2017/12/nope-... for an example.
Post reply on HN