Live data from Hacker News

Ask HN: Looking for someone to help create a trusted CA

news.ycombinator.com

1–10 of 43 posts

Ask HN: Looking for someone to help create a trusted CA

#1
Hello, This may be a long shot. but no harm in asking right? Does anyone have any experience in create a trusted certificate authority. Creating all the need Infrastructure, guidelines and submissions to get the root certificate included in all major browsers, OSs, devices etc.. And would they be interested in a new project. If so please message me.

Re: Ask HN: Looking for someone to help create a trusted CA

#2
What's your plan? Creating something in the style of Let's Encrypt (all free, all open source) or in the style of Comodo/Verisign/etc. (Paid, closed source)?

You might start using software like PrimeKey Ejbca (Enterprise Edition), Microsoft Server 2019 with Certification Authority or some wrappers around openssl that are available online.

Re: Ask HN: Looking for someone to help create a trusted CA

#5
The technology side is super easy if you know what you are doing. Getting your cert into the browsers is the problem. It's a political / sales & marketing type of problem. Why should they? You need a pretty convincing answer. Because it's pretty hard to motivate Google or Microsoft with the offer of a cash payment. It depends on what you mean but getting a cert into OSs / devices should be a lot easier.

Re: Ask HN: Looking for someone to help create a trusted CA

#6
Two things:

1) You have no contact info in your profile.

2) As throwaway pointed out, this is an expensive task to undertake and, at least based on your post, it's not clear what you hope to gain from building another CA that's sufficiently trustworthy to be accepted into the Web PKI root stores. Beyond free certs (Let's Encrypt), your needs might also be satisfied by something like Digicert's Dedicated Intermediate program [1] where they will build and manage a "sub-CA" (subordinate CA) for you that chains up to their widely trusted roots. This allows you to control certificates issued under that sub-CA (as long your requests also fall within the baseline requirements) but saves you from the management and compliance overhead of a truly new CA.

[1] https://www.digicert.com/dedicated-intermediate/

Re: Ask HN: Looking for someone to help create a trusted CA

#8
You'll probably want to read the Mozilla Root Store Policy [0], if you haven't already.

Oh, and be prepared to spend tens or hundreds of thousands of dollars over the next few years while this process plays out and your CA certificate actually gets added to the root store in the various browsers.

---

[0]: https://www.mozilla.org/en-US/about/governance/policies/secu...

Re: Ask HN: Looking for someone to help create a trusted CA

#9
post #6

Two things: 1) You have no contact info in your profile. 2) As throwaway pointed out, this is an expensive task to undertake and, at least based on your post, it's not clear what you hope to gain from building another CA that's sufficiently trustworthy to be accepted into the Web PKI root stores. Beyond free certs (Let's Encrypt), your needs might also be satisfied by something like Digicert's Dedicated Intermediate…

Thanks for the DigiCert link. Are there other CAs that offer the same service that you know of? As DigiCert is very very very expensive as they target the top end enterprise.
Post reply on HN