Earlier quoted context omitted.
Ah, but to use the Full SSL options you need an SSL on your origin server (which CloudFlare doesn't provide for free)!
That certificate can be self signed.
Let's Encrypt is Trusted
141–150 of 318 posts
Re: Let's Encrypt is Trusted
#142Earlier quoted context omitted.
Ah, but to use the Full SSL options you need an SSL on your origin server (which CloudFlare doesn't provide for free)!
That certificate can be self signed.
Re: Let's Encrypt is Trusted
#143Earlier quoted context omitted.
StartSSL is the opposite of user friendly.
Here's a cert! Hopefully you still have it around somewhere when you try to renew in a year!
Re: Let's Encrypt is Trusted
#144Earlier quoted context omitted.
I'm not sure what you're getting at. Care to elaborate?
New wannabe CA Entity B can approach an established CA entity A, convince A to sign B's root or intermediate cert, and then B can forge browser-trusted certs for every SSL website on the net that's not pinned. In this case, B is LetsEncrypt and is (hopefully) pretty solid, but that isn't always the case. Earlier this year, it became known that CNNIC had issued a CA cert to MCS Holdings (of Egypt), which then did bad…
Trusting a CA means trusting them to write certs, even via an intermediary. If you don't actually trust them, remove those CAs.
The CA model has lots of problems, but I don't see what additional harm this actually causes.
Re: Let's Encrypt is Trusted
#145Being told that you now trust someone with your secrets via a news website is a pleasingly succinct display of everything that's wrong with the CA model.
I'm not sure what you're getting at. Care to elaborate?
Re: Let's Encrypt is Trusted
#146Earlier quoted context omitted.
They are not quite the same thing: * CloudFlare doesn't give you a certificate. It terminates your TLS connection at their endpoint with a certificate they own the private key to. * StartSSL free tier is for non-commerical use only. * Haven't used WoSign so no idea what it is, but clicking on the link took was so laggy it didn't give me much confidence. (I personally wouldn't work with a company in China jurisdiction…
> user-friendly This is the key. StartSSL is NOT user-friendly at all, even if you want to use it for the non-commercial personal use that it was designed for.
Although i agree that their user interface isn't that much user friendly, it took me just a couple of hours to learn how the process is handled at StartSSL.
You let them create a certificate you then use for your login process. Then you validate your domain by email and then you're pretty much valid to pump out as much certificates as you want.
Only drawback is that the certificates are only valid for one year.
Re: Let's Encrypt is Trusted
#147Earlier quoted context omitted.
I'm not sure what you're getting at. Care to elaborate?
Probably just that we're being told who to trust, instead of deciding who to trust.
Re: Let's Encrypt is Trusted
#148From a comment on a similar reddit-thread[1]: > So thus beings the transition. EV certs are going to be the only ones that get the "green" chrome in browsers anymore. Sites using standard SSL are going to get the normal no-lock/white treatment. And sites without SSL will get the caution symbol/yellow treatment. I don't like it, but I suspect this is where we're heading. [1] https://www.reddit.com/r/linux/comments/3pg…
Are there any facts to back up this claim?
Edit: This is what HN looks like in Firefox 38.0.5: http://img4.imagetitan.com/img4/RsbN6Rsn61k2IMN/12/12_l.png
Sure, the background color is white, but there's still a padlock icon.
Re: Let's Encrypt is Trusted
#149Earlier quoted context omitted.
> user-friendly This is the key. StartSSL is NOT user-friendly at all, even if you want to use it for the non-commercial personal use that it was designed for.
I'm quite pleased with StartSSL. Although i agree that their user interface isn't that much user friendly, it took me just a couple of hours to learn how the process is handled at StartSSL. You let them create a certificate you then use for your login process. Then you validate your domain by email and then you're pretty much valid to pump out as much certificates as you want. Only drawback is that the certificates a…