So I don't like Let's Encrypt, if Mozilla "kills" WoSign/StartCom, what are my options if I want a cert for free?
WoSign and StartCom: Mozilla’s proposed conclusion
51–60 of 252 posts
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#52Earlier quoted context omitted.
Not only is it a year without revenue... I imagine this will devastate their revenues in future years as existing customers up for renewal during that time will likely permanently migrate to another CA.
It looks like Mozilla and Google have created a set of circumstances where the rational next step would be to wind down WoSign/Startcom and just start a new company.
That's a multi-year process, unless they can get another CA to cross-sign their root, like LE did. I doubt other CAs will be willing to carry that level of risk given the reputation of WoSign/StartCom.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#53If the CA market were efficient this would lead to bankruptcy of this company since there's no reason to chose them over the many competitors and many reasons to distrust them. Though of course the market is not efficient. I keep wondering when the Communist Party of China is going to make its heavy handed presence felt in the CA world.
The SSL ecosystem relies on the trustworthiness of the certificate authorities. If one of them is compromised, the whole system is compromised, not just their customers. This cannot be solved by markets. Instead, it's heavily regulated.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#54So I don't like Let's Encrypt, if Mozilla "kills" WoSign/StartCom, what are my options if I want a cert for free?
What exactly don't you like about Let's Encrypt? Besides Let's Encrypt, your other option is paying for a cert from GoDaddy or something. My two cents: don't give business to Comodo, given their horrible track record of sleaziness ( https://en.wikipedia.org/wiki/Comodo_Group#Controversies ).
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#55So people, is there a comparable free product out there (don't say LetsEncrypt, they don't do S/MIME unless I'm mistaken)?
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#56Goddammit. I really liked StartCom for free S/MIME certificates and TLS certs that don't expire after a month. So people, is there a comparable free product out there (don't say LetsEncrypt, they don't do S/MIME unless I'm mistaken)?
You can still get free S/MIME certs from Comodo.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#57Goddammit. I really liked StartCom for free S/MIME certificates and TLS certs that don't expire after a month. So people, is there a comparable free product out there (don't say LetsEncrypt, they don't do S/MIME unless I'm mistaken)?
Why are you using S/MIME? You can still get free S/MIME certs from Comodo.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#58I'd be interested to know what the plans are from other vendors (Microsoft, Google, Apple, ...); can we expect them to follow Mozilla's lead in taking action against WoSign?
Mozilla's CA policy is the only major policy where almost all discussion is public (indeed, its policy requires a public commentary period), so its decision is the most visible by far. Given that the major list vendors already collaborate in the CAB forum, it's likely that MS and Apple will follow the Mozilla/Google lead here. The prior Diginotar and Comodo scenarios involved all the vendors operating in tandem.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#59So I don't like Let's Encrypt, if Mozilla "kills" WoSign/StartCom, what are my options if I want a cert for free?
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#60A 1 year suspension and continued trust of previously signed certificates? Sounds very generous to me.
Given WoSign's history of backdating SHA-1 certificates in violation of Mozilla's rules, I wouldn't be too surprised if they reuse that practice to get around the 1 year ban, at which point Mozilla will have to consider permanently distrusting them.
> WoSign/StartCom could back-date certificates to get around this restriction. [...] if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots.