Live data from Hacker News

Termination of StartCom business

startcomca.com

11–20 of 47 posts

Re: Termination of StartCom business

#11
post #7
post #2

Apparently, they also sent out an e-mail with the same text to their customers, with an addendum that they are going to try to get a certificate for each customer with other CAs, and that to opt-out, one has to send them an e-mail. I found that addendum quite strange. Such thing should be opt-in, in my opinion.

Maybe you get a shiny new Turk Trust cert in exchange. Who knows.

I have no idea if 'Turk Trust' is even a real CA or if you made up the name in jest. I'm honestly scared to Google it and find out, in slight fear of finding out that is an actual CA. (Not to get too political here, but given Turkey's current government, I'm not sure how anyone in their right mind would 1- trust them to say or do _anything_, and 2- trust SSL encryption certs coming out of there)

Re: Termination of StartCom business

#13
post #11
post #7

Earlier quoted context omitted.

Maybe you get a shiny new Turk Trust cert in exchange. Who knows.

I have no idea if 'Turk Trust' is even a real CA or if you made up the name in jest. I'm honestly scared to Google it and find out, in slight fear of finding out that is an actual CA. (Not to get too political here, but given Turkey's current government, I'm not sure how anyone in their right mind would 1- trust them to say or do _anything_, and 2- trust SSL encryption certs coming out of there)

At least it's not Honest Achmed's Used Cars and Certificates ;)

https://bugzilla.mozilla.org/show_bug.cgi?id=647959

Re: Termination of StartCom business

#14
post #2

Apparently, they also sent out an e-mail with the same text to their customers, with an addendum that they are going to try to get a certificate for each customer with other CAs, and that to opt-out, one has to send them an e-mail. I found that addendum quite strange. Such thing should be opt-in, in my opinion.

Thank you very much for pointing out about the opt-out crap. I also got the email but I didn’t bother to read past the first paragraph because I stopped using them as soon as I switched to cloudlfare for my certificates.

I always hated their interface but as a broke high school student I couldn’t afford to have a paid certificate. Thankfully we have Let’s Encrypt now

Re: Termination of StartCom business

#16
post #2

Apparently, they also sent out an e-mail with the same text to their customers, with an addendum that they are going to try to get a certificate for each customer with other CAs, and that to opt-out, one has to send them an e-mail. I found that addendum quite strange. Such thing should be opt-in, in my opinion.

I got the email. Here is the full text:

This is an automatically generated email, please do not reply.

Dear customer,

As you are surely aware, the browser makers distrusted StartCom around a year ago and therefore all the end entity certificates newly issued by StartCom are not trusted by default in browsers.

The browsers imposed some conditions in order for the certificates to be re-accepted. While StartCom believes that these conditions have been met, it appears there are still certain difficulties forthcoming. Considering this situation, the owners of StartCom have decided to terminate the company as a Certification Authority as mentioned in Startcom´s website.

StartCom will stop issuing new certificates starting from January 1st, 2018 and will provide only CRL and OCSP services for two more years.

StartCom would like to thank you for your support during this difficult time.

StartCom is contacting some other CAs to provide you with the certificates needed. In case you don´t want us to provide you an alternative, please, contact us at certmaster@startcomca.com

Please let us know if you need any further assistance with the transition process. We deeply apologize for any inconveniences that this may cause.

Best regards,

StartCom Certification Authority

Re: Termination of StartCom business

#18
post #13
post #11

Earlier quoted context omitted.

I have no idea if 'Turk Trust' is even a real CA or if you made up the name in jest. I'm honestly scared to Google it and find out, in slight fear of finding out that is an actual CA. (Not to get too political here, but given Turkey's current government, I'm not sure how anyone in their right mind would 1- trust them to say or do _anything_, and 2- trust SSL encryption certs coming out of there)

At least it's not Honest Achmed's Used Cars and Certificates ;) https://bugzilla.mozilla.org/show_bug.cgi?id=647959

Interestingly:

> Eddy Nigg (StartCom)

> Comment 11 • 7 years ago

> According to http://www.mozilla.org/projects/security/certs/policy/ and https://wiki.mozilla.org/CA:Information_checklist apparently fails to comply to the audit requirements amongst other things at the moment. Should a valid audit statement be published and confirmed by an authorized auditor, I guess Mozilla could consider a discussion to include this CA.

Re: Termination of StartCom business

#19
post #16
post #2

Apparently, they also sent out an e-mail with the same text to their customers, with an addendum that they are going to try to get a certificate for each customer with other CAs, and that to opt-out, one has to send them an e-mail. I found that addendum quite strange. Such thing should be opt-in, in my opinion.

I got the email. Here is the full text: This is an automatically generated email, please do not reply. Dear customer, As you are surely aware, the browser makers distrusted StartCom around a year ago and therefore all the end entity certificates newly issued by StartCom are not trusted by default in browsers. The browsers imposed some conditions in order for the certificates to be re-accepted. While StartCom believes…

Amusing that they couldn't get the encoding correct on their final email either.

Re: Termination of StartCom business

#20
post #13
post #11

Earlier quoted context omitted.

I have no idea if 'Turk Trust' is even a real CA or if you made up the name in jest. I'm honestly scared to Google it and find out, in slight fear of finding out that is an actual CA. (Not to get too political here, but given Turkey's current government, I'm not sure how anyone in their right mind would 1- trust them to say or do _anything_, and 2- trust SSL encryption certs coming out of there)

At least it's not Honest Achmed's Used Cars and Certificates ;) https://bugzilla.mozilla.org/show_bug.cgi?id=647959

LMAO
Post reply on HN