Live data from Hacker News

Ask HN: What's the best company to buy an SSL certificate from?

news.ycombinator.com

21–30 of 89 posts

Re: Ask HN: What's the best company to buy an SSL certificate from?

#21

1. DigiCert. They're not the cheapest, but they really have their stuff together. Their support is awesome (speedy, technically competent, and human). They're also proactive about identifying issues with your certs, they handled the heartbleed incident perfectly - reissued for free with no issues. 2. No

Wow, one needs a super premium $595 "Wildcard Plus™" plan to secure an entire domain. Is this normal or a blatant ripoff?

Re: Ask HN: What's the best company to buy an SSL certificate from?

#22
post #18

My startup is actually centered around this. If anyone wants to purchase a certificate through me, I'll happily give you the lowest rates I can. ($25 EV or $40 wildcard) Our homepage is https://certly.io , shoot me an email at ian@certly.io

What does your startup do? How are you able to offer EV certificates so cheaply? I thought they were typically ~$1000.

Haha, you must be thinking of Symantec (we have an account with them and they don't give us good rates).

They retail at $300 typically but resellers pay dirt for them.

Our goal is to improve the way you buy your SSL/code signing/SMIME certificates. We have agreements with every large authority to give the buyer the best price for each product. We hope to take on VC funding to build our own root authority.

Re: Ask HN: What's the best company to buy an SSL certificate from?

#23
startssl.com gives out free certs to individuals. This is great for personal projects, blogs, etc. Otherwise I use Namecheap and their $9 certs. I have not found a great wildcard cert provider yet (why all certs are not wildcard by default is beyond me).

Re: Ask HN: What's the best company to buy an SSL certificate from?

#24
post #11

Pick one that can deliver the full certificate chain without using SHA-1. The faster the web moves away from SHA-1 the better, and rewarding companies that are already abstaining from SHA-1 contributes to our collective security, in the case of HTTPS. You should also do it for purely selfish reasons. Chrome is sunsetting SHA-1 for use in certificate signatures, and Chrome will eventually show SHA-1 certificates as in…

You should also do it for purely selfish reasons. Chrome is sunsetting SHA-1 for use in certificate signatures, and Chrome will eventually show SHA-1 certificates as insecure. Referring specifically to this point, and not to your wider point about moving away from SHA-1, "because one browser maker said so" is rarely a good reason to do anything. Google has an irritating habit of deciding it knows best for the entire…

Correction: two browser vendors who between them have more than half of the browser share. And the solid technical argument is that SHA-1 is no longer considered secure.

Re: Ask HN: What's the best company to buy an SSL certificate from?

#25

Th problem with EV (green bar) certs is the Browser usually ends up checking the certificate status via CRL or OCSP (URI is specified in the cert), which can add an additional .5 to 10+ seconds before the page is displayed. More so when the CA servers are down or the connection times out. So if you do go for an EV cert, go for the one that has the best listed uptime on it's CRL or OCSP servers. Having said that, I wo…

I accidentally let our EV cert expire a few years ago and ordered $10 domain verified Comodo Cert to tide us over. Hilariously we saw absolutely 0 change in order metrics. I didn't renew the EV cert. EV certs are a neat idea but the average consumer doesn't understand/know about them.

Re: Ask HN: What's the best company to buy an SSL certificate from?

#26

Th problem with EV (green bar) certs is the Browser usually ends up checking the certificate status via CRL or OCSP (URI is specified in the cert), which can add an additional .5 to 10+ seconds before the page is displayed. More so when the CA servers are down or the connection times out. So if you do go for an EV cert, go for the one that has the best listed uptime on it's CRL or OCSP servers. Having said that, I wo…

You get OCSP checking for non-EV certificates too in many browsers. However, you can remove any additional delay by using OCSP stapling.

Re: Ask HN: What's the best company to buy an SSL certificate from?

#27
post #18

Earlier quoted context omitted.

What does your startup do? How are you able to offer EV certificates so cheaply? I thought they were typically ~$1000.

Haha, you must be thinking of Symantec (we have an account with them and they don't give us good rates). They retail at $300 typically but resellers pay dirt for them. Our goal is to improve the way you buy your SSL/code signing/SMIME certificates. We have agreements with every large authority to give the buyer the best price for each product. We hope to take on VC funding to build our own root authority.

Want to expand you business exponentially? Build a WHMCS plugin/API module that lets webhosts do a 1 click cert gen/purchase. I'd be /really/ happy to work with you on this.

Re: Ask HN: What's the best company to buy an SSL certificate from?

#28
post #21

1. DigiCert. They're not the cheapest, but they really have their stuff together. Their support is awesome (speedy, technically competent, and human). They're also proactive about identifying issues with your certs, they handled the heartbleed incident perfectly - reissued for free with no issues. 2. No

Wow, one needs a super premium $595 "Wildcard Plus™" plan to secure an entire domain. Is this normal or a blatant ripoff?

Honestly? If you have the cash, DigiCert will probably be worth every penny.

One great feature is the unlimited SAN feature with the wildcards. You can secure multiple levels for free, amazing support, fast validation, etc.

They are on the high end with Symantec though, price wise.

Disclaimer: DigiCert affiliate

Re: Ask HN: What's the best company to buy an SSL certificate from?

#29

Earlier quoted context omitted.

Haha, you must be thinking of Symantec (we have an account with them and they don't give us good rates). They retail at $300 typically but resellers pay dirt for them. Our goal is to improve the way you buy your SSL/code signing/SMIME certificates. We have agreements with every large authority to give the buyer the best price for each product. We hope to take on VC funding to build our own root authority.

Want to expand you business exponentially? Build a WHMCS plugin/API module that lets webhosts do a 1 click cert gen/purchase. I'd be /really/ happy to work with you on this.

These modules actually already exist, I just think the companies offering them are bad at advertising.

I'm open to working with others, shoot me an email @ ian@certly.io

Post reply on HN