Live data from Hacker News

Ask HN: What's the best company to buy an SSL certificate from?

news.ycombinator.com

81–89 of 89 posts

Re: Ask HN: What's the best company to buy an SSL certificate from?

#81

Earlier quoted context omitted.

Could you explain more about obtaining it under someone else's name? There are many checks in place to prevent this.

> Could you explain more about obtaining it under someone else's name? There are many checks in place to prevent this. Here's what I know, which is not conclusive but possibly persuasive, and as I say below, I've never seen someone call the checks effective: 1) In my experience obtaining regular certs, the identity verification looked ineffective (though I wasn't trying to fool anyone). 2) Regarding both EV and regul…

Organizationally validated certificates do not require a lot of paperwork or manual validation. The effectiveness of the verification is still a topic for discussion. However the last point is dubious at best, as CAs make >$30-40 per certificate and validation takes max 30 minutes spread out over a day or two (typically).

I will say there are very few maliciously issued EV certificates.

Re: Ask HN: What's the best company to buy an SSL certificate from?

#83
post #82

Earlier quoted context omitted.

Gandi looks good, especially if one already use them for DNS. We intend to start using them for SSL.

Same here. Gandi is an interesting solution.

Curious: What do you mean by interesting?

Re: Ask HN: What's the best company to buy an SSL certificate from?

#84

Earlier quoted context omitted.

> Could you explain more about obtaining it under someone else's name? There are many checks in place to prevent this. Here's what I know, which is not conclusive but possibly persuasive, and as I say below, I've never seen someone call the checks effective: 1) In my experience obtaining regular certs, the identity verification looked ineffective (though I wasn't trying to fool anyone). 2) Regarding both EV and regul…

Organizationally validated certificates do not require a lot of paperwork or manual validation. The effectiveness of the verification is still a topic for discussion. However the last point is dubious at best, as CAs make >$30-40 per certificate and validation takes max 30 minutes spread out over a day or two (typically). I will say there are very few maliciously issued EV certificates.

Thanks for responding. I get the sense that you have some expertise in this field? As I said above, I don't, so if you do please forgive any ignorance on my part:

> CAs make >$30-40 per certificate and validation takes max 30 minutes spread out over a day or two (typically).

$30-40 isn't much, and 30 minutes doesn't seem nearly sufficient to reliably verify someone's identity.

> I will say there are very few maliciously issued EV certificates.

How do we know? And is there a lower fraud rate for EV certs than for standard certs? (Probably there is little fraud in any set of business transactions -- otherwise nobody would participate -- but I don't think that's what you mean.)

Re: Ask HN: What's the best company to buy an SSL certificate from?

#85

My startup is actually centered around this. If anyone wants to purchase a certificate through me, I'll happily give you the lowest rates I can. ($25 EV or $40 wildcard) Our homepage is https://certly.io , shoot me an email at ian@certly.io

I might be interested - is your root cert in all common browsers/OSs?

Re: Ask HN: What's the best company to buy an SSL certificate from?

#87
post #16
post #5

1. In terms of pricing, https://www.gogetssl.com seems good. I haven't used it personally, but $27.85 for an EV in the first year seems quite nice. Namecheap is good, too, but a bit more expensive. 2. Yes

Where do you see an option for an EV at $27.85 on that site? I'm seeing prices that start at $110 a year for 2 years. https://www.gogetssl.com/extended-validation/

https://www.gogetssl.com/business-validation/comodo-instants...

Re: Ask HN: What's the best company to buy an SSL certificate from?

#88

My startup is actually centered around this. If anyone wants to purchase a certificate through me, I'll happily give you the lowest rates I can. ($25 EV or $40 wildcard) Our homepage is https://certly.io , shoot me an email at ian@certly.io

I might be interested - is your root cert in all common browsers/OSs?

We don't have a root certificate (yet), but our partners are.

Re: Ask HN: What's the best company to buy an SSL certificate from?

#89

Earlier quoted context omitted.

Organizationally validated certificates do not require a lot of paperwork or manual validation. The effectiveness of the verification is still a topic for discussion. However the last point is dubious at best, as CAs make >$30-40 per certificate and validation takes max 30 minutes spread out over a day or two (typically). I will say there are very few maliciously issued EV certificates.

Thanks for responding. I get the sense that you have some expertise in this field? As I said above, I don't, so if you do please forgive any ignorance on my part: > CAs make >$30-40 per certificate and validation takes max 30 minutes spread out over a day or two (typically). $30-40 isn't much, and 30 minutes doesn't seem nearly sufficient to reliably verify someone's identity. > I will say there are very few maliciou…

Sorry for the late reply:

> 30 minutes doesn't seem nearly sufficient to reliably verify someone's identity.

It's actually not that long of a process once you read over the CPS's of a few CAs and the EV baseline.

> How do we know? Ah, the golden question! Hopefully CT (certificate transparency) will sort this out within the next 3 years. My statement is an assumption but any high level fraud (e.g. Google/MSFT) is caught immediately (chrome pinning/reporting and internal CA logs, if you're not DigiNotar). I don't know about small companies though.

I don't think there's ever been a maliciously issued EV cert in the context of the ComodoHacker and other very public hacks. They typically have tighter internal controls, that I know (e.g. RAs have very limited EV issuance power) but I have no numbers. :(

You should note that EV implies DV validation, so to, without hacking, maliciously issue a certificate an attacker would probably settle for a DV cert.

Post reply on HN