Live data from Hacker News

The SSL Co-operative: A Member-Controlled Certification Authority

sslcoop.org

11–20 of 90 posts

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#12

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

Pretty much what I was thinking. Here's what I almost sent as a response to the survey: This is a brilliant idea. I would pay up to $50 a year for the pleasure of being able to get domain validated SSL certs that are trusted by the major browsers. I would assume that the validation would be via emailing webmaster@domain and making them either respond or click a link or something. That could all be automated couldn't…

Mozilla created https://publicsuffix.org/ - perhaps that could help with com.au vs. example.com.au?

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#15
post #7
post #4

Earlier quoted context omitted.

That sounds very much like the service that is already offered by StartSSL.com. You pay for identity validation, but you can then create as many regular and wildcard certificates as you wish. It's a superb service.

it's a superb service, until you want a revocation, then they try to extort $25/revocation out of you (even if you've been a long term paying customer) this may be OK if you have only issued one cert, but if you've issued a few hundred (which is the main point of StartSSL: pay once and issue many), then you are SOL unless you can afford to plonk down thousands of dollars. more here: https://www.techdirt.com/articles/…

To be fair, it seems like they have a point that revocation is actually expensive for them.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#16
post #4

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

That sounds very much like the service that is already offered by StartSSL.com. You pay for identity validation, but you can then create as many regular and wildcard certificates as you wish. It's a superb service.

I use and like StartCom certificates, but they wouldn't solve this problem. Wildcard certificates should not require identity validation; you should be able to get a domain-validated wildcard certificate for free.

Also, their free certificates expire every year; domain-validated certificates should only require revalidation if the domain changes hands.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#17
post #13

NSA, is that you? :) (Thanks for the downvotes in advance)

What about this post makes you think the NSA is or would be involved?

I think the question you should ask yourself is: how is the NSA involved in the currently established CA system? The answer (to your question) is , the very same way. Besides, who does think that having an alternative CA provider is going to change anything? The crypto empowering security nowadays is un-trusted, implementations proven containing backdoors, and on the top of that all the implementations are written in languages that can't be formally verified and there are serious security bugs every other week. Back to the topic, what is this new CA group addressing? Which part of this chain that going to be fixed by any mean with this initiative? I guess the answer is none. :)

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#18

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

Pretty much what I was thinking. Here's what I almost sent as a response to the survey: This is a brilliant idea. I would pay up to $50 a year for the pleasure of being able to get domain validated SSL certs that are trusted by the major browsers. I would assume that the validation would be via emailing webmaster@domain and making them either respond or click a link or something. That could all be automated couldn't…

Well, one way to automatedly ensure someone controls all the subdomains a wildcard certificate gives would be to ask them to create dns records indicating that. Basically, the CA could say "you want *.example.com, then create a dns txt record at mzzafr2pr.example.com with the following text: F5cbUl7pL2JM7z and click here. We'll get back to you once we see the dns change propagate". If I can create a random subdomain they suggest within a wildcard range, that makes it almost certain I can create every subdomain.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#19
post #18

Earlier quoted context omitted.

Pretty much what I was thinking. Here's what I almost sent as a response to the survey: This is a brilliant idea. I would pay up to $50 a year for the pleasure of being able to get domain validated SSL certs that are trusted by the major browsers. I would assume that the validation would be via emailing webmaster@domain and making them either respond or click a link or something. That could all be automated couldn't…

Well, one way to automatedly ensure someone controls all the subdomains a wildcard certificate gives would be to ask them to create dns records indicating that. Basically, the CA could say "you want *.example.com, then create a dns txt record at mzzafr2pr.example.com with the following text: F5cbUl7pL2JM7z and click here. We'll get back to you once we see the dns change propagate". If I can create a random subdomain…

This breaks for obvious cases such as mzzafr2pr.blogspot.com

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#20

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

Pretty much what I was thinking. Here's what I almost sent as a response to the survey: This is a brilliant idea. I would pay up to $50 a year for the pleasure of being able to get domain validated SSL certs that are trusted by the major browsers. I would assume that the validation would be via emailing webmaster@domain and making them either respond or click a link or something. That could all be automated couldn't…

The same issue appears when deciding allowance of cookie share-ability across subdomains.

The solution is called a public suffix list - more information about it is available at https://wiki.mozilla.org/Public_Suffix_List .

Post reply on HN