Earlier quoted context omitted.
I wonder what Google will do with their Cloud Platform Google-managed SSL certificates that have used Let's Encrypt so far... But I guess in the worst case I can just buy traditional certificates for a couple of years.
You can literally exchange the certificates manually in the chain delivered by your webserver using a text editor.
Let’s Encrypt to transition to ISRG root
111–114 of 114 posts
Re: Let’s Encrypt to transition to ISRG root
#112So what motivates one CA to cross-sign another? I would have thought, if you were a CA you'd prefer not to enable your competitors - especially one who's planning to give away the product for free.
IdenTrust has OV, EV, managed PKI, and even DV certificates with 2 year validity that some legacy organization infrastructure requires.
Re: Let’s Encrypt to transition to ISRG root
#113Earlier quoted context omitted.
Something like Ubuntu sounds like a great fit then.
Modern ubuntu is getting pretty heavyweight. Gone are the days it'll run on any old laptop.
I found Linux Lite, based on Ubuntu 18.04 LTS:
Re: Let’s Encrypt to transition to ISRG root
#114Earlier quoted context omitted.
It's worth noting here, too, that the vast majority of commercial CAs do not make a lot of money from their public SSL business. The public SSL business is viewed as a loss leader that provides a public profile and security assurance for the company, but most of them make far more money from their private PKI engagements (providing all of the certificates for a company's Active Directory infrastructure, e.g.). As suc…
There's no way that a multi-thousand dollar EV wildcard cert is a "loss leader".
(DigiNotar, of course, famously gave out a fraudulent * .google.com cert and is now defunct.)
As a CA you're assuming a whole lot of liability for not that much money (not that much at the scale of even a small business, anyway), and that just doesn't seem like it'd scale to a wildly profitable venture, especially considering the kinds of people who are actually well equipped to run a CA can probably make a lot more money doing basically anything else in web security. When you add up the contingency risks, the opportunity costs, and whatever actual day-to-day business expenses, it does seem like you'd be looking for other ways to make more comfortable profits.
That doesn't mean CAs should charge more or anything, just that I could accept that SSL certs for standard websites isn't what anyone with a good vision for their business is really trying to hold onto.