CA's currently maintain internal keyword warning systems that flag domain validated requests for manual intervention. Anything that even hints that it is involved with a major company, church, charity, bank or financial institution gets flagged and approved manually.
The SSL Co-operative: A Member-Controlled Certification Authority
21–30 of 90 posts
Re: The SSL Co-operative: A Member-Controlled Certification Authority
#22Earlier quoted context omitted.
Pretty much what I was thinking. Here's what I almost sent as a response to the survey: This is a brilliant idea. I would pay up to $50 a year for the pleasure of being able to get domain validated SSL certs that are trusted by the major browsers. I would assume that the validation would be via emailing webmaster@domain and making them either respond or click a link or something. That could all be automated couldn't…
Mozilla created https://publicsuffix.org/ - perhaps that could help with com.au vs. example.com.au?
Re: The SSL Co-operative: A Member-Controlled Certification Authority
#23Earlier quoted context omitted.
Well, one way to automatedly ensure someone controls all the subdomains a wildcard certificate gives would be to ask them to create dns records indicating that. Basically, the CA could say "you want *.example.com, then create a dns txt record at mzzafr2pr.example.com with the following text: F5cbUl7pL2JM7z and click here. We'll get back to you once we see the dns change propagate". If I can create a random subdomain…
This breaks for obvious cases such as mzzafr2pr.blogspot.com
Re: The SSL Co-operative: A Member-Controlled Certification Authority
#24Am I the only one that finds it hillarious (or troubling) that the SSL cert for this site is for a different host name?
Re: The SSL Co-operative: A Member-Controlled Certification Authority
#25Earlier quoted context omitted.
Well, one way to automatedly ensure someone controls all the subdomains a wildcard certificate gives would be to ask them to create dns records indicating that. Basically, the CA could say "you want *.example.com, then create a dns txt record at mzzafr2pr.example.com with the following text: F5cbUl7pL2JM7z and click here. We'll get back to you once we see the dns change propagate". If I can create a random subdomain…
This breaks for obvious cases such as mzzafr2pr.blogspot.com
Re: The SSL Co-operative: A Member-Controlled Certification Authority
#26I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…
There are not any significant costs to obtaining SSL certificates, so a new CA is hardly likely to change the SSL landscape at all.
Re: The SSL Co-operative: A Member-Controlled Certification Authority
#27I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…
[0] - https://getssl.me/
Re: The SSL Co-operative: A Member-Controlled Certification Authority
#28Earlier quoted context omitted.
Well, one way to automatedly ensure someone controls all the subdomains a wildcard certificate gives would be to ask them to create dns records indicating that. Basically, the CA could say "you want *.example.com, then create a dns txt record at mzzafr2pr.example.com with the following text: F5cbUl7pL2JM7z and click here. We'll get back to you once we see the dns change propagate". If I can create a random subdomain…
This breaks for obvious cases such as mzzafr2pr.blogspot.com
You do have a good point though. I'm sure there are some services right now that allow decent control of a chosen subdomain's dns, but don't mean for you to be able to create ssl certs valid for all other subdomains too. Perhaps there should be a blacklist of sites like "blogspot". Perhaps there should be a way for a domain to indicate that wildcard certs cannot be automatically created for it without passing other conditions.
Re: The SSL Co-operative: A Member-Controlled Certification Authority
#29Earlier quoted context omitted.
What about this post makes you think the NSA is or would be involved?
I think the question you should ask yourself is: how is the NSA involved in the currently established CA system? The answer (to your question) is , the very same way. Besides, who does think that having an alternative CA provider is going to change anything? The crypto empowering security nowadays is un-trusted, implementations proven containing backdoors, and on the top of that all the implementations are written in…
Re: The SSL Co-operative: A Member-Controlled Certification Authority
#30I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…
StartCom charges $60 for a wildcard certificate that will be accepted by just about every important browser out there. You might even be able to get them cheaper elsewhere. There are not any significant costs to obtaining SSL certificates, so a new CA is hardly likely to change the SSL landscape at all.