Live data from Hacker News

Don't submit to the SSL cert racket. You can get one for no charge

startssl.com

31–40 of 88 posts

Re: Don't submit to the SSL cert racket. You can get one for no charge

#31

I've used StartSSL in the past. I will never do so again. Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.

I find their service excellent. The website doesn't have the latest hip look, but the service is solid, and they are very responsive and helpful in case you run into an issue. For a free service, that's impressive.

their support is excellent too, I've had Eddy Nigg (the founder) respond to emails within 10 minutes on several occasions.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#32

I've used StartSSL in the past. I will never do so again. Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.

This hasn't been my experience. Their web site is ugly and lame but once you're logged in it's about a 3-step process to apply for the cert. Both times I was emailed within 10 minutes that my cert was ready, and it works fine.

I'll just chime in saying that my experience was smooth like this. I'd use them in the future myself.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#33

Earlier quoted context omitted.

I second this experience, and "Lovecraftian" is indeed an excellent way to describe it. It's not just that the process was difficult, it's that my confidence dwindled through every strange and baffling step. Since you mentioned paying "a few dollars" to Namecheap, can you comment on the feasibility of their $8.95 "PositiveSSL" certificate? ( http://www.namecheap.com/ssl-certificates/comodo.aspx )

The best (in terms of browser compatibility) cheap cert that Namecheap sell is the RapidSSL cert at http://www.namecheap.com/ssl-certificates/geotrust-ssl-certi...

Be aware though that GeoTrust and Thawte certs don't work[1] on android devices. There are claims that it can be fixed by adding a cross-root cert[2] but for me that didn't work out.

More generally: If you need to support mobile devices then read your CA's compatibility list closely (if you can find it...) and test, test, test. You'd think this shouldn't be an issue anymore in 2012, but it sadly still is.

[1] http://www.zimbra.com/forums/administrators/44675-new-geotru...

[2] https://support.servertastic.com/entries/426677-rapidssl-and...

Re: Don't submit to the SSL cert racket. You can get one for no charge

#34
post #2

I'd feel a lot better about using this if its website looked a bit more professional.

Is there any certificate authority with a clean UI? Every single one I have come across has been fairly horrid by today's standards.

We're talking about the actual design of the site. I'm not one to get all wound up over definitions so please excuse if I use the wrong terminology here, I'll try to be as clear as possible.

A beautiful site can have an awful UI. The StartSSL site doesn't have that polished hipster-corporate look that we're so used to seeing these days. I think you might be talking about the experience. It's one thing to have a pain in the ass experience with forms or actions that require multiple page views/reloads to complete and quite another to have an ugly site in general. "Ugly" can be a very subjective thing though. StartSSL's site isn't exactly ugly but more dated looking. Speaking striclty from a design point of view, without being overly critical, the site is aligned nicely, has a nice grid, the typography isn't fancy but it's not so ugly that you'd complain about it on first glance, the colors are okay and don't hinder readability, there's enough white space, etc. Even so, when it comes to design there are always those intangible qualities that you can't quite describe or put into objective terms (which I'm sure is very frustrating for programmers as we're all about exact, measurable, science-y stuff).

So considering that the site isn't ugly from an objective standpoint, how could it still be ugly? To answer that you have to take into account experience. Web design, much like fashion, has fads and trends. Right now we're used to seeing what I like to call "hipster-corporate" design. This style is all about being casual while still looking corporate enough for people to take the comoany's site seriously. It's really tough to straddle the line between trying too hard to look hipster-corporate and looking dated and old fashioned. We've all seen the website for the local doctor's office that looks like it's trying too hard to be that big corporate style but failing miserably and looking like the crappy free Wordpress template that it is. Hipster-corporate is really interesting because there are a lot of variations and the amount of hipster style or corporate style that mixed in all depends on the company's personality and size. Too much or too little of one or the other totally breaks the feel.

So the point is, after all that, I think we're talking more about the "feeling" that the site gives you rather than the objective reality of things when we talk about the site looking pretty or ugly, good or bad, well designed or poorly designed.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#35
post #2

I'd feel a lot better about using this if its website looked a bit more professional.

This seems to have been downvoted but its not an invalid point. The web is old enough now that a certain level of design is expected of things people need to trust. A shop down a side alley with a hand written sign inspires less confidence than something plastic on the high street - however wrong that initial impression may be. People with background knowledge may know startssl is legit/good but to a newcomer I can e…

Oh, c'mon. You KNOW they licensed that knife image from Victorinox. ;-)

Re: Don't submit to the SSL cert racket. You can get one for no charge

#36

I've used StartSSL in the past. I will never do so again. Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.

Not my experience at all. It's easy and straightforward (really takes less than 10 mins). I have a bunch of startSSL certs in use. Before I started using startSSL certs I used Thawte certs. Dealing with Thawte was HORRIBLE, these guys are extremely pushy (their sales reps repeatedly called me at home to 'convince' me I really should renew my certificates with them and wouldn't take no for an answer). Contrast that wi…

[deleted]

Re: Don't submit to the SSL cert racket. You can get one for no charge

#38
post #12

Keep in mind that Gandi includes 1 free SSL cert with every domain name. Per year.

I'm actually shocked at how many places accept the trust chain of my free SSL certificate from Gandi. Some browsers refuse my company's very expensive wildcard certificate from GoDaddy saying it's not trusted but trust mine from Gandi!

Did you configure the server to send the intermediate certificates for your GoDaddy wildcard certificate? I've experienced similar problems in the past, but sending the intermediate certificate fixed it.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#39
post #33

Earlier quoted context omitted.

The best (in terms of browser compatibility) cheap cert that Namecheap sell is the RapidSSL cert at http://www.namecheap.com/ssl-certificates/geotrust-ssl-certi...

Be aware though that GeoTrust and Thawte certs don't work[1] on android devices. There are claims that it can be fixed by adding a cross-root cert[2] but for me that didn't work out. More generally: If you need to support mobile devices then read your CA's compatibility list closely (if you can find it...) and test, test, test. You'd think this shouldn't be an issue anymore in 2012, but it sadly still is. [1] http://…

More precisely, older Android devices.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#40
post #39
post #33

Earlier quoted context omitted.

Be aware though that GeoTrust and Thawte certs don't work[1] on android devices. There are claims that it can be fixed by adding a cross-root cert[2] but for me that didn't work out. More generally: If you need to support mobile devices then read your CA's compatibility list closely (if you can find it...) and test, test, test. You'd think this shouldn't be an issue anymore in 2012, but it sadly still is. [1] http://…

More precisely, older Android devices.

Not really. We've had the issues on Froyo devices, too...
Post reply on HN