Live data from Hacker News

EuroDNS introduces free SSL certificates to customers

news.eurodns.com

31–40 of 40 posts

Re: EuroDNS introduces free SSL certificates to customers

#31
post #20
post #18

Ok, for the semi-newb here - this would do if I just wanted to secure a single site (e.g. a blog) without a subdomain, right? Because I should really get on that

Hi, you could have blog.yourdomain.tld and yourdomain.tld in the same certificate for free. edit: to make it simple you have the right of one sub domain and the root domain without subdomain. As soon as you need more than one, you will need to go for a wildcard (which is not free).

perfect, thanks.

Re: EuroDNS introduces free SSL certificates to customers

#32

If they had announced this before the Let's Encrypt[0] initiative it would have been more impressive, but still it is a nice gesture to offer these for the month or two that people are still buying them. I wonder if it is a preemptive move to keep customers from taking their certificates elsewhere, as you will be able to do with the Let's Encrypt certs? Reading the rest of the announcement, It looks like they are slo…

> It looks like they are slowly catching up to Gandi.net, who have offered free one year certs

As far as I know, you only get a free certificate with a new domain registration, so after the first year, you'd still need to pay an annual renewal fee for the certificate.

Re: EuroDNS introduces free SSL certificates to customers

#33
post #23

If they had announced this before the Let's Encrypt[0] initiative it would have been more impressive, but still it is a nice gesture to offer these for the month or two that people are still buying them. I wonder if it is a preemptive move to keep customers from taking their certificates elsewhere, as you will be able to do with the Let's Encrypt certs? Reading the rest of the announcement, It looks like they are slo…

Even in a world where Lets Encrypt exists and actually provides free certs, I don't want a world where they become the SPOF for all certs, and I can't even imagine that they want that world. Insofar as I can guess the end-game, it seems like they want to offer free certs so that providers like EuroDNS do exactly this. That way we have lots of providers offering free certs and competing on features and security rather…

> Even in a world where Lets Encrypt exists and actually provides free certs, I don't want a world where they become the SPOF for all certs, and I can't even imagine that they want that world.

Considering that Let's Encrypt seems to be planning to release all their software as Open Source, it seems like anyone willing to go through the time-consuming and expensive audit process could become a provider using similar infrastructure.

In particular, Let's Encrypt isn't just about the free certificates, it's about having automatic renewal and easy setup. Automatic renewal in particular is something I haven't seen from any other provider; I don't know any CAs that even have an API. I'd like to see that become a minimum expectation from all CAs.

I wonder sometimes why Amazon doesn't offer a CA as part of the AWS family of services, with an API for creating new certificates.

Re: EuroDNS introduces free SSL certificates to customers

#34

If they had announced this before the Let's Encrypt[0] initiative it would have been more impressive, but still it is a nice gesture to offer these for the month or two that people are still buying them. I wonder if it is a preemptive move to keep customers from taking their certificates elsewhere, as you will be able to do with the Let's Encrypt certs? Reading the rest of the announcement, It looks like they are slo…

> It looks like they are slowly catching up to Gandi.net, who have offered free one year certs As far as I know, you only get a free certificate with a new domain registration, so after the first year, you'd still need to pay an annual renewal fee for the certificate.

Yeah, I'm pretty sure only the first one-year certificate is free for each domain at Gandi, so after the first year you have to pay for it. Same if you want more than one certificate for the same domain. It's part of the reason I moved to a different certificate provider after a year.

Re: EuroDNS introduces free SSL certificates to customers

#35
post #29
post #10

According to their site, http://blog.eurodns.com/eurodns-ssl-certificates/ , this is only for domains registered with them. So it's not really free. StartCom/StarSSL has provided fully free certificates for some time: http://www.startssl.com/?app=1 edit : Title is now clearer, I believe the "to customers" portion wasn't initially there. Or I just suck at reading.

StartSSL has been on the naughty list for a while They charge for revocation, so it negates the entire idea of a "free certificate" if you can't properly revoke them without forking over money. It literally breaks the entire idea of revocation. This was made very clear when Heartbleed happened

Revocation is pretty broken even without that. Instead of explaining why I'll just link this:

http://news.netcraft.com/archives/2013/05/13/how-certificate...

Re: EuroDNS introduces free SSL certificates to customers

#38
post #34

Earlier quoted context omitted.

> It looks like they are slowly catching up to Gandi.net, who have offered free one year certs As far as I know, you only get a free certificate with a new domain registration, so after the first year, you'd still need to pay an annual renewal fee for the certificate.

Yeah, I'm pretty sure only the first one-year certificate is free for each domain at Gandi, so after the first year you have to pay for it. Same if you want more than one certificate for the same domain. It's part of the reason I moved to a different certificate provider after a year.

This is true and I could have worded it better. My point is that with Let's Encrypt coming online soon, Gandi's one free single year cert per domain gets you HTTPS now, and by the time it expires you won't need to buy another.

Re: EuroDNS introduces free SSL certificates to customers

#39
post #23

If they had announced this before the Let's Encrypt[0] initiative it would have been more impressive, but still it is a nice gesture to offer these for the month or two that people are still buying them. I wonder if it is a preemptive move to keep customers from taking their certificates elsewhere, as you will be able to do with the Let's Encrypt certs? Reading the rest of the announcement, It looks like they are slo…

Even in a world where Lets Encrypt exists and actually provides free certs, I don't want a world where they become the SPOF for all certs, and I can't even imagine that they want that world. Insofar as I can guess the end-game, it seems like they want to offer free certs so that providers like EuroDNS do exactly this. That way we have lots of providers offering free certs and competing on features and security rather…

If renewal is automatic, there's also little reason not to make the expiry date really short.

Re: EuroDNS introduces free SSL certificates to customers

#40
post #26

Earlier quoted context omitted.

No, we don't. The CA is supposed to verify the owner of the certificate and stand behind that with a financial guarantee. Otherwise, it's just security theater.

I'm getting certificates for various websites with fake details for years now. The theater is there already, it would and we should not pay for it anyway.

Please post bad certs on "dev-security-policy@lists.mozilla.org". They can be revoked. Mozilla is introducing a Mozilla-controlled revocation list in Firefox 37.

There's a lot going on to tighten up the CA world.

Post reply on HN