Live data from Hacker News

The SSL Co-operative: A Member-Controlled Certification Authority

sslcoop.org

41–50 of 90 posts

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#41
A couple of questions:

- Where do you plan to place the infrastructure of the cooperative?

- What is your expected timeline to issue Browser accepted certificates?

- Are you planning to provide an API for signing CSRs?

I am currently working on a solution for self hosted messaging and file synchronization, and your project would complement our efforts to give people the possibility to self-host securely.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#42

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

StartSSL/Startcom already does not charge for individual (wildcard) certificates, you can request unlimited numbers.

You do pay a $60 fee for identity validation, which is valid for 2 years. You can also have automated validation, but they don't allow wildcard certificates (which I sort-of understand, they do need to make money some way right)

So you get unlimited free non-wildcard certificates or unlimited wildcard certificates for $30/year. Not a bad deal.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#43
post #7
post #4

Earlier quoted context omitted.

That sounds very much like the service that is already offered by StartSSL.com. You pay for identity validation, but you can then create as many regular and wildcard certificates as you wish. It's a superb service.

it's a superb service, until you want a revocation, then they try to extort $25/revocation out of you (even if you've been a long term paying customer) this may be OK if you have only issued one cert, but if you've issued a few hundred (which is the main point of StartSSL: pay once and issue many), then you are SOL unless you can afford to plonk down thousands of dollars. more here: https://www.techdirt.com/articles/…

Since the revocation protocol is broken anyways I don't really think this is a real problem.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#44
post #30

Earlier quoted context omitted.

StartCom charges $60 for a wildcard certificate that will be accepted by just about every important browser out there. You might even be able to get them cheaper elsewhere. There are not any significant costs to obtaining SSL certificates, so a new CA is hardly likely to change the SSL landscape at all.

I disagree, I think free would be a significant difference. A low barrier vs. no barrier.

But this initiative (however good) will also not provide a no-barrier approach. You need to be a member of the coop (with associated fees) to request certificates.

Which is logical. Running a CA and getting the root certificate into the right places is not cheap. Unless someone with money (e.g. Google, as they do with their CDN) decides to provide this service for free some money needs to be earned.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#45
post #37
post #5

Am I the only one that finds it hillarious (or troubling) that the SSL cert for this site is for a different host name?

(I'm the sslcoop.org guy) Yeah, well, I haven't worked out how to tell nginx to look at the SNI for a HTTPS request and bomb out completely if it doesn't match any SSL-enabled vhost. Unless you've got pervasive IPv6 -- then I can set everything up so manually mangling URLs to use HTTPS doesn't cause problems (there's no links to HTTPS resources on sslcoop.org)... Turns out the real scarce resource is IPv4 addresses -…

if you find a way, could you post a gist here please !!

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#46

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

StartCom charges $60 for a wildcard certificate that will be accepted by just about every important browser out there. You might even be able to get them cheaper elsewhere. There are not any significant costs to obtaining SSL certificates, so a new CA is hardly likely to change the SSL landscape at all.

> $60 for a wildcard certificate

It is $60 for as many as you need, for multi-name certificates too, as long as (presumably, I'd need to recheck the smallprint to remind myself) they are all for you and you aren't signing certificates for others. The fact that they are signed for two years instead of one is handy too.

I've recently signed up for that to get some wildcard+multiname certs mainly for convenience (not having to sign a new cert for every tld/sub-domain combination), and not have s wildcard cert for my vanity domain and one for all the names associated with a project that I'm trying to work on (.domain.net, .domain.com, .domain.co.uk, .domain.uk all in one certificate). Remember before considering this though: there is some extra security in having separate certificates for everything instead of a huge wildcard-for-all arrangement. If you PK for a combined wildcard certificate leaks from any one location any security problems that causes affects every location you have that one certificate in use, so I am trading off a convenience gain against taking a little extra risk.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#47
post #42

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

StartSSL/Startcom already does not charge for individual (wildcard) certificates, you can request unlimited numbers. You do pay a $60 fee for identity validation, which is valid for 2 years. You can also have automated validation, but they don't allow wildcard certificates (which I sort-of understand, they do need to make money some way right) So you get unlimited free non-wildcard certificates or unlimited wildcard…

> So you get unlimited free non-wildcard certificates

Do note the "no commercial use" clause on the free certificates. Not an issue for any of my uses but it may affect quite a few people. Though I'm not sure how they would enforce this.

Of course if you can't afford $60 for two years for the next grade up, then your commercial venture is probably not a roaring success!

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#48
post #37
post #5

Am I the only one that finds it hillarious (or troubling) that the SSL cert for this site is for a different host name?

(I'm the sslcoop.org guy) Yeah, well, I haven't worked out how to tell nginx to look at the SNI for a HTTPS request and bomb out completely if it doesn't match any SSL-enabled vhost. Unless you've got pervasive IPv6 -- then I can set everything up so manually mangling URLs to use HTTPS doesn't cause problems (there's no links to HTTPS resources on sslcoop.org)... Turns out the real scarce resource is IPv4 addresses -…

[deleted]

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#49
post #7

Earlier quoted context omitted.

it's a superb service, until you want a revocation, then they try to extort $25/revocation out of you (even if you've been a long term paying customer) this may be OK if you have only issued one cert, but if you've issued a few hundred (which is the main point of StartSSL: pay once and issue many), then you are SOL unless you can afford to plonk down thousands of dollars. more here: https://www.techdirt.com/articles/…

To be fair, it seems like they have a point that revocation is actually expensive for them.

Where does it say that? I would assume it's just as easy as issuing them in the first place.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#50
post #37
post #5

Am I the only one that finds it hillarious (or troubling) that the SSL cert for this site is for a different host name?

(I'm the sslcoop.org guy) Yeah, well, I haven't worked out how to tell nginx to look at the SNI for a HTTPS request and bomb out completely if it doesn't match any SSL-enabled vhost. Unless you've got pervasive IPv6 -- then I can set everything up so manually mangling URLs to use HTTPS doesn't cause problems (there's no links to HTTPS resources on sslcoop.org)... Turns out the real scarce resource is IPv4 addresses -…

Possibly a stupid question, but why not make whichever vhost is correctly configured for SSL your default? Any traffic will go there unless another match is found. This is what I do to force SSL and redirect anything not matching another vhost.

  Catch-all + HTTP --> HTTPS
  server {
          # Set server name & make it the default for this IP address
          listen 80 default_server;
          listen [::]:80 default_server ipv6only=on;
          return 301 https://EXAMPLE.TLD$request_uri;
  }
Or, rewrite HTTPS to HTTP for that vhost only

  server {
          listen      443;
          server_name EXAMPLE.TLD;
          return 301 http://EXAMPLE.TLD$request_uri;
  }
Mozilla's server-side TLS wiki at https://wiki.mozilla.org/Security/Server_Side_TLS is the best documentation I've found yet, and includes great examples of complete configs for various servers. Hope that helps.
Post reply on HN