My startup is actually centered around this. If anyone wants to purchase a certificate through me, I'll happily give you the lowest rates I can. ($25 EV or $40 wildcard) Our homepage is https://certly.io , shoot me an email at ian@certly.io
Ask HN: What's the best company to buy an SSL certificate from?
41–50 of 89 posts
Re: Ask HN: What's the best company to buy an SSL certificate from?
#42My startup is actually centered around this. If anyone wants to purchase a certificate through me, I'll happily give you the lowest rates I can. ($25 EV or $40 wildcard) Our homepage is https://certly.io , shoot me an email at ian@certly.io
I am an early adopter, but the blank home page and blank blog are a little too early for my tastes.
Re: Ask HN: What's the best company to buy an SSL certificate from?
#43Don't EV certs create a net increase in security risk (if any web users understood what they were supposed to mean)? I'm not expert in these issues, but I've always doubted their security value: EV certs are supposed to communicate certainty[1] to typical web users about identity, confidentiality, and integrity. But, if I understand correctly, obtaining EV certs in someone else's name (or something close enough to fo…
Re: Ask HN: What's the best company to buy an SSL certificate from?
#44My startup is actually centered around this. If anyone wants to purchase a certificate through me, I'll happily give you the lowest rates I can. ($25 EV or $40 wildcard) Our homepage is https://certly.io , shoot me an email at ian@certly.io
Your home page is a "coming soon" page...
Re: Ask HN: What's the best company to buy an SSL certificate from?
#451. DigiCert. They're not the cheapest, but they really have their stuff together. Their support is awesome (speedy, technically competent, and human). They're also proactive about identifying issues with your certs, they handled the heartbleed incident perfectly - reissued for free with no issues. 2. No
DigiCert also has a nice "enterprise" offering where you can confirm your domain with them once then have role accounts that can approve and issue certificates without them needing to re-do verification. Others within your company can then make their own sub-accounts and request certificates. I've dealt with their support people a few times as well, and agree that they are fantastic.
Re: Ask HN: What's the best company to buy an SSL certificate from?
#46Earlier quoted context omitted.
You should also do it for purely selfish reasons. Chrome is sunsetting SHA-1 for use in certificate signatures, and Chrome will eventually show SHA-1 certificates as insecure. Referring specifically to this point, and not to your wider point about moving away from SHA-1, "because one browser maker said so" is rarely a good reason to do anything. Google has an irritating habit of deciding it knows best for the entire…
Correction: two browser vendors who between them have more than half of the browser share. And the solid technical argument is that SHA-1 is no longer considered secure.
For example, instead of saying "it's a good idea to do this because Google will show scary messages", it would be more helpful to link to a site with a test tool and explanatory information about the underlying issue, such as this one:
Re: Ask HN: What's the best company to buy an SSL certificate from?
#47Regarding EV certs, they're not worth the extra money and inconvenience. They provide no additional security, and the assurance they provide visitors is highly questionable (e.g. see shiftpgdn's comment about how switching to a non-EV cert resulted in absolutely no change in order metrics: https://news.ycombinator.com/item?id=8344666).
Re: Ask HN: What's the best company to buy an SSL certificate from?
#48Re: Ask HN: What's the best company to buy an SSL certificate from?
#49Earlier quoted context omitted.
They charge for reissuing certs though. https://news.ycombinator.com/item?id=7557764
That's not a good reason to skip over them. Unless you expect multiple Heartbleed-severity bugs to be exposed in two years you are still way ahead. Just don't lose your private key.
Heck for $99 you can buy a Comodo "EssentialSSL" wildcard, which grants you unlimited re-issue (plus you don't have to deal with StartSSL's terrible UI):
Re: Ask HN: What's the best company to buy an SSL certificate from?
#50Th problem with EV (green bar) certs is the Browser usually ends up checking the certificate status via CRL or OCSP (URI is specified in the cert), which can add an additional .5 to 10+ seconds before the page is displayed. More so when the CA servers are down or the connection times out. So if you do go for an EV cert, go for the one that has the best listed uptime on it's CRL or OCSP servers. Having said that, I wo…
It's important to answer in the context of the question.