Live data from Hacker News

Don't submit to the SSL cert racket. You can get one for no charge

startssl.com

51–60 of 88 posts

Re: Don't submit to the SSL cert racket. You can get one for no charge

#52
I did not get a good feeling about StartSSL when I tried getting a free cert. First, as many have pointed out, the web site experience is miserable.

Second, I just got a "Error 107 (net::ERR_SSL_PROTOCOL_ERROR): SSL protocol error." at https://auth.startssl.com

For a product that is supposed to be confidence inspiring, StartSSL is the opposite.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#53
post #51

Is it possible to sign object code (.exe , .dll etc) with any SSL certificate that we buy ? or does this have to be mentioned clearly in the list of features of SSL certificate..

It's possible that an ssl certificate may have that capability added, but in my experience they've always been sold as separate products. If you need a code signing certificate the cheapest I've found was through Tucows. It's hidden in their developer resource subdomain. We paid $199 for a 3 year code signing cert.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#54
post #12

Earlier quoted context omitted.

I'm actually shocked at how many places accept the trust chain of my free SSL certificate from Gandi. Some browsers refuse my company's very expensive wildcard certificate from GoDaddy saying it's not trusted but trust mine from Gandi!

Their certs are issued by Comodo, which is a well established CA. And they are hardly free , their price is simply rolled into the domain registration fee.

They may be well established, but remember ComodoGate [1,2].

[1] https://en.wikipedia.org/wiki/Comodo_Group#Breach_of_securit... [2] http://www.securelist.com/en/blog/6177/A_Web_of_Mis_Trust_Co...

Re: Don't submit to the SSL cert racket. You can get one for no charge

#55
post #52

I did not get a good feeling about StartSSL when I tried getting a free cert. First, as many have pointed out, the web site experience is miserable. Second, I just got a "Error 107 (net::ERR_SSL_PROTOCOL_ERROR): SSL protocol error." at https://auth.startssl.com For a product that is supposed to be confidence inspiring, StartSSL is the opposite.

You're supposed to have installed the client SSL certificate in your browser before visiting that URL. It caught me out too initially. They use client side SSL certificates for authentication. I don't know any other site which does this.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#56

I've used StartSSL in the past. I will never do so again. Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.

The only complication is the fact that they use client side SSL certificates for authentication. I don't know of any other site which does this. Although I like that they're dog fooding, it probably would have been better if they'd stuck with a traditional username/password/cookie scheme for logging in, from a business/usability perspective.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#57

I've used StartSSL in the past. I will never do so again. Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.

I second this experience, and "Lovecraftian" is indeed an excellent way to describe it. It's not just that the process was difficult, it's that my confidence dwindled through every strange and baffling step. Since you mentioned paying "a few dollars" to Namecheap, can you comment on the feasibility of their $8.95 "PositiveSSL" certificate? ( http://www.namecheap.com/ssl-certificates/comodo.aspx )

I have a Comodo certificate purchased through cheapssl.com. There is one problem: some older android 2.3 phones don't recognize it as valid and refuse to download any non-html data files.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#58
The SSL certificate for https://grepular.com/ is from StartSSL. I renewed it 5 days ago. The CN is for "secure.grepular.com" (for historical reasons), with a subjectAltName of "grepular.com"

I'd like to create a wild card certificate, but that costs money. My understanding is that it is a one off fee (60USD) for them to validate your identity and that it doesn't cost money to renew after that point. I could be wrong though. It's not completely clear.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#60

The SSL certificate for https://grepular.com/ is from StartSSL. I renewed it 5 days ago. The CN is for "secure.grepular.com" (for historical reasons), with a subjectAltName of "grepular.com" I'd like to create a wild card certificate, but that costs money. My understanding is that it is a one off fee (60USD) for them to validate your identity and that it doesn't cost money to renew after that point. I could be wrong…

The identity validation expires every year, and you have to pay the $59.90 again to renew it. However, once you've validated your identity, you can generate as many "class 2" certificates (including wildcard certificates) as you like, and those certificates last 2 years.
Post reply on HN