Live data from Hacker News

The SSL Co-operative: A Member-Controlled Certification Authority

sslcoop.org

1–10 of 90 posts

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#2
I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates.

Certificates cost approximately nothing to issue, and most of the CA's infrastructure would not need significant scaling with the issuance of more certificates.

Manual validation of human/organization identities (the type that requires reading identity documents, such as for EV) costs money, and that could have associated fees, but it doesn't need to occur on a per-certificate basis. And automatable validation costs nothing.

In particular, wildcard certificates don't need to cost any more than standard certificates, and no-cost wildcard certificates would change the SSL landscape significantly. Today, any service that uses subdomains incurs significant fees to secure those subdomains.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#4

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

That sounds very much like the service that is already offered by StartSSL.com. You pay for identity validation, but you can then create as many regular and wildcard certificates as you wish. It's a superb service.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#6
post #4

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

That sounds very much like the service that is already offered by StartSSL.com. You pay for identity validation, but you can then create as many regular and wildcard certificates as you wish. It's a superb service.

[deleted]

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#7
post #4

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

That sounds very much like the service that is already offered by StartSSL.com. You pay for identity validation, but you can then create as many regular and wildcard certificates as you wish. It's a superb service.

it's a superb service, until you want a revocation, then they try to extort $25/revocation out of you (even if you've been a long term paying customer)

this may be OK if you have only issued one cert, but if you've issued a few hundred (which is the main point of StartSSL: pay once and issue many), then you are SOL unless you can afford to plonk down thousands of dollars.

more here: https://www.techdirt.com/articles/20140409/11442426859/shame...

the CEO (Eddy Nigg) is similarly patronising over email too.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#8
post #3

http://www.cacert.org/ is a similar-ish effort that's been ongoing for quite a long time.

Unfortunately they are so messed up, it isn't even funny.

Honestly, my experiences with CAcert were awful. Pressuring people into signing legal contracts that are just laughably unfair was just one part of it.

They may have been a likable organisation at the begininng (maybe with a penchant for over-the-top policy), but when they realized they wouldn't get into major browsers by default, they tried to get "serious", changing too much too fast and wrecking the whole thing. Without the big result they were hoping for.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#9
post #3

http://www.cacert.org/ is a similar-ish effort that's been ongoing for quite a long time.

It's sad that debian removed them. I think cacert needs more dedicated governance. If all the money we spent on ssl certificates could be pooled together to create non-profit organisation dedicated to public certificates, it would be awesome! And we could probably get opensource PKI infrastructure.

Re: The SSL Co-operative: A Member-Controlled Certification Authority

#10

I'll say the same thing here that I said in a response to the survey: I'd be interested in taking part in a CA co-op that seeks membership/sponsorship to cover its infrastructure costs (including the huge initial cost of becoming an accepted CA), but that does not charge to issue certificates, including wildcard certificates. Certificates cost approximately nothing to issue, and most of the CA's infrastructure would…

Pretty much what I was thinking. Here's what I almost sent as a response to the survey: This is a brilliant idea. I would pay up to $50 a year for the pleasure of being able to get domain validated SSL certs that are trusted by the major browsers. I would assume that the validation would be via emailing webmaster@domain and making them either respond or click a link or something. That could all be automated couldn't it.

Also, make wildcard certificates for domains available for the same low price, because it shouldn't take any more work should it. If I control example.org, then I think it's obvious that I control www.example.org and slighly-biased.example.org.

But then you have the issue of, if Org A controls com.au, that doesn't mean they control mywebsite.com.au. I don't know how you would automate that issue.

The non-automated stuff, make people pay for it. Seriously.

Post reply on HN