Live data from Hacker News

WoSign: Free two-year multi-domain SSL certificate

ohling.org

1–10 of 63 posts

Re: WoSign: Free two-year multi-domain SSL certificate

#2
That's really neat.

I just thought my past employee (used to have StartSSL but got rejected recently) have to buy an wildcard one for a year while "Let's Encrypt" is not yet here, but this is just great. Will tell them to save their money.

Hope they'll update MAC soon. Wonder if they have an option to sign only for an year, so expiry date won't get past 2017. SHA1 should suffice for an year.

Re: WoSign: Free two-year multi-domain SSL certificate

#3
Seems they just recently passed Mozilla's/Google's CA root inclusion process: https://bugzilla.mozilla.org/show_bug.cgi?id=851435

Edit: Hmm, looks like the free certs will never pass strict OCSP checks. As broken as the OCSP system is, I would still like to be able to check against it.

Re: WoSign: Free two-year multi-domain SSL certificate

#4
Nice find! But given the amount of hassle to get one, your hourly rate must be very low. But I'm sure it will be the future to get near-0$ DV-certificates.

It's a pity no CA besides StartCom and Comodo pick up the S/MIME market. Both options are not very usable for non-IT people.

Re: WoSign: Free two-year multi-domain SSL certificate

#5
post #2

That's really neat. I just thought my past employee (used to have StartSSL but got rejected recently) have to buy an wildcard one for a year while "Let's Encrypt" is not yet here, but this is just great. Will tell them to save their money. Hope they'll update MAC soon. Wonder if they have an option to sign only for an year, so expiry date won't get past 2017. SHA1 should suffice for an year.

I wonder if they provide an easy way to revoke and re-issue a certificate, too. Probably not.

Re: WoSign: Free two-year multi-domain SSL certificate

#6
post #4

Nice find! But given the amount of hassle to get one, your hourly rate must be very low. But I'm sure it will be the future to get near-0$ DV-certificates. It's a pity no CA besides StartCom and Comodo pick up the S/MIME market. Both options are not very usable for non-IT people.

Cloudflare offer free SSL now, so if you are small and can't afford a certificate, they could be a good choice.

Re: WoSign: Free two-year multi-domain SSL certificate

#7
post #6
post #4

Nice find! But given the amount of hassle to get one, your hourly rate must be very low. But I'm sure it will be the future to get near-0$ DV-certificates. It's a pity no CA besides StartCom and Comodo pick up the S/MIME market. Both options are not very usable for non-IT people.

Cloudflare offer free SSL now, so if you are small and can't afford a certificate, they could be a good choice.

S/MIME != SSL http://en.wikipedia.org/wiki/S/MIME

Re: WoSign: Free two-year multi-domain SSL certificate

#8
post #6
post #4

Nice find! But given the amount of hassle to get one, your hourly rate must be very low. But I'm sure it will be the future to get near-0$ DV-certificates. It's a pity no CA besides StartCom and Comodo pick up the S/MIME market. Both options are not very usable for non-IT people.

Cloudflare offer free SSL now, so if you are small and can't afford a certificate, they could be a good choice.

Cloudflare Univeral SSL uses SNI https://support.cloudflare.com/hc/en-us/articles/203041594-W...

Re: WoSign: Free two-year multi-domain SSL certificate

#9
post #3

Seems they just recently passed Mozilla's/Google's CA root inclusion process: https://bugzilla.mozilla.org/show_bug.cgi?id=851435 Edit: Hmm, looks like the free certs will never pass strict OCSP checks. As broken as the OCSP system is, I would still like to be able to check against it.

Usually it's quite easy to pass this (a single vendor) - you just need to get verified by a WebTrust recognized company (E&Y or some other bookkeeping company) and be able to convince the vendor (the process is pretty much the same with each vendor).

However you'll need to build and run your infrastructure upfront so you're already burning some years money just to get those documents. When you finally get them and become ready to apply for inclusion with the vendors (Apple/MSFT/GOOG/Mozilla/Debian etc) it will take another couple of months. Even when you're included there is a big chance that it will take a couple of years to reach a high enough distribution rate to be acceptable for business purposes (think of old android devices or Windows XP).

Getting cross-signed by another CA costs money and they will re-validate your setup as you will sign "below" their root CA.

I wonder what the total initial and running costs of starting up a CA (including WebTrust & yearly re-audit) are today...

Re: WoSign: Free two-year multi-domain SSL certificate

#10
At risk of sounding xenophobic, you have to wonder if this is simply an effort to have Chinese-issued certificates become common place in the west. A common form of certificate pinning is based on the CA that issued the certificate (to allow certificate rotation). More Chinese issued certificates being used intentionally will make the mere fact that a certificate was issued by a Chinese CA less suspicious.
Post reply on HN