5 ms·
In case you are looking for alternative free certificate authority then there is also http://CAcert.org http://CAcert.org PS. I'm a happy CAcert certificate us
by plaes 17y ago
In case you are looking for alternative free certificate authority then there is also http://CAcert.org http://CAcert.org
PS. I'm a happy CAcert certificate user ;)
- tptacek 17y agoDoes any mainstream browser include the CACert root? Without it, you might as well just use no certificate; self-signed certs add no additional security to TLS in the HTTPS case.
- Sidnicious 17y agoAt the moment, no, but CACert is working on it. Certificates issued by CACert are still more valuable than self-signed because the owner's identity has been verified and, if the user installs the CACert root once, they can all be checked against it.
- tptacek 17y agoWithout the root cert installed, they add zero additional security, because the browser can't verify them. They might as well be self-signed. CACert has been working on this for a long time, and the outlook does not seem positive. If they can't even get past Mozilla's audit requirements, how well do you think they'll fare with Microsoft?
- Sidnicious 17y agoI checked in with someone from CACert at 26C3. As far as he knows, the audit is moving forward and they expect to make it into both.
- kogir 17y agoThat's like saying that SSH host keys add no additional security. If I add the self-signed cert to my certificate store, if anyone ever tries to present me a fake one, I'll know. Doesn't help with public sites, but does with personal administrative ones.
- tptacek 17y agoSSH and TLS use two totally different trust models. With SSH, you deliberately accept an insecure first connection, but then rely on key continuity so that subsequent connections won't be any less secure than the first. This happens automatically; users don't have to think about it. TLS has no key continuity. Browsers talk to tens of thousands of different sites. TLS doesn't work unless you can verify public key signatures all the way back to a trusted root. Yes, you can manually manage certificates, but you can just as easily add the CACert root to your certificate manager and use TLS the way it's meant to be used. Which, fine, do that. But for the other 99.999% of your users, CACert is no better than a self-signed cert.
- deleted 17y ago[deleted]
- ars 17y agoSo CACert in principle is fine, and better than a self signed. It's just that most (windows) people don't have the CACert root cert installed. I think many of the linux distributions (notably not including redhat) include the CACert root cert.
- tptacek 17y agoYou use this word "better" like it means something. If all your users use Linux, you're fine. Otherwise, you need a real cert.
- plaes 17y agohttp://wiki.cacert.org/InclusionStatus http://wiki.cacert.org/InclusionStatus
- tptacek 17y agoSo: no.