5 ms·
Show HN: Free SSL Certificates
- ng-user 11y agoCan anyone comment who's used it? Is it generally accepted by most browsers or is there more issues than that?
- jimmaayn 11y agoThey use letsencrypt https://community.letsencrypt.org/t/frequently-asked-questions-faq/26 https://community.letsencrypt.org/t/frequently-asked-questio...
- theWheez 11y agoI like the idea of making encryption easy, but getting my private key from a third party that isn't the CA itself seems like a big security flaw.
- etrackr 11y agoThe key is generated and instantly outputted over SSL. Nothing is ever stored nor would I want that liability. Would it better if I did the private key generation on the client side so that your browser generates it? The only issue with that is that it's a lot slower and browser compatibility isn't great.
- brianberlin 11y agoi appreciate the effort to make SSL free and easy. i know the first time I attempted to use lets encrypt it took a bit of work getting setup. what's the possibility of using electron and doing the work locally?
- etrackr 11y agoI don't use electron so I'm not sure. This service is for people that don't have access to SSH or don't know how to use letsencrypts' official client on their hosting server. If you do have access then it's best to use the client and have an auto-renew cron, then you won't ever have to renew a certificate again as it will renew and install periodically. If you run cPanel on Cent 6/7 use this guide https://forums.cpanel.net/threads/how-to-installing-ssl-from-lets-encrypt.513621/ https://forums.cpanel.net/threads/how-to-installing-ssl-from....
- etrackr 11y agoOkay sorry, I looked at electron. If you want a local copy you can try https://gethttpsforfree.com/ https://gethttpsforfree.com/ it's completely client sided, you can save the html file and use whenever. You have to generate your own keys and CSR though
- ntw1103 11y agoI just ran through the process, and it worked very smoothly. No hick-ups, it just worked. SSLlabs reports an A. Very awesome.
- etrackr 11y agoThanks. SSL should always have been this easy. I used the let's encrypt client when it came out and it took 3 hours to install on my server requiring root access. I couldn't get a client working on windows as well so for people without root access to their server they can't even really get a certificate. I paid for my certificates before this and it takes at least 30 minutes. This literally takes seconds once you know your FTP or know how to manually do it.
- sarciszewski 11y agoLook at StartSSL's workflow.
- profmonocle 11y agoEven getting your private key from the CA isn't a good idea.
- etrackr 11y agoPrivate keys are now generated on the client using the Web Crypto API and never transmitted now. Merry Christmas all!
- ntw1103 11y agoI agree with the other comment that generating this on the server is a security flaw. That being said, I thought I would give it a try. The manual verification process doesn't give me any files to upload. FTP is disabled. (I am using Palemoon, if that matters)
- etrackr 11y agoIt should work now. There was some browser compatibility problems that I just fixed.
- kumarski 11y agoDoes this split the ssl among multiple websites?
- etrackr 11y agoThis service supports up to 100 domains per certificate using SAN. By default it secures domain.com and www.domain.com