11 ms·
Learning this, I will not renew my certs with Comodo. This is childish behaviour on Comodos part. If it helps I'll advise any companies I consult to do the sa
by CommanderData 10y ago
Learning this, I will not renew my certs with Comodo. This is childish behaviour on Comodos part.
If it helps I'll advise any companies I consult to do the same until this changes. Money is the only thing this company will understand.
- distances 10y agoI agree. I have an existing cert from Comodo for my personal site, as they were cheap and easy to get when I was looking for one. I will look for another provider when it's time to renew.
- nik736 10y agoWhy are you looking for another provider? Just use Lets Encrypt ;-)
- jakobegger 10y agoLets encrypt certs are only valid for 3 months. In many situations the auto-renewal stuff is inconvenient. Then its easier to just buy a commercial cert that's valid for a few years.
- _jomo 10y agoI always use acme-tiny [0] to set up LE certs. You can follow their README to set up everything, including automatic reneweal cronjob in a couple minutes. 0: https://github.com/diafygi/acme-tiny#readme https://github.com/diafygi/acme-tiny#readme
- bradleyjg 10y agoThat's not always an option. For example, when I was looking into it for google app engine, I came across these directions: http://blog.seafuj.com/lets-encrypt-on-google-app-engine http://blog.seafuj.com/lets-encrypt-on-google-app-engine and http://igorartamonov.com/2015/12/lets-encrypt-ssl-google-appengine/ http://igorartamonov.com/2015/12/lets-encrypt-ssl-google-app... That's not so bad if you have to do it once a year or better yet once every two years, but I'm not doing that every 3 months. There's an issue open to allow for the process to be automated, hopefully by the next time I need to renew it'll be available. But as it stands today I went with a paid certificate.
- bouk 10y agoI know this doesn't help you, but the best fix for this would be for App Engine to implement letsencrypt support directly, so they can automatically provision and renew certificates for anyone that uses app engine
- Ajedi32 10y agoHere's the issue for that, FYI: https://code.google.com/p/googleappengine/issues/detail?id=12535 https://code.google.com/p/googleappengine/issues/detail?id=1...
- newman314 10y ago+1 I was just looking at doing this last night for two sites and came to the conclusion that it was too painful. Far too many products still require manual intervention which is a huge bummer. Synology, VMware, ddwrt etc. OTOH, lego with Cloudflare DNS challenge proved to be very easy to use with a single command.
- distances 10y agoThe Comodo cert was for 5 years at a total of $25 IIRC. I didn't consider that bad at all, especially as that was add-and-forget. Of course that's still like a money printing machine, and wildcards and greenbars are much more. But the deal was pretty fine for my personal domain. To be frank, I would probably have renewed with them.
- davidgerard 10y agoThe whole idea is to motivate you to automate the process as far as possible. This is basically a good idea. It's a faff for us at present 'cos we don't have direct access to our load balancers at this moment (just switched hosting), but we're working on that.
- deleted 10y ago[deleted]
- distances 10y agoThat counts as a provider too, and a likely one at that.
- vec 10y agoLet's Encrypt doesn't offer EV certs. Which is reasonable; EV certs can't be automated (and they're a dumb idea anyway), but they're still necessary for some of my sites.
- nailer 10y ago> EV certs can't be automated No entirely, but mostly: seeing as this is my job, I should have some idea. Currently writing a post about how we've used some psych techniques to automate the non-automatable parts which I'll post on HN. > (and they're a dumb idea anyway) EV matches identity to public keys. Nothing more, nothing less. If you need EV, we (https://certsimple.com https://certsimple.com) specialise in making those background checks far less painless with a bunch of unique tech. This means you get your certificate faster and with a lot less effort on your behalf (and a lot more on ours) during the verification process: https://certsimple.com/about https://certsimple.com/about If a DV cert is fine, go with Let's Encrypt (Hi Richard!), dnsimple (Hi Anthony!) or CloudFlare (Hi John and Filippo!) or Heroku.
- Mtinie 10y agoAnecdotally: I fully recommend CertSimple. We used them for an EV cert we needed and not only was it simple to set up the request, but the processing was quick, too!
- nailer 10y agoThanks Ben :^)
- jakobegger 10y agoI can't find pricing on your website. There's a page called 'pricing' that says I can find pricing on the home page. When I click the link, I find a lot of marketing text, but no pricing.
- nailer 10y agoIt's right underneath the 'Domain names' box, in to USD / GBP / EUR based on country (which is in turn based on your IP location).
- mpclark 10y agoTurns out I have a Comodo cert expiring soon. Let's see if they do the right thing before I do...
- icebraining 10y agoThey already refused to back down, even after requests from Let's Encrypt lawyers. Backpedalling now in response to the PR crisis would not be enough, in my opinion. I'd only consider them again if they were to make a decent donation to Let's Encrypt.
- lucb1e 10y agoI had a Comodo cert expiring in a year or so, but still went with Let's Encrypt since I was setting it up for other domains.
- waterphone 10y agoI had one just about to expire, and this was my motivation to switch over to Let's Encrypt.
- mpclark 10y agoWell, colour me impressed. Looks like they have indeed done the right thing. Fair's fair, I'm going to go ahead and renew my Comodo cert.
- ultramancool 10y agoYeah, the only reason to use them was that they were cheap and now AlphaSSL's resellers are cheaper anyways, $40 wildcards are hard to argue with. Heck, I paid $100 for 3 years on renewal.
- jonlucc 10y agoJust curious, but do you think companies you consult care enough to switch? It's usually easier to just renew, and I wonder if consultants have the leverage to get customers to care.
- davidgerard 10y agoWe buy EV certs for those sites where the business unit and/or marketing demands it, but otherwise we just use Let's Encrypt. (Small publisher with some paid info sites.)
- eximius 10y agoIs it easier? How automated can you make renewal with Comodo? Even big companies goof and have a few hours of downtime where their cert expired. With Let's Encrypt, you make it not a human's error anymore.
- JoshTriplett 10y agoIt'd be easy to make a case that Comodo is no longer trustworthy, pointing to several of their past actions, and recommending a switch to a safer provider. If the consultant does the work to make the switch happen, and the cost doesn't increase, I doubt the customer would object.
- CommanderData 10y agoThey couldn't care if I mentioned it and I don't plan to. Renewals often involve just as much work as installing a new cert. This is more about personal recommendations, after I recommend its normally accepted without question.
- danra 10y agoI've avoided buying a code signing certificate from Comodo just because of their reputation, even though they offered the cheapest price. To me, this behavior reinforces that that was the right decision.
- devy 10y agoI am on LetsEncrypt's side to defend their branding. However, Comodo's intent is understandably clear: you take away my business by giving away free certs I screw you in your branding. (not that I agree with this tactic.)
- nikcub 10y agoI've avoided the big issuers for a while now. Big plug for Digicert who are excellent - they're independent (so not conflicted), have great infrastructure (fastest on OSCP), super support and active in pushing standards such as CT, short-lived certs, and adopting .onion support after internal names were deprecated. I use LetsEncrypt in most cases (and have companies I work with donate a portion of what they used to spend) and then DigiCert for EV SAN.
- knet 10y ago+1 for Digicert, awesome service. I'm definitely looking at letsencrypt for our next project.
- johansch 10y agoIt's quite a bit more than being childish. They're basically saying F U to the security community and to people who want a secure Internet. How is this company still alive after their numerous security breaches/issue (https://en.wikipedia.org/wiki/Comodo_Group#Controversies https://en.wikipedia.org/wiki/Comodo_Group#Controversies) and then on top of those, this thing? They need to go out of business.
- rhizome 10y agoIt's troubling that an ostensibly security-oriented company would seek to muddy the waters like this and reduce the reliability and integrity of the marketplace.
- sandGorgon 10y agogo with rapidssl - because we use docker and bake our certificates into our vms, we find it hard to use letsencrypt. but we have been very happy with rapidssl (even using it on our apis that serve legacy android devices)