5 ms·
Let's Encrypt doesn't offer EV certs. Which is reasonable; EV certs can't be automated (and they're a dumb idea anyway), but they're still necessary for some o
by vec 10y ago
Let's Encrypt doesn't offer EV certs. Which is reasonable; EV certs can't be automated (and they're a dumb idea anyway), but they're still necessary for some of my sites.
- nailer 10y ago> EV certs can't be automated No entirely, but mostly: seeing as this is my job, I should have some idea. Currently writing a post about how we've used some psych techniques to automate the non-automatable parts which I'll post on HN. > (and they're a dumb idea anyway) EV matches identity to public keys. Nothing more, nothing less. If you need EV, we (https://certsimple.com https://certsimple.com) specialise in making those background checks far less painless with a bunch of unique tech. This means you get your certificate faster and with a lot less effort on your behalf (and a lot more on ours) during the verification process: https://certsimple.com/about https://certsimple.com/about If a DV cert is fine, go with Let's Encrypt (Hi Richard!), dnsimple (Hi Anthony!) or CloudFlare (Hi John and Filippo!) or Heroku.
- Mtinie 10y agoAnecdotally: I fully recommend CertSimple. We used them for an EV cert we needed and not only was it simple to set up the request, but the processing was quick, too!
- nailer 10y agoThanks Ben :^)
- jakobegger 10y agoI can't find pricing on your website. There's a page called 'pricing' that says I can find pricing on the home page. When I click the link, I find a lot of marketing text, but no pricing.
- nailer 10y agoIt's right underneath the 'Domain names' box, in to USD / GBP / EUR based on country (which is in turn based on your IP location).
- jakobegger 10y agoOk, now I discovered it. Had to put my phone in landscape mode (in portrait mode the website is totally different) Pricing starts at 220€ per year, in case anyone is interested.
- sijoe 10y agoQuick plug for a company I've used: SSLmate (http://sslmate.com http://sslmate.com) makes cert purchase (for those whom need this) painless and fast. They use Comodo and Geotrust FWIW. I've had my own pain with Comodo through other resellers, and moved on to sslmate and godaddy. Recently moved my home blog (http://scalability.org http://scalability.org) to LE. Work (http://scalableinformatics.com http://scalableinformatics.com) is using godaddy for now, though thinking hard on using sslmate going forward for it (because ... godaddy).
- JoshTriplett 10y ago> EV certs can't be automated Not entirely, but Let's Encrypt could partially automate the verification process (e.g. looking up business entities and contacting their registered agent with an authorization code), and then fully automate obtaining a certificate with those verified credentials.
- derefr 10y ago(Not to sound like an advertisement, but) I got an email from StartCom the other day, saying that they're moving their StartSSL service to work on a similar policy to Let's Encrypt (which I hope means they're just running an ACME server)—but with the proviso that, since they do have the background-checking infrastructure required for EV "trust verification", they've combined the two. If I recall, StartSSL sort of hoists their EV identity-verification out into its own step before you actually apply for certs. The identity-verification process costs money (and it can't not; it involves paying real people to do background checks), but any EV certs issued to a verified identity are free. I think what this will mean is that, if you do an ACME request to StartSSL using an identity they've verified—and for a domain associated with that identity—then the cert in the response will automatically be an EV cert. This is pretty huge, in that usually EV certs cost a large amount per issuance—whereas a pre-verified ACME-issued cert effectively has zero marginal cost to reissue. Previously, EV certs were usually used only for apex domains, with a secondary DV cert collecting the internal SANs together—because the DV cert had a low (now zero) reissuance cost, while the EV cert cost the full amount each time to get reissued. Now you can just use your EV cert for everything, and alter it as suits you: much simpler. I hope other CAs adopt the same approach; it's a very good idea. (Pie-in-the-sky thought: maybe one day we'll have the equivalent of the semi-automated KYC service providers that have phone apps to scan drivers' licenses, but for corporations. Then issuing EV certs will just mean an API call.)
- pfg 10y agoUnfortunately, it doesn't look like they have plans to use ACME. They do have a public API (StartAPI) for issuance, which is better than nothing, but they definitely missed an opportunity with ACME, IMO. Mainly, being the first CA with OV/EV support that would also benefit from the existing ACME ecosystem (i.e. server auto-configuration). StartEncrypt, the equivalent of an ACME client for their API, appears to be a closed-source binary blob with no documentation whatsoever (based on what's visible on their product landing page and what's inside the downloaded files).
- djsumdog 10y ago...oh but they do. If you're in education and are an InCommon member, you get unlimited EV certs. It's pretty nice as you can add read certs to literally every server in your system and not have to abuse a *. cert. Hell you can even add real certs to every AD machine; no more creating your own CA and installing it via a group policy. That was back in 2012 when I worked for a University. Good luck getting those certs though. Their web service was so broken and if you ever asked for a 2nd cert it'd revoke the first one (which is great if you use them for e-mail encryption because now you can't read any of your old e-mails :-P .. that was more of an Outlook/GAL issue though). I really hate that InCommon was using Comodo considering all the shit they've done (like issue Google and Facebook certs to the Iranian government).