6 ms·
Now that LetsEncrypt exists there's no excuse for anyone to use StartCom. They've had a whiff of dodginess for ages, and their customer service is among the rud
by ascorbic 10y ago
Now that LetsEncrypt exists there's no excuse for anyone to use StartCom. They've had a whiff of dodginess for ages, and their customer service is among the rudest I've known. This should be the final straw. Their root needs removing from browsers. Give their existing customers a year's warning.
- bkor 10y agoWildcard domains aren't supported by Let's Encrypt last I checked. StartCom provided GNOME with a free account which can create certificates (including the wildcard ones and so on). Those are pretty much mandatory in certain cases (secure Bugzilla attachment hosting).
- creshal 10y ago> Wildcard domains aren't supported by Let's Encrypt last I checked. But with ACME, the need for wildcard certs is strongly reduced. If you don't need dynamic, on-the-fly subdomain creation, it's trivial to have Let's Encrypt generate certs with all the subdomains you need (especially now that the limits are much higher than during beta).
- sirn 10y agoI believe that's exactly the use case of secure Bugzilla attachment hosting the OP mentioned. IIRC, it will generate the subdomain on the fly using ticket ID in the form of bug12345.bugzilla.example.com to host the attachment.
- creshal 10y agoAh, interesting. Haven't worked with Bugzilla for years, didn't know they added this.
- bruo 10y agoI agree with you, there is no alternative to StartCom right now in wildcard certs. While GNOME got a free account to get those certs, the last time i checked is still the cheapest way to get wildcard certificates (60 usd for unlimited wildcard certs). It also removes the complexity of having to deploy let's encrypt certificates every X months without storing the LE's account key online. But if they release certificates for anybody claiming to be you there is no advantage in this area.
- SEJeff 10y agoI actually asked Eddy Nigg (startcom CTO) to do the gnome deal and give us ssl certs for free (back when I was able to ssh/irc from work and be a member of the GNOME Sysadmin Team), which they did. As much hate as they get, they are one of the few "secure" CAs of all of them I've ever worked with. One of the more quiet things when it was first revealed Comodo was hacked was that Startcom was also hacked. Eddy went on the record as bragging not a single rogue SSL certificate was issued as they have a human validate every single certificate request (yes seriously) and that prevented any rogue certificates. So as much as people think Startcom is scummy, they are actually pretty decent people. They're also quite secure. So YMMV. This was long before the alleged sale to china though, maybe 5-8 years ago? I forget.
- BillinghamJ 10y agoThey definitely don't visually check every cert any more. They're issued instantly.
- SEJeff 10y agoOh I wasn't referring to their lame knock off letsencrypt product, but their main ssl cert.
- BillinghamJ 10y agoTheir normal ones are issued instantly also.
- agwa 10y agoGlobalSign gives free wildcard certificates to open source projects: https://www.globalsign.com/en/company/press/061913-globalsign-offers-free-ssl-certificates-open-source-projects/ https://www.globalsign.com/en/company/press/061913-globalsig...
- Jaruzel 10y agoI know I'm in the minority on here, but... LetsEncrypt's certs are not trusted on Blackberrys (including BB10 devices), and because Blackberry's big thing is 'a secure OS' there's no way to side-load[1] a root cert. Although dwindling rapidly - there's still some big business out there that are still issuing Blackberrys to it's users. My main home server is behind a StartCom cert... and I use a BB10 device - so no LetsEncrypt migration for me :( -- [1] Happy to be corrected on this, If I'm wrong!
- koolba 10y ago> LetsEncrypt's certs are not trusted on Blackberrys (including BB10 devices), and because Blackberry's big thing is 'a secure OS' there's no way to side-load[1] a root cert. > Although dwindling rapidly - there's still some big business out there that are still issuing Blackberrys to it's users. What business are you in that Blackberry users are a factor? What percent (or total number of users) would be impacted? Only time I've seen a Blackberry in recent memory is as a stock image on a "Why RIM failed..." article.
- Jaruzel 10y agoBelieve it or not - Large Financial still roll out BBs, mainly because they have a big investment in the BES backend, and don't want to replace it unless they absolutely HAVE to. Latest version of BES (v12) supports iPhone and Android now, but it's not as complete as native BB support. My Blackberry is personal though (I love hard keyboards!).
- kstrauser 10y agoThat's a pickle to be in. Until LetsEncrypt is trusted on BB, you might consider switching to a different traditional CA. For example, Namecheap resells Comodo certs for $9 per year: https://www.namecheap.com/security/ssl-certificates/domain-validation.aspx https://www.namecheap.com/security/ssl-certificates/domain-v... . That's what I was using on my personal domains until LetsEncrypt came around. If you can afford a home server, $9 is cheap. It's way cheaper than what StartCom will charge you to revoke your cert if you ever need to (security breach, the next heartbleed, etc.). In fact, StartCom's terrible handling of heartbleed is what prompted me to switch from their free-but-expensive certs to Namecheap/Comodo's paid-but-cheap service.
- lucb1e 10y agoTheir customer service is rude. But they're giving you free certificates, and they have customer service. That's already better than what you get when you pay for Google services or have a Windows license and run into Windows problems or something. Lesson of the day: public perception of customer support is important. Rude support worse than no support at all. Noted.
- ascorbic 10y agoI've had terrible service when paying them hundreds of dollars. There's no correlation.