9 ms·
Well shit. I always liked StarCom because of their approach to charge for verification (with increasing costs for each higher trust level) but not for issuing c
by ylere 10y ago
Well shit. I always liked StarCom because of their approach to charge for verification (with increasing costs for each higher trust level) but not for issuing certs (while still manually checking every cert request, at least for any OV&EV cert in my case).
This entire WoSign acquisition is incredibly shady. Shortly after that some of the customer reps had chinese names, service quality declined and we got offered to become an "Intermediate CA" (StartPKI) for 10k$/yr.
What is the best alternative CA that also offers wildcard certificates (preferably with a similar business model)?
- finnn 10y agoWhat use case do you have for wildcards that you can't use Let's Encrypt or similar automated issuance? Just curious, as I've yet to hear a terribly compelling one...
- ylere 10y agoLet's Encrypt cannot issue EV (green bar) certs, wildcard certs and certs with a validity longer than 90 days. While these are good features for many applications (i.e. a typical hosted website), there a lot of cases where that's not optimal: - EV (green bar) certs are required to increase customer trust (it may be mostly snakeoil, but the CA system is heavily flawed and we are still forced to rely on it anyway) - Applications where certs are used on other platforms than web servers (e.g. embedded devices, routers etc.) and 90-day renewals are not easy to implement in an automated way. - Wildcard certs are mostly useful for convenience reasons, e.g. to easily secure a changing number of hosts within certain (sub)domains/zones (especially when they are only or mostly used in internal networks). I agree that the need for wildcard certs is greatly reduced with let's encrypt and acme.
- seanot 10y agoI have a site that creates a subdomain for each new enterprise account and all subdomains relay on one StartCom wildcard cert. Ultimately, I can write a script to create a let's encrypt cert for each new subdomain but I've got plenty of other work on my plate at the moment.
- joepie91_ 10y agoMulti-tenant systems, for example, where each tenant gets their own subdomain. Let's Encrypt still has rate limits in place.
- dlgeek 10y agoNot the parent, but wildcard certs are necessary for compatibility with clients that don't support SNI (ex: IE on WinXP)
- xorcist 10y agoNo. You could also issue SubjectAltName certificates. Works fine with XP.
- BuildTheRobots 10y agoWhat would being an "Intermediate CA" actually mean in practise? Am I right in thinking I could generate my own certificates for any domain I wanted and have them validate in any browsers or devices that currently trust StartSSL/WoSign? Or to put it another way, would it give me the same powers as running my own internal CA but without the problem of convincing people to install my root-ca? I assume it _can't_ mean that, otherwise people would surely be up in arms (10k to mitm anyone is scarily cheap), so could someone educate me please?
- mcpherrinm 10y agoI'm not sure about this specifics here, but this is a feature offered by some CAs: They create a new intermediate, signed by their root, just for you. You then get to ask that CA to issue certs for you - and only you. You don't have total control over the intermediate -- as you suggest, that would let you mitm everyone. But by having an intermediate that you effectively control, you could have apps/devices/etc that trust only that intermediate (via pinning, HPKP, etc). That prevents a bunch of the possible downsides of using the public PKI (eg, a CA mis-issuing a cert for your domains), the downsides of pinning a leaf cert (because you can always issue another one off your intermediate if you change names, etc), and the downsides of a private PKI (because stuff that trusts the public PKI works too)