4 ms·
Apart from the reasons posted earlier, "legacy" also comes into play. Symantec acquired the CA business from the old VeriSign in 2010, which back then was the
by asclepi 10y ago
Apart from the reasons posted earlier, "legacy" also comes into play.
Symantec acquired the CA business from the old VeriSign in 2010, which back then was the largest CA and had a large corporate client portfolio accustomed to paying $$$$ per certificate per year. Corporations can become very reluctant to change, even if it benefits them, and there are some who just pay up every year without researching alternatives or even being aware of any.
You will find that there are a lot of similarities with the domain name industry where there is also a company operating with a VeriSign heritage: Network Solutions. Network Solutions also charge premium prices, because their legacy customers expect those. And although market share is slowly eroding over the years and cheap (and even free) competitors rise, more than enough legacy customers stay on board to remain very profitable for many years to come. What definitely helps is that most of the processes in the domain registration and CA industries can be automated and don't need a lot of maintenance.
- yuhong 10y agoAnd they tends to need legacy stuff such as SHA-1 certificates more often.