3 ms·
Does anyone know if it's true that root CAs pay browser vendors to include their certs in the browsers by default?
by sr3d 16y ago
Does anyone know if it's true that root CAs pay browser vendors to include their certs in the browsers by default?
- ciupicri 16y agoMozilla CA Certificate Policy [1] doesn't seem to mention anything about money. You might also want to read "CA:How to apply" [2]. [1] http://www.mozilla.org/projects/security/certs/policy/ http://www.mozilla.org/projects/security/certs/policy/ [2] https://wiki.mozilla.org/CA:How_to_apply https://wiki.mozilla.org/CA:How_to_apply
- koenigdavidmj 16y agoIt is in the interest of browser vendors to do so, cash or not.
- chmike 16y agoIt depends. Some ask a payment others don't. They generally require an audit of the CA which is what is charged for. The audit is preferably done by an independent company specialize in such activity. CACert provide free certificates and are trying hard to get their root CA certificate approved. By the time it takes I assume it is very difficult.
- sr3d 16y agoDo you know any details about the auditing process that the independent company would perform of a CA? Since the whole signing SSL business is built around keeping a 256-byte or so private key private then this file would probably be protected pretty well.
- viraptor 16y agoHave a look at http://wiki.cacert.org/InclusionStatus http://wiki.cacert.org/InclusionStatus and follow the links in comments. There's a lot of information about different audits done and planned, lists of rules, discussions about what happened in the past, etc. Direct link to Mozilla rules is http://www.mozilla.org/projects/security/certs/policy/ http://www.mozilla.org/projects/security/certs/policy/
- morgs 16y agoIt's the WebTrust audit for Certification Authorities: http://www.webtrust.org/certauth_fin.htm http://www.webtrust.org/certauth_fin.htm (warning: PDF)
- morgs 16y agoComplying with the audit is costly - both in direct costs to the auditors, and in implementing the infrastructure and policies and procedures to pass the audit.
- heyrhett 16y agoI'd like to know how Mark Shuttleworth got the cert for Thawte included in Netscape (The company he later sold to Verisign for $575 Million). I think Verisign was willing to pay so much because his certs were already grandfathered into the browsers, and it was too hard to just pay the browser companies directly.
- jdbeast00 16y agoi thought he (or someone in his company?) was one of the original people on the mailing list that helped develop how certificates should work in browsers. just was a matter of right place right time.
- morgs 16y agoAFAIK it was him - having developed the first non-US 128 bit crypto capable SSL web server called Sioux (basically, Apache + SSLeay) he was on all the same mailing lists as the Netscape crypto guys. He then realised that the certs were more interesting than the web servers, and sold off Sioux to Stronghold so he could position Thawte as a CA instead of a software vendor. Then with the browser war on the go, MSIE3.0 copied Netscape Navigator, right down to the list of CAs included...
- morgs 16y agoIn 1999, Netscape started charging something like $100,000/year + $5000 per root cert, before there were any audit requirements. I think the idea was to weed out those who couldn't afford to run a CA worthy of browser inclusion. I'm no longer in the SSL industry but I'm not aware of Mozilla charging. Perhaps it was dropped when Mozilla spun out of Netscape and the WebTrust audit came on the scene.