3 ms·
I use and like StartSSL for class one validation, which is free, though the class one certs are only for single hosts. (Don't forget to load the intermediate ce
by irons 16y ago
I use and like StartSSL for class one validation, which is free, though the class one certs are only for single hosts. (Don't forget to load the intermediate certificate in the web server config, or Firefox will act like there's no root cert loaded.)
Class two validation, supporting wildcart certs, is available, but requires high-resolution documentation of personal identity, resubmitted annually and kept on file outside my legal jurisdiction (Startcom is based in Israel), until seven years after the certificate's eventual expiration or revocation, which rounds up to forever.
I admire Start's model of charging only for actions that require human intervention, like identity validation, but I can't bring myself to have faith that their current trustworthiness precludes being acquired or compromised in the distant future. It's aggravating that organizational validation (for wildcard or EV certs) is layered on top of individual validation, meaning that an individual's ID always has to be on file.
- pudquick 16y agoAnd $50/2yr for wildcards from StartSSL is nothing to sneeze at! Very nice recommendation, will definitely be checking them out.
- growt 16y agoI use the StartSSL Wildcard/Class2 certificate and I'm quite happy with it. The validation process is really quick and easy: you send them a scan of your id/passport or similar and some grumpy guy from israel calls you and asks for your name and birthdate. I'm not that worried about a scan of my id-card getting lost, you have to provide that all the time.