15 ms·
What do you think is a realistic estimate to get a new CA off the ground? Just the minimal cost for hardware and audits and whatnot to create the required artif
by mmalone 7y ago
What do you think is a realistic estimate to get a new CA off the ground? Just the minimal cost for hardware and audits and whatnot to create the required artifacts and get them into the three major root programs. Not including staff and ongoing operational expenses (I can estimate that myself). I’ve heard it can be done for as little as $250,000.
Also, timeline. It took Let’s Encrypt a couple years to get in root programs and have good penetration, right? Would it be faster or slower now?
If someone was willing to undergo this ordeal and could secure funding so it wouldn’t split the philanthropic community and affect LE, would LE be willing to cross-sign (once they’re in good standing) to get them off the ground, the way IdenTrust did for the ISRG roots?
Asking for a friend ;)
- Ayesh 7y agoNot much: https://bugzilla.mozilla.org/show_bug.cgi?id=647959 https://bugzilla.mozilla.org/show_bug.cgi?id=647959 It's not about the money, either. LetsEncrypt had their intermediate certificates cross-signed by IdenTrust, otherwise they wouldn't have the 30% market share. It takes a lot of time with the CA application process. You will need to convince Microsoft, Apple, Mozilla, Java, etc that you will be a good CA with good practices. Multiple security audits (starting at about $40K... KPMG don't come cheap), hardware (HSM, servers for validation, OCSP, CT, etc) and people (needs to be trusted people, and often are paid top dollars). It's easy to _buy_ a CA than creating one. You can get your new root certificates included later easily now that you have a root already, from which you can cross-sign until they are included. CAs are sold out more often than many of us think.
- mmalone 7y agoThat link is amazing. Thank you for that. Yea I have a pretty good idea of what’s involved. None of that is impossible to do. Time consuming? Sure. Impossible? Far from it. The root programs have documented processes to get included and will (eventually) accept a legit new CA that’s passed WebTrust audit and has good practices (afaik). Hardest thing is finding someone to cross-sign to accelerate the process. That’s why I asked jaas if he would do so :P. I run a company that does public key infrastructure stuff (smallstep.com) so I have the software and some of the people. I think I could track down some hosting and a couple operators from a partner or two. What’s left seems like maybe a few hundred thousand a year for audits and HSMs, mostly. Pretty sure I could scrape that together too. Idunno though. Mostly it’s Friday night and this is a fun thought experiment. Good thought on buying an existing CA. Are any currently up for sale, I wonder? If anyone who reads this knows, plz email me (mike at smallstep).
- nickf 7y agoLE are pretty open about their expenses, ~$3.6m a year currently, if I remember correctly. They got bootstrapped with a cross-signing from IdenTrust and so were able to get off the ground fairly quickly. That won't have been cheap, and I'd be very surprised if anyone would offer the same service now - there's some pretty big risks associated with it. Getting a new trusted CA off the ground is slow and expensive, sadly, and of course you can't really issue anything 'trusted' until you get a critical mass of browsers and OSs to include and distribute the root. Of course it's quicker now than it used to be, with automated updates and better update cadence. You'll still have problems in some areas (embedded devices, older Android devices). Funny how a project can have problems because there's a ton of customers with 'smart' TVs that only support old roots and have no update mechanism... Buying a CA or an existing root is the best way for now, probably. Not cheap. Amazon and Google both did this (roots from GoDaddy and Globalsign respectively). Not sure if any are for sale at the moment, but it would never hurt to ask - although the pricetag might be scary! (Disclosure: I've been doing this over 16 years, at one of the larger CAs. nick -at- sectigo -dot- com)
- Ayesh 7y agoConsidering the amount of VC money being burnt every day by some startups with no future, this $3.6m is well spent.
- Ayesh 7y agoI would try contacting some of the lesser known CAs. Those who voted "No" on recent CA/B forum ballot to reduce certificate lifetime are probably having some hard time keeping up with ACME, and might as well sell the business. A root valid for next 3-4 years gotta do because Android updates are faster now and current shitty IOT devices and "smart" devices would be dead by then. In recent Symantec sellout to Digicert, it looks like the more pressure a CA has, more likely it would be to buy them out. It's gotta cost in millions though I suppose.
- atmosx 7y agoIf convincing about security best practices was hard, Comodo along with GoDaddy and many other providers would be out of the market.