3 ms·
That link is amazing. Thank you for that. Yea I have a pretty good idea of what’s involved. None of that is impossible to do. Time consuming? Sure. Impossible?
by mmalone 7y ago
That link is amazing. Thank you for that.
Yea I have a pretty good idea of what’s involved. None of that is impossible to do. Time consuming? Sure. Impossible? Far from it. The root programs have documented processes to get included and will (eventually) accept a legit new CA that’s passed WebTrust audit and has good practices (afaik). Hardest thing is finding someone to cross-sign to accelerate the process. That’s why I asked jaas if he would do so :P.
I run a company that does public key infrastructure stuff (smallstep.com) so I have the software and some of the people. I think I could track down some hosting and a couple operators from a partner or two. What’s left seems like maybe a few hundred thousand a year for audits and HSMs, mostly. Pretty sure I could scrape that together too.
Idunno though. Mostly it’s Friday night and this is a fun thought experiment.
Good thought on buying an existing CA. Are any currently up for sale, I wonder? If anyone who reads this knows, plz email me (mike at smallstep).
- nickf 7y agoLE are pretty open about their expenses, ~$3.6m a year currently, if I remember correctly. They got bootstrapped with a cross-signing from IdenTrust and so were able to get off the ground fairly quickly. That won't have been cheap, and I'd be very surprised if anyone would offer the same service now - there's some pretty big risks associated with it. Getting a new trusted CA off the ground is slow and expensive, sadly, and of course you can't really issue anything 'trusted' until you get a critical mass of browsers and OSs to include and distribute the root. Of course it's quicker now than it used to be, with automated updates and better update cadence. You'll still have problems in some areas (embedded devices, older Android devices). Funny how a project can have problems because there's a ton of customers with 'smart' TVs that only support old roots and have no update mechanism... Buying a CA or an existing root is the best way for now, probably. Not cheap. Amazon and Google both did this (roots from GoDaddy and Globalsign respectively). Not sure if any are for sale at the moment, but it would never hurt to ask - although the pricetag might be scary! (Disclosure: I've been doing this over 16 years, at one of the larger CAs. nick -at- sectigo -dot- com)
- Ayesh 7y agoConsidering the amount of VC money being burnt every day by some startups with no future, this $3.6m is well spent.
- Ayesh 7y agoI would try contacting some of the lesser known CAs. Those who voted "No" on recent CA/B forum ballot to reduce certificate lifetime are probably having some hard time keeping up with ACME, and might as well sell the business. A root valid for next 3-4 years gotta do because Android updates are faster now and current shitty IOT devices and "smart" devices would be dead by then. In recent Symantec sellout to Digicert, it looks like the more pressure a CA has, more likely it would be to buy them out. It's gotta cost in millions though I suppose.