15 ms·
Another free CA as an alternative to Let's Encrypt
- lambda_obrien 6y agoHow do these services make money? edit: thanks for the replies!
- dewey 6y agohttps://letsencrypt.org/sponsors/ https://letsencrypt.org/sponsors/
- toomuchtodo 6y agoLet’s Encrypt is a non profit funded by donors, other vendors sell value add services (the free SSL cert is marketing/a loss leader). More options are good, Let’s Encrypt is mandatory to ensure good (or non predatory or oligopoly) behavior by other cert providers. It’s a check on their power.
- brunoluiz 6y agoLet's encrypt is not run for profit, and is sponsored by many companies. https://letsencrypt.org/about/ https://letsencrypt.org/about/ https://www.abetterinternet.org/ https://www.abetterinternet.org/
- Spivak 6y agoBut a more direct answer to the parents question is that they "make money" by providing a service that by virtue of its existence saves the sponsoring companies money and headache. I'm surprised this model isn't more common as an alternative to licensing.
- anonunivgrad 6y agoCollective action problem. You don’t have to sponsor to reap the benefits. You can pull it off for this or that cause celebre, but it’s not a workable model in general.
- 0df8dkdf 6y agowell when you are service that has to rely on them to renew your site every 90 days, the data alone from different site is worth money. “ The world’s most valuable resource is no longer oil, but data.” ~The Economist, May 6, 2017
- dewey 6y agoExcept that they (At least in LE's case) are funded by a lot of companies and donors and are not in it for the money. https://letsencrypt.org/privacy/#we-do-not-sell-your-data-or-information https://letsencrypt.org/privacy/#we-do-not-sell-your-data-or...
- hedora 6y agoWhat information can they (theoretically) gather beyond certificate renewal times (which can be inferred by any web scraper)?
- 0df8dkdf 6y agoWell you don't have to scrap it. And a centralised CA authority seems dangerous. I'm not saying LE is bad it one of good thing that came along. However, whenever we trust to one authority it alway gets dangerous. So yes I personally welcome another CA. However, don't think your data is or will not be used for something. Organization change, and people who runs the organization change.
- TheDong 6y ago> Well you don't have to scrape it Certificate logs from the certificate transparency project [0] are already public knowledge and shared freely. The only thing lets encrypt gets in addition to what's in those logs and publicly discoverable is what challenge you chose (dns or tls), and what email you're using. > So yes I personally welcome another CA More CAs generally means more chance that one CA loses a private key or has a vulnerability. Tragically, since browsers trust all CAs for all websites, if the new CA has an issue, people can forge TLS certs for my website even though I have no intention of ever using that new CA. In a very real way, having an excess of CAs is bad for the security of the entire internet. Letting anyone become a trusted CA would be an unequivocal disaster, so clearly more CAs isn't always good. I do think there's a balance, where we should have several viable CAs that we trust to be secure, but not 100s of them, just 10s. We already trust a ton more roots than that, so right now I see a new CA as being detrimental to security overall. That all being said, I'm pretty sure this CA is using an existing trusted root and processes, so since it doesn't require cross-signing in a new root, it's less big of a deal. [0]: http://www.certificate-transparency.org/how-ct-works http://www.certificate-transparency.org/how-ct-works
- abcleb 6y agoDo they sell the private keys to the NSA? Maybe not. It is an effort by many companies and groups to make the web more secure.
- hu3 6y agoLet's imagine they do sell private keys to state actors (which I highly doubt). Would that allow transparent sniffing of traffic encrypted with these certs?
- AgentME 6y agoMost HTTPS connections today negotiate ephemeral keys at the start of the connection, so even if an attacker has the server's private key (which the CA never sees and couldn't sell!), the attacker can't do passive listening attacks on connections using it. The attacker would have to do an active man-in-the-middle attack that rewrites the connection and swaps out the ephemeral keys with keys known to the attacker, which risks detection. If an attacker has the CA's private key, then the attacker can mint new HTTPS certificates. They wouldn't be able to do passive listening attacks on connections, but they could use an active man-in-the-middle attack to swap out the server's certificate in the connection. However, this attack could be detected through Certificate Transparency, and the CA's leaked keys would become untrusted by browsers.
- blibble 6y agothey couldn't sell your private keys to the NSA as they don't have them as they're generated locally on your machine and never leave it they could sell their keys, but impersonations would likely be spotted thanks to certificate transparency
- huhtenberg 6y agoThey don't see the private keys.
- cocoa19 6y agoThey can't sell the keys since they don't have them. NSA could still mount an attack by asking the CA to register NSA's certs as valid, and tamper the victim's network connection. What makes certs secure is our trust in certificate authorities.
- cordite 6y agoThis links to ZeroSSL. They only offer 3 domains for free on their pricing page. https://zerossl.com/pricing/ https://zerossl.com/pricing/
- richardwhiuk 6y agoPlus no wildcard support (which Let's Encrypt provides). They say "No REST API access" - but presumably ACME does work?
- edoceo 6y agoWhat! LE does wildcard now!? /me searches... https://community.letsencrypt.org/t/acme-v2-production-environment-wildcards/55578 https://community.letsencrypt.org/t/acme-v2-production-envir...
- zymhan 6y agoOh yes, it's a lifesaver.
- rohansingh 6y agoYeah, looks like ACME is indeed free and includes wildcards: https://zerossl.com/letsencrypt-alternative/ https://zerossl.com/letsencrypt-alternative/
- jakobmartz3 6y agoonly 3???
- surround 6y agoIt says “no credit card required.” Can they stop people from making multiple accounts and getting unlimited certificates?
- gtirloni 6y agoThrottling
- geocrasher 6y agoAnother player in this market is Sectigo. They are providing cPanel branded free SSL certificates to cPanel servers. Some hosts have switched to these because of API rate limiting done by Let's Encrypt. Mind you, it's specific to cPanel (a web hosting control panel) but that is a giant market.
- mholt 6y agoZeroSSL is a Sectigo reseller.
- swiley 6y agoThe only time I've ever had a machine owned was through a borken cPanel installation our professor forced on us. I'm still not sure what it does that I couldn't do with a normal ssh session.
- geocrasher 6y agoIt's not for people like you. It's for hosts doing mass amounts of hosting for people who couldn't get a directory listing at a bash prompt if their life depended on it.
- swiley 6y agoOSX at least used have support for opening sftp (that is, file transfer over ssh) URLs in finder. You don't need to know bash to use ssh.
- jeremiahlee 6y agoNow, one of them just needs to provide certs for .onion domains.
- SalimoS 6y agoIsn’t the hash ( before the . Onion) is the public key ? So technically we don’t need a cert for onion
- milkey_mouse 6y agoYou're correct, but I recall a Tor dev saying at one point that HTTPS for .onion wasn't completely useless, I think in that more secure settings (CSP, etc.) apply to pages loaded with HTTPS.
- jeremiahlee 6y agoThe Tor Project discussed the advantage a little in this blog post ("Part four: what do we think about an https cert for a .onion address?"): https://blog.torproject.org/facebook-hidden-services-and-https-certs https://blog.torproject.org/facebook-hidden-services-and-htt...
- surround 6y agoSome onion websites use the certificate as an anti-phishing measure. Since onion domains are hard to remember, a certificate can verify that you are, indeed, connected to e.g. Facebook’s servers and not a phishing website.
- bawolff 6y agoPresumably worked a lot better when EV certs got the fancy UI
- lights0123 6y agoThat's EV though, and it looks like DigiCert is the only one that does it for .onion: https://crt.sh/?Identity=%25.onion https://crt.sh/?Identity=%25.onion They do offer ACME though: https://docs.digicert.com/certificate-tools/Certificate-lifecycle-automation-index/acme-user-guide/ https://docs.digicert.com/certificate-tools/Certificate-life...
- deleted 6y ago[deleted]
- surround 6y agoUnlike LetsEncrypt, it supports certificates for IP addresses, which is nice for hobbyists who don’t want to buy a domain.
- scaladev 6y agoWhy would you necessarily buy a domain? I use lots of free domains in .tk and .cf, they work great. https://freenom.com/ https://freenom.com/ For frequently changing IPs there are also services like http://duckdns.org http://duckdns.org which provide you with a third-level domain like xyz.duckdns.org
- surround 6y agoWhy get a domain, if you don’t need one? The free .tk domains are only free for 1 year. And even if you are only going to use it for a year, some people would rather not give out their credit card number for a free trial.
- scaladev 6y agoPlease stop spreading misinformation. You don't need a card, you don't have to provide any identification at all. The domains are free for as long as you want (I've been using one for the last 3 years), you just have to click a button once a year, and freenom sends you emails two weeks in advance.
- spurgu 6y agoCorrect. I just got one with a fake name and address, no phone number needed, nor a credit card.
- surround 6y agoPerhaps I’m mistaken, but I believe at one point in time, years ago, they required a card for the free registration. It certainly wasn’t my intent to spread misinformation. Now I’m wondering, how does Freenom make money?
- mholt 6y agoHere is a maintained list of all known, public ACME endpoints: https://docs.https.dev/list-of-acme-servers https://docs.https.dev/list-of-acme-servers In Caddy 2.3, Caddy [1] will default to both Let's Encrypt and ZeroSSL [2]. If it can't get a cert from one, it will try the other. You can configure more too, including self-signed certs, as a last fallback for example. Caddy will be the first web server and ACME client to support multi-issuer fallback. (Pre-releases coming soon, or you can build from source and try it today.) ZeroSSL's website is being updated to clarify that certs are free and unlimited through ACME. You can even view them in your ZeroSSL dashboard. [1]: https://caddyserver.com https://caddyserver.com [2]: https://github.com/caddyserver/caddy/pull/3862 https://github.com/caddyserver/caddy/pull/3862
- bxk1 6y agoFor anyone else wondering why they use ZeroSSL as a fallback: "Caddy has been acquired by the company behind ZeroSSL"
- mholt 6y agoTrue, that's one reason, but I've been planning this feature for years and would have implemented it either way. As explained in the linked pull request: - Let's Encrypt is a busy non-profit organization. We can help maximize their budget by not using it as the exclusive default for every server. - ZeroSSL does not have rate limits and is also publicly trusted. And yes, it is free to use it with ACME. - ZeroSSL offers a graphical dashboard where you can log in and see and download your certificates. - Having more than just 1 free ACME CA is a very, very good thing for the PKI ecosystem. This is the beauty of standardization; if you give a server a URL, you can give it two and three and four, and not have to worry about global reliance on a single source.
- HeroSSL 6y agoPlease have or be or create my babies. Dang be fucked, I bypassed the commenting cocksuckery! Lucky for me.
- 6y ago
- certera 6y ago> Why not just use Let's Encrypt? ZeroSSL comes with significant advantages compared to Let's Encrypt, including access to a fully-featured SSL management console, an REST API for SSL management, SSL monitoring, and more. This is where I shamelessly plug my project, Certera: https://docs.certera.io https://docs.certera.io I love LE, like really really love it. I was surprised to hear that certs were going from 2 to 1 year expiration and that made me really pause for a second to think about the lack of proper infrastructure around certificates, especially LE certs. I envision these short lived certs from LE/ZeroSSL needing some of the components that ZeroSSL mentioned above and much, much more. Eventually, if/when we have 1 week/1 day cert expirations, we'll need a certificate exchange system to better handle complex scenarios where other parties are involved (i.e. when doing client certs, SAML certs, etc.).
- ryan29 6y agoI've looked at setting that up for my home lab a few times and when reading the docs I always get hung up on one thing. How do I retrieve certificates on my servers? Do I have to use the Certera API for that? What I'd like to have is an ACME compatible endpoint so I can change the ACME endpoint in my Traefik config to `https://acme.certera.example.com https://acme.certera.example.com` and not have to make any other significant changes. Basically I'd like to have an ACME proxy with a dashboard like Certera.
- certera 6y ago> How do I retrieve certificates on my servers? Do I have to use the Certera API for that? Yes, and it's very simple & basic. A single CURL to get it like so: curl https://<your_certera>/api/certificate/<cert_name> https://<your_certera>/api/certificate/<cert_name> \ -H "apiKey:<your_api_key>" You can pipe that out to a file directly as it's in PEM format by default. More info here: https://docs.certera.io/#certificates-api https://docs.certera.io/#certificates-api The thing that's unique about Certera is that it's not opinionated on your existing setup. It doesn't care whether it's Traefik, apache, nginx or IIS. The "glue" is a standard PEM file format, the way it should be. It's up to you how to tell whatever system cares about the PEM and do the "reload" of the cert. I'm not sure how Traefik would communicate with it as I'm not familiar with Traefik in general. I'm assuming that you'd like Traefik to simply say: "gimme the cert for xyz domain" and have some endpoint/system take care of the rest, right? Don't hesitate to create an issue in GitHub and we can discuss further. Sometimes I lose track of HN comments due to a lack of notifications.
- jamescun 6y agoProbably just an oversight, but I find it odd their (ZeroSSL) site does not use a certificate issued by their own CA, it is instead one of CloudFlare's SNI certificates.
- mholt 6y agoThis is common for sites that are behind a TLS-terminating CDN. (They could still be using one between their origin and Cloudflare.) In general it doesn't matter who issues the certificate as long as they're trusted.
- snazz 6y agoIt's also worth mentioning that you can give Cloudflare your own certificate to use if you care what users see. I think this option might require one of the paid Cloudflare plans.
- jamescun 6y agoYou are correct, however CloudFlare does support supplying your own certificate, and I'd consider it an element of dogfooding to use their own CA on their own site.
- Xylakant 6y agoNote that you’d either need to hand cloudflare the private key for the cert or use their key server and run it on your infrastructure. You’ll also need to manage the certificates lifecycle. Unless you have a very compelling reason to do so, I doubt it’s worth the effort.
- analyte123 6y agoIt's good that there are alternatives, particularly those that are outside the scope of US law, where at least some CAs believe certificates can be revoked for copyright reasons [1]. Let's Encrypt says they can revoke your cert if "our Certificate is being used, or has been used, to enable any criminal activity...[or] ISRG is legally required to revoke Your Certificate pursuant to a valid court order issued by a court of competent jurisdiction" [2]. But I'm sure Austria where ZeroSSL is based is still party to a number of copyright conventions and law enforcement data sharing agreements. [1] https://torrentfreak.com/sci-hub-pirate-bay-for-science-security-certs-revoked-by-comodo-ca-180503/ https://torrentfreak.com/sci-hub-pirate-bay-for-science-secu... [2] https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf https://letsencrypt.org/documents/LE-SA-v1.2-November-15-201...
- DyslexicAtheist 6y ago> But I'm sure Austria where ZeroSSL is based is still party to a number of copyright conventions and law enforcement data sharing agreements. it is!! in recent news: https://news.ycombinator.com/item?id=25091994 https://news.ycombinator.com/item?id=25091994
- gsich 6y agoBuypass is Norwegian.
- stephenr 6y agoIt’s been mentioned zerossl is a reseller for “sectigo”, which is the new name for Comodo. Comodo are the bunch of cunts who tried to trademark “let’s encrypt”. There’s zero reason to give them any market share or business.
- 1MachineElf 6y agoThanks, I wasn't aware of ZeroSSL's history there. Are there any links you can share about that fiasco?
- stephenr 6y agohttps://en.wikipedia.org/wiki/Comodo_Cybersecurity#Let's_Encrypt_trademark_registration_application https://en.wikipedia.org/wiki/Comodo_Cybersecurity#Let's_Enc...
- nickf 6y agoTo be clear, Sectigo was split from Comodo by PE. They are separate companies. The CEO at Comodo who did the LE trademarking attempt hasn’t been a part of Sectigo and the CA for 3 years. Sectigo have also worked with LE and helped to sponsor the CT log they operate. It may not change your opinion, but it’s important to be aware of the details.
- stephenr 6y agoGood to know.
- quesera 6y ago> Comodo are the bunch of cunts Ugh, surely you're aware of how poorly that word, as an epithet, lands for most of the English-speaking population. Your message is worth hearing. It will be lost if you can't communicate it well.
- stephenr 6y ago
- tashian 6y agoThe ACME protocol (used by Let's Encrypt / ZeroSSL) can be used with internal infrastructure, too. I know that some folks already use Let's Encrypt to issue internal TLS certificates, but that's not always ideal. Step CA[1] is an ACME v2-compliant, open source CA that supports all of the challenge types as Let's Encrypt / ZeroSSL. [1]: https://github.com/smallstep/certificates/ https://github.com/smallstep/certificates/
- freedomben 6y agoNice, thanks for the tip! I've needed something like this a few times the last few months and knew there had to be something out there I was missing. This looks awesome.
- tialaramex 6y agoNote that this only really makes sense if you're using tooling that already came with ACME support, and so this drops in easily. I guess that's becoming pretty common though. Older tools might support technologies like SCEP but not ACME. These older protocols can't be used (on their own) to get certificates trusted in the Web PKI because the whole point of ACME is to do the proof-of-control step needed to get those certificates. But in your private PKI you likely don't need or even want that feature. I guess it can make sense for new software that is at least sometimes for public access to just do ACME, but it does feel like maybe Smallstep should have a legacy SCEP mechanism available. I see there is a GitHub ticket for that so no need to raise it again.
- Arnavion 6y agoThese days private PKI probably uses EST instead of SCEP.
- francislavoie 6y agoCaddy actually ships with smallstep CA built in, and can act as an ACME server for mTLS. https://caddyserver.com/docs/caddyfile/directives/acme_server https://caddyserver.com/docs/caddyfile/directives/acme_serve... You can have Caddy instances that act as ACME clients to one that acts as the ACME server and load balancer. Read more about using it here: https://caddy.community/t/what-does-embedded-acme-server-do/8589/2 https://caddy.community/t/what-does-embedded-acme-server-do/...
- unixhero 6y agoWhy is this needed? Genuinely curious.
- the8472 6y agoeggs, when the basket fell
- CyanLite2 6y agoWanted: free CA that offers longer than 90 day certs
- yreg 6y agoApple already distrusts certs older than 398 days[0], no matter what the issuer says. I can see this lifespan only decreasing. [0] https://support.apple.com/en-us/HT211025 https://support.apple.com/en-us/HT211025
- gsich 6y agoBuypass https://www.buypass.com/ssl/products/acme https://www.buypass.com/ssl/products/acme
- francislavoie 6y agoShorter lifetimes are better. There's really no valid reason to make them longer. Upgrade your tooling to automate renewals, and it's no longer a problem.
- theandrewbailey 6y agoWhy? Changing web server certs/keys should be painless.
- qurashee 6y agoThis reminded me the beginning of Spot/Exceed https://www.youtube.com/watch?v=2qbAfyF6IIc https://www.youtube.com/watch?v=2qbAfyF6IIc and Contour/TBL, both classic demos now.
- peterwwillis 6y agoBrings up an interesting question: Why do we need a Let's Encrypt to issue a TLS certificate? At what point can we stop using them? PKI in a nutshell: the CA signs your CSR which was created with your private key; the CA gives you a cert based on your CSR; you show random people a website using your private key + CA-signed cert; random person's browser trusts your private key+CA-signed cert content because their browser trusts the CA-signed stuff implicitly. Why we need more than 1 of them: in case one of them goes down and so we can't get new certs; in case one gets compromised and the browser revokes their trusted CA cert; diversity of "features". What could we do instead of this process? Idea 1: the registry becomes the CA. Why? To get a cert, you have to prove you are allowed to have it. Currently that almost always involves proving that you currently control the IP space that is pointed to by a DNS record. There are other verification methods which are somewhat more problematic than this, but this is the simplest method. And if you can find one single CA which will create you a cert if you can do this, that means that if anyone can do it, they can get a cert. Meaning that this verification method is the minimum security barrier for getting a valid cert. How can an attacker to subvert this process to generate a valid cert for any domain? Options: 1) Take over the domain, by hacking the domain's account at the registrar. 2) MITM the registrar, such that updates to the registry's NS end up controlled by the attacker. 3) Take over the domain, by hacking one of the domain's nameservers. 4) Perform a DNS hijack, such as cache poisoning, so when the CA looks up your domain to find the IP space, you return attacker IP space. 5) Perform a BGP hijack so when the CA tries to connect to the IP space, it connects to attacker-controlled IP space. 6) Plenty of others based on other validation methods such as DNS record alone, HTTP [no S] content, a pre-configured list of e-mails for a domain, etc. How to prevent all but one of these attacks? Option A: Make the registrar the CA. The registrar would simply request the user use an HTTPS API to request a new cert, using an API token generated by the login for the domain's account. The only way for an attacker to generate a cert at that point is to either hack the registrar account, or hack the customer's server to get the API token (basically the same impact as if they compromised the customer's web server). The browsers would trust the registrars who would follow the exact same stringent guidelines that CAs use today. The difference to the end-user is the CA is run by the registrar. Option B: The registrar and the CAs stay independent, but they use a standard secure protocol to authorize signing of certs using a customer API token. Same benefits, but an extra hop. Browsers continue working as before, users use an HTTPS API to the CA to generate the certs. With either options A or B, there's no more stupid hoops to jump through just to prove you own the domain and thus deserve a certificate.
- encom 6y agoSo, Scott's car blog started writing about encryption again? Nice.
- M2Ys4U 6y agoThis looks like it's only for personal and non-public certs in a commercial context. From their Terms and Conditions: " ZeroSSL is for your personal or internal business use only and must be in compliance with all applicable ZeroSSL policies, laws, rules and regulations. As well as this, no third party rights can be violated or infringed upon through use of ZeroSSL. You may not use ZeroSSL for any commercial purpose including but not limited to selling, licensing, providing services, or distributing ZeroSSL to any third party unless you have received the express written consent of ZeroSSL beforehand." https://zerossl.com/terms/ https://zerossl.com/terms/
- deleted 6y ago[deleted]