5 ms·
I assume they are more trusted by older devices than Let's Encrypt. Source?
by crazypython 5y ago
I assume they are more trusted by older devices than Let's Encrypt. Source?
- gregoriol 5y agoNot sure its reliable but I've found this comparison: https://www.xf.is/2020/06/30/list-of-free-acme-ssl-providers/ https://www.xf.is/2020/06/30/list-of-free-acme-ssl-providers...
- Deathmax 5y agoZeroSSL's current RSA intermediate is https://crt.sh/?id=2427368505 https://crt.sh/?id=2427368505, which chains up to USERTrust RSA Certification Authority (https://crt.sh/?caid=1167 https://crt.sh/?caid=1167). I was going to migrate over to ZeroSSL, but there were red flags in the form of missing documentation that you would expect from a CA, like what is the chain of trust for certificates that are being issued? If I have to issue myself a certificate to check which CA is being used to sign the cert, that doesn't feel right.
- tialaramex 5y agoI suspect there is no source that tracks exactly what's trusted on a large range of devices. Perhaps somebody should maintain this information, although it seems like a really thankless volunteer task, I'm really interested in such stuff and still it makes me feel tired just thinking about it.
- barbazoo 5y agoIs there a range of trust? AFAIK you either trust a cert (directly or transitively) or not.
- tialaramex 5y agoThere aren't degrees of trust in the system, but it is common for more sophisticated systems to have conditional or constrained trust. For example https://wiki.mozilla.org/CA/Additional_Trust_Changes https://wiki.mozilla.org/CA/Additional_Trust_Changes or Microsoft's "NotBefore" constraint in newer versions of their operating system (not to be confused with the "notBefore" parameter in an X.509 certificate itself).
- cmeacham98 5y agoI think what they meant was "I assume they are trusted by [more] older devices..."
- currysausage 5y agoRelevant for Apple OSs: https://support.apple.com/en-us/HT209143 https://support.apple.com/en-us/HT209143 "Buypass Class 3 Root CA", which appears to be the root certificate they currently use, is present for all listed iOS versions (7+), which seems like a good sign. Let's Encrypt's "ISRG Root X1" is present in iOS 10+. Similar lists for Android would be wonderful but probably impossible to compile due to ecosystem fragmentation. I guess there is no caniuse.com for root certificates.
- gregoriol 5y agoThanks, interesting page! ZeroSSL seems to have their chained "AAA Certificate Services" in the list for iOS 7 (until 2028)