7 ms·
Ask HN: What's the best company to buy SSL certificates from?
- tyrelb 15y agoname.com
- citricsquid 15y agoWhat's your goal? There are all types of certificates, some cheap and some expensive. If you're aiming for cheap, companies like Namecheap and GoDaddy sell them for peanuts but they're "cheap" certificates, not with bells and whistles.
- Mavyrk 15y agoIs there a chance you could elaborate on this some? What would some example "bells and whistles" be with regards to SSL certs?
- XERQ 15y agoVerisign EV certs get the green text along with the name of the company in the browser (ex: https://paypal.com https://paypal.com) More information: http://www.verisign.com/ssl/ssl-information-center/extended-validation-ssl-certificates/index.html http://www.verisign.com/ssl/ssl-information-center/extended-...
- gnu8 15y agoAll EV certificates provide that feature, not just the ones sold by Verisign. Are you a paid shill of Verisign? In general, no one should ever do business with Verisign, due to their practice of domain slamming, their Site Finder misfeature, and other shady practices.
- GFischer 15y agoDo they still do that? Thanks for pointing that out though, I found this: http://www.theregister.co.uk/2002/05/14/verisign_hit_with_slamming_lawsuit/ http://www.theregister.co.uk/2002/05/14/verisign_hit_with_sl... through Wikipedia: http://en.wikipedia.org/wiki/Domain_name_scams#cite_note-6 http://en.wikipedia.org/wiki/Domain_name_scams#cite_note-6 "VeriSign was sued in 2002 for their actions in sending ambiguous emails informing people, often incorrectly, that their domain was about to expire and inviting them to click on a link to renew it. Renewing the domain resulted in the registration company being transferred to VeriSign from the previous registrar."
- smountcastle 15y agoVerisign cannot do that anymore since they no longer operate a registrar (Network Solutions was spun-off/sold-off).
- GFischer 15y agoOk, I didn't know that. What I should investigate is whether the same people that authorized those shady tactics are still in charge there (or whether that culture persists).
- GFischer 15y agoGoDaddy is listed among the issuers of EV certificates on Wikipedia, so don't they offer them? : http://en.wikipedia.org/wiki/Extended_Validation_Certificate http://en.wikipedia.org/wiki/Extended_Validation_Certificate (I don't know the difference between standard SSL certificates and EV ones)
- DanManAz 15y agoGoDaddy does look like they offer them: http://www.godaddy.com/ssl/ssl-extended-validation.aspx http://www.godaddy.com/ssl/ssl-extended-validation.aspx
- zumda 15y agoMostly, they are the same. There are some "addons" that are possible with SSL certificats. For example wildcard certificats which are valid on all subdomains, included support, encryption strength, browser support and others.
- charliesome 15y agoI like Gandi. You get a free SSL certificate for a year with your domain, and it's $12 a year after that.
- agwa 15y agoThey say you also get a free 1-year certificate with domain name renewals, implying that if you renew your domains for 1 year you can get a perpetual stream of free certs.
- orftz 15y agoThe only downside is that Gandi's certificates are not wildcard; i.e. they only apply to your root domain.
- blakdawg 15y agostartssl.com is free.
- leftnode 15y agoI get mine through DNSimple. I'm sure they're a reseller for another company, but $20 a year for a single domain SSL and $100 a year for wildcard.
- dangrossman 15y agoThat's expensive. The same GeoTrust RapidSSL certificate is $9.95/year through Namecheap, for example.
- XERQ 15y agoWe've used Comodo certs for our projects, given out for free by our provider SSD Nodes (http://www.webhostingtalk.com/showthread.php?t=1122631 http://www.webhostingtalk.com/showthread.php?t=1122631). I think the certs by themselves are $9-10/year if you decided to get them on your own.
- josephb 15y agoNameCheap has been great for me, for SSL certificates and domains.
- oblasco 15y agoComodo with PositiveSSL is bargain for 9$ USD
- charliepark 15y agoI get ours through our registrar (who also does our sideproject hosting), DreamHost. They have $15/year certificates (via Comodo), and you automatically get both the root and the www. subdomain of the certificate, included in the price.
- 8ig8 15y agoFWIW, Stripe recommends DigiCert: https://stripe.com/help/ssl https://stripe.com/help/ssl > We recommend DigiCert — their certificates have very wide acceptance (for example, Facebook uses a DigiCert certificate). Other options include NameCheap and GoDaddy. They have slightly lower acceptance but their basic certificates cost $10 to $20.
- pasbesoin 15y agoFB's been switching over the VeriSign -- at least, in my neck of the woods. I pay attention to certs, so I noticed this and took some time to somewhat reassure myself that no MITM was going on. (If I'm wrong, someone please tell me!)
- jvdh 15y agoStartSSL.com offers free yearly simple SSL certificates, and are supported by all major browsers. If you want higher-grade, you'll have to pay. They're very open about wanting to provide free simple certificates for everyone.
- mp3geek 15y agoWe use StartSSL-free on https://secure.fanboy.co.nz https://secure.fanboy.co.nz .. no issues with it :)
- RyanMcGreal 15y agoWhat's the difference between a simple certificate and something higher-grade? What does the simple certificate lack that a higher grade certificate provides?
- JoachimSchipper 15y agoExtended verification certificates (EV; "actually verified") cause the browser bar to turn green. That will make people more likely to trust you.
- RyanMcGreal 15y agoThanks for clarifying! Will a free StartSSL certificate trigger an 'untrusted source' warning from the browser? Also, will a free certificate be adequate for encrypting authentication data in a web API?
- JoachimSchipper 15y agoStartSSL is completely fine for those goals. Pretty much the only effect of an EV certificate is the green bar. (Which is easily worth $150/yr if you're doing millions in e-commerce, of course!)
- RyanMcGreal 15y ago
- shocks 15y agoI use http://exoware.net/ http://exoware.net/ They're a small company, but they care and they do a good job so we get along just fine. SSL starts at £15 a year and goes up. £70 per year for a wildcard.
- hencq 15y agoSlightly off topic, but how are people using SSL with App Engine? Last time I checked they didn't support SSL on your own domain. I'm not sure if this is similar for e.g. Heroku. I presume most non-trivial apps would have some kind of secure login.
- 18pfsmt 15y agoLooks like it went into testing last October [1], otherwise people have been using their appspot subdomains. [1]http://googleappengine.blogspot.com/2011/10/app-engine-ssl-for-custom-domains-in.html http://googleappengine.blogspot.com/2011/10/app-engine-ssl-f...
- ck2 15y agoDon't feed the SSL cartel Free SSL cert accepted by all modern browsers https://www.startssl.com/?app=1 https://www.startssl.com/?app=1 They are owned and operated by http://www.startcom.org/ http://www.startcom.org/
- mike-cardwell 15y agostartssl.com is part of the cartel you don't want to feed... Yes, they offer free certificates, but only in order to market their paid certificates. FWIW, I use free certs from startssl.com myself. If you really want to avoid the "cartel", use cacert.org or a self signed cert.
- saiko-chriskun 15y agoI will use cacert as soon as they're part of the standard cert group on all the major browsers :P
- plaes 15y agoI use cacert.org (free) on my private stuff. Unfortunately they are not included with Mozilla, so leaning towards startssl.com for my public project.
- conanite 15y agoSide question: what's the best company for SSL certificates where you're hosting multiple distinct domains for various clients on the same server? I've read about SAN certs, but I haven't found any documentation ...
- nodata 15y agoWhat do you want to do? Have multiple sites using the same ip address and port share a certificate? Get an SNI certificate, but beware of WinXP.
- Erwin 15y agoDigiCert claims that you can add/remove alternative names on already purchased certificates right from their account (you don't even need to include them in the CSR just the primary), but I haven't tried it personally. I wonder about what authentication you, as owner of www.foo.com, have to undergo to add e.g. myapp.client.com to the alternate name. The downside seems that the organization/country/city fields must be the same but that doesn't show unless you use EV The upside is no painful IP acquisition, CSR and renewal process.
- jd 15y agoAs far I know the only thing that works reliably is to get multiple IPs and multiple (wildcard) SSL certificates. You can try to save a little money by getting startssl certificates (free) or by using SSL host headers (multiple SSL on one IP address), but it doesn't work on all browsers so you end up wasting time explaining to your customers why they get an error when they access their site.
- rickard 15y agoWhat is "SSL host headers"? Is it wildcard certs, as Microsoft describes them on http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/596b9108-b1a7-494d-885d-f8941b07554c.mspx?mfr=true http://www.microsoft.com/technet/prodtechnol/WindowsServer20... ?
- zumda 15y ago
- crististm 15y agoI can imagine the SSL cert sellers laughing at those buying them. How is it that money can BUY TRUST is beyond my comprehension.
- nodata 15y agoWell how can you trust a company you have never dealt with before? It used to be that SSL certificates were a mark of insurance, proof that they had thought about securing your data in transmission, and proof that someone had validated the company as being real (like an auditor should). Nowadays points 1 and 3 are no longer true.
- ofutur 15y agoGet the best SSL cert for the job... If you just want to secure a login page for your own personal use, get a free cert from StartSSL. If you need to give access to the page to more people, it's best to get a cheap cert from Comodo, etc. because they're compatible with more mobile devices. Don't spend more than $15 If you intend on selling something from the site, I'd recommend getting some form of company validation on top of the standard domain validation which is performed when buying cheaper certs. GeoTrust, Comodo, Globalsign, etc. can help. It should cost less than $100. The best certs to get to re-assure your customers are the EV ones. No need to go full Verisign and waste ton of money on them, you can get them cheap-ish from Globalsign, Comodo and Geotrust resellers. If you're getting a cert generated by an established certificate authority, it doesn't really matter who you buy it from. Aim for the best price for the level of support that you want to get.
- foobarbazetc 15y agoIgnore anyone in this thread telling you to use StartSSL. When you care about your cert (validated, EV, etc): DigiCert. When you don't care that much: RapidSSL from Namecheap. The end.
- nimrody 15y agoYou might care about your cert. However, your users do not care at all. Most users (not most HN readers!) have no idea what is the difference between certificates. Do you really think users pause to check what type of SSL certificate the site has? .. And what CA had signed that certificate? They don't -- even when they access their bank.
- RyanMcGreal 15y ago> Ignore anyone in this thread telling you to use StartSSL. Why? What's wrong with it?
- ibejoeb 15y agoI like https://www.alphassl.com/ https://www.alphassl.com/. It's one hop down the chain from the Global Sign root.
- ibejoeb 15y agoAlso, you might be interested in the trust relationships between the major CAs. - https://www.eff.org/files/colour_map_of_CAs.pdf https://www.eff.org/files/colour_map_of_CAs.pdf - https://www.eff.org/files/DefconSSLiverse.pdf https://www.eff.org/files/DefconSSLiverse.pdf
- getsat 15y agoDigicert is ballin'. Using them on a few sites.
- georgelawrence 15y agoA little off topic, but I'm thinking of using CloudFlare's "Easiest SSL Ever"... Is anyone here using it? http://blog.cloudflare.com/easiest-ssl-ever-now-included-automatically-w http://blog.cloudflare.com/easiest-ssl-ever-now-included-aut...
- traxtech 15y agoNot yet, but that's my plan :) I'll setup CloudFlare soon, for the "go live" of my new startup this month.
- dshep 15y agoI had a good experience with StartCom.
- finnw 15y agoI cannot recommend Comodo. I paid for one of their certificates (through a re-seller) but they refused to issue it on the grounds that they could not verify my phone number. It was true that it was not in the directories they referred to, but they did not make that clear before selling the certificate. I would have made a chargeback, but was paranoid about them informing other CAs of the fact - it would be a disaster if I was never able to get another SSL certificate.
- qedeshbala 15y agoI would definitely advice to you startssl.com, they offer free ssl certificates.