5 ms·
StartSSL's default usage mode is to generate private keys on their website. Yet another horribly insecure system. I'd much rather that people used self-signed
by sexmonad 12y ago
StartSSL's default usage mode is to generate private keys on their website. Yet another horribly insecure system.
I'd much rather that people used self-signed certs (and browsers had certificate pinning) by default, and could then step up to real CA certificates. Self-signed certs provide almost the same amount of trust that StartCom does.
- kmac_ 12y ago> StartSSL's default usage mode is to generate private keys on their website. No. AFAIR they use HTML5 <keygen> tag to generate key pair.
- drdaeman 12y agoThat's for personal (client) certificates. For server certificates, unless you supply the CSR by yourself by skipping a step (IIRC, you're softly encouraged to do so), they generate the key server-side and send it to you back. They even have a FAQ entries (##43,44, although their site is down ATM, so Google for a cached copy) about that.
- kmac_ 12y agoYou're right, I've mixed up things.