6 ms·
That sounds very much like the service that is already offered by StartSSL.com. You pay for identity validation, but you can then create as many regular and wil
by pugz 12y ago
That sounds very much like the service that is already offered by StartSSL.com. You pay for identity validation, but you can then create as many regular and wildcard certificates as you wish. It's a superb service.
- deleted 12y ago[deleted]
- blibble 12y agoit's a superb service, until you want a revocation, then they try to extort $25/revocation out of you (even if you've been a long term paying customer) this may be OK if you have only issued one cert, but if you've issued a few hundred (which is the main point of StartSSL: pay once and issue many), then you are SOL unless you can afford to plonk down thousands of dollars. more here: https://www.techdirt.com/articles/20140409/11442426859/shameful-security-startcom-charges-people-to-revoke-ssl-certs-vulnerable-to-heartbleed.shtml https://www.techdirt.com/articles/20140409/11442426859/shame... the CEO (Eddy Nigg) is similarly patronising over email too.
- dochtman 12y agoTo be fair, it seems like they have a point that revocation is actually expensive for them.
- aianus 12y agoWhere does it say that? I would assume it's just as easy as issuing them in the first place.
- Someone1234 12y agoYou would assume wrong. Revocation is a massive PITA.
- Karunamon 12y agoWhy? It appears a CRL is nothing more than a file containing blobs of DER-encoded cert files.
- womble 12y agoRunning a revocation service is an annoyingly fiddly job, but all of that needs to be setup and running before you become a CA. Pretty much all of the faffing around is in the need to regularly regenerate (including signing with the CA key) CRLs and OCSP responder certificates. Like the rest of a CA's operation, revoking an individual certificate should be a miniscule incremental cost, modulo the larger CRL size due to the added fingerprint. I was rather surprised that so many people are sucking down CRLs, but clearly they do (http://blog.cloudflare.com/the-hard-costs-of-heartbleed http://blog.cloudflare.com/the-hard-costs-of-heartbleed).
- the_mitsuhiko 12y agoSince the revocation protocol is broken anyways I don't really think this is a real problem.
- womble 12y agoAll we have to do is get all certs flagged with must-staple and have all webservers handle stapling, and we're set! (Sarcasm? Moi?)
- JoshTriplett 12y agoI use and like StartCom certificates, but they wouldn't solve this problem. Wildcard certificates should not require identity validation; you should be able to get a domain-validated wildcard certificate for free. Also, their free certificates expire every year; domain-validated certificates should only require revalidation if the domain changes hands.
- womble 12y agoThere are rules being introduced against issuing certificates for more than about three years (you can still get five years certs at the moment, but not for much longer); this is more to limit the risk of private key compromise than it is to require people to revalidate. I don't find it too onerous to have to install a new cert every year or so (he says, with several certs currently expired).
- JoshTriplett 12y agoStill, I'd suggest issuing certificates for the maximum allowed length, unless requested shorter. Scalable revocation is possible; follow best practices for encryption keys by keeping a separate offline copy of a signed revocation request.
- womble 12y agoRevocation for X509 certs is a very different matter to that of revoking PGP keys. For X509, the CA can revoke the cert unilaterally, or at the request of the subscriber without the need for the subject private key. In fact, I'm not aware of the existence of a subject-side revocation process that doesn't involve the cooperation of the CA.
- 0x0 12y agoDo take note that they will reject and/or also refuse renewal if they think the domain whois doesn't exactly identify you, even if you confirm the domain webmaster validation. Lots of hassle if your domains have other entities or business names listed as the whois admin contact.