4 ms·
StartSSL offers free class 1 certificates. Don't know if that's any use to you.
by danbee 12y ago
StartSSL offers free class 1 certificates. Don't know if that's any use to you.
- smnrchrds 12y agoI'm aware of that, but because revoking the certificate is not free, it would be impossible for us to do. Not very good security-wise.
- Alupis 12y agoIf you are not capable of affording at least a cheap-almost-free ssl cert in order to protect your site's users, and given your site actually requires SSL (such as secure account login, transactions, etc) you probably should not be running the site. SSL certs can be found for $1.99 per year sometimes from companies (that's cheaper than it costs to run your server). Sure they are not the "name brand" ssl certs like from Verisign that cost $300 a year -- but to a browser, SSL is SSL (so long as the browser recognizes the trust chain). If your country prohibits SSL's use -- then you really should consider not hosting your site from within your country. Security is not a joke.
- zampano 12y agoI don't think he was saying he couldn't pay because he couldn't afford to pay, I think he was saying he couldn't pay because he doesn't have the option of paying with the economic sanctions against Iran.
- Alupis 12y agoThat does not change the spirit of my comment. If your server requires SSL due to security reasons, and you are not capable of using SSL for one reason or another, then I'd rather you don't run that server at all. Besides, if it's not an cost-prohibitive problem, but rather one can't get an SSL cert due to sanctions, etc... well, that argument doesn't hold water either. Not every country holds sanctions against Iran for example. You may not be able to get an SSL cert from a USA company, but there are many other countries who have CA's available that probably have no sanctions. In the end, security is not a joke. If your server requires itself to be secure, you'd better do it.
- JohnTHaller 12y agosmnrchrds isn't saying they don't have the money to pay for it. They're saying they can't pay for it. Because they're in Iran, they can't get PayPal, a foreign credit card, etc. So, while they could get this SSL for free, it would be a security risk for them since they'd be unable to revoke it if it were compromised because they have no way to carry out the transaction.
- deleted 12y ago[deleted]
- Alupis 12y agoMost countries have operating CA's... and not every country has sanctions imposed against Iran -- so it is possible to get a cert even if you live in Iran.
- JohnTHaller 12y agoI'd wager smnrchrds has tried that route as well. I'd also wager that most countries with CAs accepted worldwide likely obey the UN ratified Iran sanctions. So, unless you can suggest a specific CA that is accepted by most browsers that is headquartered in a country that does not obey the UN ratified sacntions against Iran, this discussion is moot.
- Alupis 12y agoHere is one company offering SSL certs to Iranians (albeit, very expensive, but it's still possible to get): http://www.ouriran.com/sslservices.cfm http://www.ouriran.com/sslservices.cfm So the discussion is not "moot". If you run a website or webservice that must be secured -- you need to secure it or not host it. As an aside -- I don't believe Iran is currently under UN sanctions -- I believe they expired at the beginning of 2014 [1] ... the US, and several EU countries and others still do have Sanctions, sure... but it's not the entire world... specifically China and Russia are not on the Sanctions list, and both operate public CA's. [1] http://en.wikipedia.org/wiki/Sanctions_against_Iran http://en.wikipedia.org/wiki/Sanctions_against_Iran
- Someone1234 12y agoThey're only usable for non-commercial purposes. So for an *.ir business, it remains problematic.
- dspillett 12y agoThough be wary of the "non commercial use" clause on the free certificates. I have no idea how, or indeed if, they enforce that (revoking the certificate if they find you using it for commercial purposes?) but it is there.
- cnst 12y ago> StartSSL offers free class 1 certificates. Don't know if that's any use to you. No, that doesn't work. 0. Once you go https, you're basically hooked. What if StartSSL stops offering free certs tomorrow? They've been offering free certs for ages now, yet still have no competition! So much for the free market. 1. What if you have a good dozen of different domains? The cheapest multidomain certificates seem to start 50$+/domain/year, that's a pretty hefty price tag for non-commercial projects. We need something like STARTTLS in smtp/xmpp/etc for http, which just protects the traffic from eavesdropping and passive attacks. Because right now as it is, from the user's experience, having a self-signed https is WORSE than not having any https at all. Do you get any warnings on http web-sites? What about self-signed https? WTF? I don't live in Iran, but I completely agree with the OP that TLS is not ready yet, by not being affordable and dependable. I'll adopt TLS for http as soon as, (1), I can guarantee that existing users won't suffer, (2), I won't be required to update certificates all the time (when was the last time you've updated your ssh certs?), (3), I won't be required to pay hundreds/thousands of dollars (per year) to secure all my domains.
- Alupis 12y agoYou do know TLS and SSL can be on the same server? In fact, if you are on a modern browser, look at the SSL cert HN is using -- it should show you are using TLS 1.2. -- so no users "suffer". Some SSL certs have become bloated in price (without good reason), such as the VeriSign certs, etc. No SSL cert should cost $300 a year... that's absurd. However, they can't be free... someone has to pay for the infrastructure that not only signs certs, but provides the trust backbone that SSL rides on.
- cnst 12y ago> In fact, if you are on a modern browser, look at the SSL cert HN is using -- it should show you are using TLS 1.2. -- so no users "suffer". No, once you go SNI and people start sharing https links, you basically cut off all users who have older browsers. Which is complete bullshit -- they should just be getting the non-encrypted web-site, just like what happens with smtp and STARTTLS. > No SSL cert should cost $300 a year Yet you won't find a cert for a dozen different domains cheaper than 600$/year. And what if you want to wildcard each of those domains, too? > someone has to pay for the infrastructure that not only signs certs, but provides the trust backbone that SSL rides on. And I should care about the trust backbone for my personal web-site and non-commercial projects why exactly?