36 ms·
Why are wildcard SSL certs so expensive? I want to use SSL certs on my personal subdomains, but they are usually priced at around $150/year at least. I hope let
by ynak 11y ago
Why are wildcard SSL certs so expensive? I want to use SSL certs on my personal subdomains, but they are usually priced at around $150/year at least. I hope let's encrypt will support multi or subdomains.
- nisa 11y agoStartSSL offers as many wildcard certs as you want for a low fixed yearly fee (50$)?
- dspillett 11y agoMultiple name certificates are included in that too, which is handy if you have several distinct domain names, limited IPv4 addresses, are worried about ancient browsers that don't support SNI. I have a single certificate that covers a couple of domains that way. Saves on admin too (though could be a pain if the PK were ever compromised as every service would need to be updated - if you have separate certs for everything and one is compromised you don't have that complication).
- creshal 11y agoStartSSL is very much "you get what you pay for", though. Their web interface is sporadically unreachable, and their validation is rather sloppy – as long as you pay up, you can happily break their terms of service and still be re-validated.
- StavrosK 11y agoI never understood how that matters, though. My visitors will see a green bar, job done. Breaking the ToS or not, I don't care as long as my address bar is green. How is Verisign any different from StartSSL, in that regard?
- creshal 11y ago> I never understood how that matters, though. It will matter if StartCom is abused to print certificates for foreign domains. Even if your domain isn't targeted, browsers and OS vendors will probably react by invalidating all StartCom CA certs. That means no green bar.
- nosefrog 11y agoHas this ever happened before? I'm genuinely curious, as I've heard this warning often but it seems more like FUD than anything else.
- zymhan 11y agoGoogle just removed CNNIC as a trusted CA from Chrome because of their sloppy security and trust.
- WorldWideWayne 11y agoCNNIC had provided "unauthorized digital certificates for several Google domains" and in an update on April 1st Google said that "To assist customers affected by this decision, for a limited time we will allow CNNIC’s existing certificates to continue to be marked as trusted in Chrome, through the use of a publicly disclosed whitelist" - http://googleonlinesecurity.blogspot.ro/2015/03/maintaining-digital-certificate-security.html http://googleonlinesecurity.blogspot.ro/2015/03/maintaining-... So, I doubt they would treat StartSSL any worse than they treated China.
- lepht 11y agoCan you link to this? I wasn't able to find info about this fixed yearly fee plan on their site.
- nisa 11y agoLooks like it's only a one time fee? of 60$ here are some links: https://www.startssl.com/?app=2 https://www.startssl.com/?app=2 as well as this answer: https://www.startssl.com/?app=25#27 https://www.startssl.com/?app=25#27 A friend of mine got validated and he send me signed and working wildcard cert with multiple domains a few days ago - so it's a real thing I believe.
- 0x006A 11y agothey will not support wildcard domains. you can create a cert per domain though or one for multiple subdomains.
- ynak 11y agoYou mean I can issue multiple certs at each subdomain separately instead of one wildcard cert? That's promising. It's also OK on my personal use.
- xtrumanx 11y agoBugger. I was really excited for Let's Encrypt specifically for the possibility of a free wildcard cert. I was thinking of building an app which would be under two domains like heroku.com/herokuapps.com and github.com/github.io and I rather not spend hundreds of dollars on two wildcard certs. Guess I'll just buy one and not use subdomains on the main site.
- sp332 11y agoYou can get a certificate covering multiple specific domains. https://github.com/letsencrypt/lets-encrypt-preview/issues/66#issuecomment-68920377 https://github.com/letsencrypt/lets-encrypt-preview/issues/6... A wildcard cert wouldn't cover both heroku.com and herokuapps.com anyway. https://en.wikipedia.org/wiki/Wildcard_certificate https://en.wikipedia.org/wiki/Wildcard_certificate
- msumpter 11y agoI've picked up wildcard certificates signed under AlphaSSL for around $50 on sale in the past. For personal projects the acceptance is decent.
- PaulBurke 11y agoThe price of Wildcard SSL certificate is a bit expensive because multiple sub-domains are secured with single certificate. For a large business with multiple sub-domains (mail..com, blog..com, info..com, anything.com, etc...), if the business purchases individual SSL certificate for each sub-domain it need to spend more money, and the process will be so long as generation of new CSR, private key, certificate installation, etc... A Wildcard SSL secures unlimited sub-domains which saves time and money as well. $150 is much higher for a wildcard SSL certificate, Visit CheapSSLSecurity (https://www.cheapsslsecurity.com https://www.cheapsslsecurity.com) where you can get Wildcard SSL certificate at $60/year for Domain Validation and $108/year for organization validation.
- florin5255 11y agoToday I purchased wildcard ssl https://www.ssl2buy.com/alphassl-wildcard.php https://www.ssl2buy.com/alphassl-wildcard.php at $42, It works fine and secures my all subdomains.
- kennycox 11y ago$42 wildcard ssl - http://community.spiceworks.com/topic/539962-wildcard-ssl-for-42-year http://community.spiceworks.com/topic/539962-wildcard-ssl-fo...