I'm now just curious what happens to my data if they're sold to China. I mean, the amount of personal data they are asking for when acquiring a certificate is not really small.
So you want a secure website, and you agree that SSL is needed for things to be secure.
But you're not willing to put in one inch of effort yourself to secure your own SSL keys. You can't even bother to back up the master key to your own certs, because it's too much work?
Cognitive dissonance much?
If you care about security, then do it properly. If you're going to do it half-assed, just don't bother at all. All you're doing then is contributing to security-theater, which is all the work and no real benefits.
I don't know what you have been doing the last 20 years on the web (and I'll assume it's more than just surfing facebook), but it's not entirely uncommon, and I've encountered it several places.
Symantec's CA uses it. My online bank used to do so too. I've seen VPNs using it. Iirc some IPv6 tunnel-providers also require you to authenticate using certificates before letting you set up new IPv6 subnets.
It may not be mainstream, but it's part of the standard. And it's much more secure than a regular username/password, for the same reason SSH keys are more secure than allowing username/password logins.
To be clear about that: My point about half-assed was your seeming unwillingness to back up client-certificates which gives full access to your real certificates and (in some cases) private certificate keys.
Unless on Windows (where StartSSL has its private keys marked non-exportable in the certificate store, sic), doing such a backup takes almost no effort. There's no excuse for going all the way through to get a cert and then not bothering backing up these client-certs too.
./letsencrypt-auto renew(Browser makers are quarter-assing their UX for using client certs, but that's a separate issue).
If you accidentally visit their page with the wrong browser (Safari or Chrome, I forget) when you need to renew an expiring client certificate - the browser doesn't download it properly, you can't ever request another one. Anyway, letsencrypt sorts that out.
The guy kept throwing out extremely passive-aggressive lines while using smilies while I was nothing but polite.
Things like:
- "I understand your problem, maybe you should be more careful next time. ;)"
- "Next time read the fine print! :)"
This was all because I needed to get a certificate revoked. Due to their terrible and unclear interface I had managed to lose a private key that they generated for me and as you know, revoking certificates with StartSSL costs money.
The hilarious thing is the revoke fee is way more expensive than just buying a certificate with a different provider.
Thankfully I'll never have to deal with them again in my life because superior services exist to obtain/revoke free basic certificates.
Found your problem: you should never have someone generate a private key for you.
It's one of StartSSL's flaws too. They are an enabler of doing stupid things.
Maybe that's because 90 % of them actually are?
Oh, and they allow you to authenticate for their web interface using client certificates instead of form abominations? Sweet.
Automating this simply means that if someone hacks your machine, they also have full access to generate any certs they like.
I don't consider this a positive thing.
You can separate the generation onto another machine, but it's much more complicated, and the default install is not that way.
I have yet to hear any useful reason to rotate the key.
Well, they can generate certs for your domain. But what exactly is the big difference between generating a new certificate for your domain and having your private key. I fail to see why it would be a huge risk, they can access all your users data in any case.
>I have yet to hear any useful reason to rotate the key. http://security.stackexchange.com/questions/85963/what-is-th...
Basically limiting damage in case of a compromise.
Another side-effect is that you don't need to manage revocation stuff as diligently, because certificates automatically expire shortly. The window during which a certificate is valid is extremely short and recent, which means there is less chance that a problem happens. when that probability increases (as a result of being older), certificates become automatically invalid.
All in, the Lets Encrypt way brings you more security. Since the certificate validity is shorter, even generating an extra certificate will give the attacker a smaller average time with a valid cert than stealing your StartSSL cert.
I'll take an automated process I run via cronjob and that requires no manual intervention, over a process that requires I touch it once a year.
The decision (to me) is a no-brainer.
For the very first time, you can use let's encrypt's manual verification process, but then have the let's encrypt client set up to renew certs automatically (possibly even from a separate container) using same data file mappings.
I use a temporary self-signed keypair, which then gets replaced when the certificate is issued.
In addition, domain authorizations last for 10 months, so you don't have to go through the DNS verification each time: just renewing is sufficient. Run the issue command, drop new certs into configuration management, done. Couple minutes tops. Just set your calendar!
Started with Let's Encrypt. Running Mac OS X. Failed. Guessed cause has something to do with macports vs homebrew and having the proper Python version active. Disabled macports. Now the app runs.
But I got "Failed to connect to host for DVSNI challenge".
Start googling, reading, messing around with this for a while. No joy.
Bailed on Let's Encrypt, started over with StartSSL, because its the first source of free for not-for-profit certs I found.
Happy to take recommendations for alternatives.
Use something small like https://github.com/kuba/simp_le or https://github.com/diafygi/acme-tiny
Note that the update process needs to be automated because let's encrypt certificates last only 3 months as I have read.
Think about how much time it is going to take you to learn how to deploy and maintain your 'free' certificates and remember time is money. What do you make an hour? Is that more than the cost of a paid certificate?
I have used these certificates - https://cheapsslsecurity.com/comodo/positivessl.html - on multiple sites and it is very fast and easy. Other vendors sell them too and are likely just as good. Gandi do them too (at a slightly higher cost) and are the fastest method for me, though this may be because I have all my domains there already: https://www.gandi.net/ssl/standard?currency=USD#single
Don't waste hours chasing down free certificates when paid ones are so cheap now. Use Let's Encrypt only if you need lots of certificates and the paid options become prohibitively high.
I'll use Let's Encrypt when they have a easy setup available.
But the biggest problem here is wildcarded subdomains, since LE doesn't let you get more than 5 certificates per domain.
Also I think with Firefox on Windows XP it should work.
Let's Encrypt actually has compatibility issues with Windows XP, so wildcard certificates wouldn't help.
https://community.letsencrypt.org/t/which-browsers-and-opera...
Not perfect but seems to work fine.
Have you tried using it? On every domain I've tried to obtain a cert it has failed.
For me StartSSL may be suboptimal, but at least it works, which is more than I can say for Letsencrypt in its current state.
In practice, for most people, reserve a few hours for your first deployment. After you got a script that calls openssl right, it's fast to adapt for other domains, but the first time is hard.