What is the best alternative CA that also offers wildcard certificates (preferably with a similar business model)?
What is the best alternative CA that also offers wildcard certificates (preferably with a similar business model)?
Am I right in thinking I could generate my own certificates for any domain I wanted and have them validate in any browsers or devices that currently trust StartSSL/WoSign? Or to put it another way, would it give me the same powers as running my own internal CA but without the problem of convincing people to install my root-ca?
I assume it _can't_ mean that, otherwise people would surely be up in arms (10k to mitm anyone is scarily cheap), so could someone educate me please?
They create a new intermediate, signed by their root, just for you. You then get to ask that CA to issue certs for you - and only you.
You don't have total control over the intermediate -- as you suggest, that would let you mitm everyone.
But by having an intermediate that you effectively control, you could have apps/devices/etc that trust only that intermediate (via pinning, HPKP, etc). That prevents a bunch of the possible downsides of using the public PKI (eg, a CA mis-issuing a cert for your domains), the downsides of pinning a leaf cert (because you can always issue another one off your intermediate if you change names, etc), and the downsides of a private PKI (because stuff that trusts the public PKI works too)
- EV (green bar) certs are required to increase customer trust (it may be mostly snakeoil, but the CA system is heavily flawed and we are still forced to rely on it anyway)
- Applications where certs are used on other platforms than web servers (e.g. embedded devices, routers etc.) and 90-day renewals are not easy to implement in an automated way.
- Wildcard certs are mostly useful for convenience reasons, e.g. to easily secure a changing number of hosts within certain (sub)domains/zones (especially when they are only or mostly used in internal networks). I agree that the need for wildcard certs is greatly reduced with let's encrypt and acme.