Despite revoked CA’s, StartCom and WoSign continue to sell certificates
ma.ttias.be
ma.ttias.be
There will however be a brief period where they did sell their own certificates, signed by their own CA, that are now being blocked.
But I've only bought certs from a handful of resellers, so maybe there are other ways for resellers to integrate with a CA's system. StartSSL's unusual pricing scheme (validate once, get unlimited certs for a year) makes me a bit suspicious in this regard.
This is true even in cases like Gandi.net where some of the certs they sell come from a custom-branded intermediate certificate. The root CA is Comodo and they are doing the validation, controlling the private key's of the certs that handle issuance, etc. Its just a branding thing.
There are a few cases with Sub-CAs/Registration Authorities where a third-party company is handling some/all of the certificate validation. Symantec is currently in trouble for the bad actions of CrossCert, a Korean company that was licensed to be a Sub-CA. But WoSign/StartCom would not be able to participate in any sort of arrangement like this without being immediately banned again.
So there is no inherent problem with a banned CA continuing to sell certificates that another CA is validating. However, in the investigation of WoSign it was found that the company is deeply dishonest, incompetent, and even a little bit malicious. So anything that puts money in their pocket should be avoided.
Thank you for the information, but I disagree, this is exactly a link-bait article; the headline clearly implies that they are still selling their revoked certs.
He also offered an alternative explanation: the title was a mistake.
You no longer have to ask year after year for a new certificate. It will be renewed automatically for as long as your webserver lives. And everything is backed by good protocols, a strong community and a trustworthy organization (EFF).
Now you have to ask every three months.
It improves security at the small cost of having to slightly improve your deployment process.
No, you have a script running that updates your certificate automatically, and you never ever have do that that manually again. Or, you don't need that script because your webserver (e.g. Caddy) does that for you.
Oh, and just in case one of the intermediate certificates of Let's Encrypt had to be revoked for some reason: The very same mechanism would provide you with a new, working certificate as soon as possible. This, again, is fully automatic without any headache on your side.
Do you know any other CA where get this level of comfort?
I have a running system with Let's Encrypt certificates for webserver (HTTPS) as well as mail server (SMTPS, IMAPS, POP3S), based on nginx, exim4 and dovecot, using certbot.
Setting up Let's Encrypt literally consists of just 3 steps:
1. In the webserver for all domains on HTTP, add alias /.well-known/acme-challenge to /var/www/letsencrypt/.well-known/acme-challenge
2. Run "certbot certonly" once for every domain
3. Add cronjob for "certbot renew" with a post-hook that restarts your webserver and mailservers.
Well, to be honest, there is one more step, but that one is specific to my own setup, and also just a one-time effort:
3a. Add a post-hook command that fixes a permission issue with Debian-exim. Note that this is only needed if you want to use the certificates for SMTPS and use exim under Debian.
If you add a new domain later on, this is just a single step, no need to touch the cronjob:
1. Run "certbot certonly" once for that domain
So yes! Once you have the setup running, setting up a new SSL/TLS domain is actually easier with Let's Encrypt than with any other CA.
(Of course, you'll also have to add the domain to your webserver configuration, but that's always needed, whether you use Let's Encrypt or not.)
StartSSL was at the perfect price point for my needs (which are a weird mixture of SMB with Large/Enterprise). It's a damn shame what happened to it.
To say this is "shady practice" is putting it nicely; I daresay few but the keenest observers would pick up the problem.
Prior to the clusterfk of becoming untrusted by Mozilla (etc), it was really useful.
Once verified you could generate many certificates (subdomains, etc) without forking over cash each time.
Compared to the general (scam-like?) model of other providers, it seems like a sane alternative.
Now they're untrusted though, it's kind of moot. :(
But I have been using Let's Encrypt which is pretty automated, and did I say it is totally free? Awesome is a word I will describe this kick-ass product.
What is the status of Wosign/Startcom certificates in the Opera browser? And in the Qihoo ("360 secure") browser?
https://blog.mozilla.org/security/2016/10/24/distrusting-new...