No obvious revenue stream feels like it's a recipe for something that's going to go poof rather quickly.
No obvious revenue stream feels like it's a recipe for something that's going to go poof rather quickly.
Anyway scrolling down to the bottom¹ they seem to be resellers for DigiCert/Symantec certificates. So based on their strategy to fish for users with free certificates, I'd strongly question both their motives and their track record with handling the technical requirements for operating a CA. If they are a serious actor in this space then they should at the very least have either ETSI TSP² or WebTrust³ certifications to meet the security/trust requirements for operating a CA. Judging from the info on this site, I doubt they do.
¹ https://www.certcenter.com/company/terms
² https://portal.etsi.org/tbsitemap/esi/trustserviceproviders....
>they should at the very least have either ETSI TSP² or WebTrust³ certifications to meet the security/trust requirements for operating a CA
A reseller does not need to meet any of these certifications. Resellers have a business relationship with a CA, and all the steps related to certificate verification and issuance are handled by that CA.
On the backend, a certificate request for your site is handled the same by the CA whether if comes through a reseller or through them directly.
I actually thought that was a legal requirement in Germany.