Don't submit to the SSL cert racket. You can get one for no charge
startssl.com
startssl.com
Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.
Dealing with Thawte was HORRIBLE, these guys are extremely pushy (their sales reps repeatedly called me at home to 'convince' me I really should renew my certificates with them and wouldn't take no for an answer). Contrast that with startSSL where I had some questions and Eddy Nigg personally replied within minutes.
In summary, I highly recommend giving startSSL a shot.
I can see why you may want something simpler if you need 10+ certificates, but if you just want to set up SSL for something then startSSL is fine.
Since you mentioned paying "a few dollars" to Namecheap, can you comment on the feasibility of their $8.95 "PositiveSSL" certificate? ( http://www.namecheap.com/ssl-certificates/comodo.aspx )
More generally: If you need to support mobile devices then read your CA's compatibility list closely (if you can find it...) and test, test, test. You'd think this shouldn't be an issue anymore in 2012, but it sadly still is.
[1] http://www.zimbra.com/forums/administrators/44675-new-geotru...
[2] https://support.servertastic.com/entries/426677-rapidssl-and...
The cross-root cert should work, but you need to make sure it's presented in the right order, I think.
FWIW, my latest RapidSSL-through-Namecheap certs were issued by:
issuer=/C=US/O=Equifax/OU=Equifax Secure Certificate Authority
And that's the "good"/trusted CA. I'm not sure when they made the switch, but I only got this cert issued a couple of months ago.
FWIW, we also support Docomo phones, and that is a huge pain in the ass. The only CA that works there is:
i:/C=US/O=VeriSign, Inc./OU=Class 3 Public Primary Certification Authority
If you don't need to support really old mobile devices, the best certs going are, IMHO, Digicert. They get chained all the way back to Entrust:
1 s:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV CA-1 i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA 2 s:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA i:/C=US/O=Entrust.net/OU=www.entrust.net/CPS incorp. by ref. (limits liab.)/OU=(c) 1999 Entrust.net Limited/CN=Entrust.net Secure Server Certification Authority
And the company has some of the best customer service going anywhere.
Not only that, they check your installed cert after you buy it and email you if you installed it incorrectly: http://www.digicert.com/help/
That said, once I registered with a new account, the client certificate worked great.
CACert does.
People with background knowledge may know startssl is legit/good but to a newcomer I can easily see why their first impression is off.
SSL certain are important and I don't think their design is helping them look like a legit business. I trust they are after all the comments here but on first glance I was skeptical and thought it was too good to be true. I know we all pride ourselves on being smart, critical thinker that can look past a site's design and see the true value behind it but I think in some cases it's perfectly normal and acceptable to react this way to a design. Superficiality be damned. I'd rather run from a poorly designed, non-legit looking site and be safe rather than risking it and being sorry later because I gave in to the PC, "don't be superficial" side of me.
A beautiful site can have an awful UI. The StartSSL site doesn't have that polished hipster-corporate look that we're so used to seeing these days. I think you might be talking about the experience. It's one thing to have a pain in the ass experience with forms or actions that require multiple page views/reloads to complete and quite another to have an ugly site in general. "Ugly" can be a very subjective thing though. StartSSL's site isn't exactly ugly but more dated looking. Speaking striclty from a design point of view, without being overly critical, the site is aligned nicely, has a nice grid, the typography isn't fancy but it's not so ugly that you'd complain about it on first glance, the colors are okay and don't hinder readability, there's enough white space, etc. Even so, when it comes to design there are always those intangible qualities that you can't quite describe or put into objective terms (which I'm sure is very frustrating for programmers as we're all about exact, measurable, science-y stuff).
So considering that the site isn't ugly from an objective standpoint, how could it still be ugly? To answer that you have to take into account experience. Web design, much like fashion, has fads and trends. Right now we're used to seeing what I like to call "hipster-corporate" design. This style is all about being casual while still looking corporate enough for people to take the comoany's site seriously. It's really tough to straddle the line between trying too hard to look hipster-corporate and looking dated and old fashioned. We've all seen the website for the local doctor's office that looks like it's trying too hard to be that big corporate style but failing miserably and looking like the crappy free Wordpress template that it is. Hipster-corporate is really interesting because there are a lot of variations and the amount of hipster style or corporate style that mixed in all depends on the company's personality and size. Too much or too little of one or the other totally breaks the feel.
So the point is, after all that, I think we're talking more about the "feeling" that the site gives you rather than the objective reality of things when we talk about the site looking pretty or ugly, good or bad, well designed or poorly designed.
This feature has just convinced me to stick with them for future purchases.
> With each domain name transferred to Gandi, we include a Standard SSL certificate for free the first year.
Included for free the first year with the purchase,
transfer, or renewal of your domain name.
My understanding was that if I had a domain with them and renewed for another year, that would fall under the "renewal" clause of the above.[1] https://en.wikipedia.org/wiki/Comodo_Group#Breach_of_securit... [2] http://www.securelist.com/en/blog/6177/A_Web_of_Mis_Trust_Co...
They have a very detailed policy document describing all sorts of security procedures they purport to adhere to, but I have no way to validate whether they are actually following those policies and no recourse for me or my wife even if it was determined that they are not following them.
That is just too risky for the value I would get out of the process.
(posted to twitter also https://twitter.com/#!/deinspanjer/status/158596876772450304 )
EDIT: I was contacted by Eddy Nigg with some follow up information. I should have said that the reason they asked for my wife's info is because they wanted phone bills and those are in my wife's name which isn't the same last name as mine. That said, I'll still stand by my statement that the risk and complexity vs. reward was just not suitable for me.
EDIT 2: Okay, they offer an alternative for validation: they can mail you a registered letter with a validation code on it. That is much more acceptable to me, so I'll continue on with the process to see how that goes.
Also their certs are only free as long as you don't need to revoke it.
It's $25 to revoke a cert, i.e. free up the name so you can use it again elsewhere. I used part of my domain name for an XMPP cert that I later wanted to use for a web subdomain with the same name.. nope. Stupid.
..ouch!
I've used positivessl from namecheap whenever I need certs, its something crazy cheap like $5
You might mean self-signed certificates?
I'd like to create a wild card certificate, but that costs money. My understanding is that it is a one off fee (60USD) for them to validate your identity and that it doesn't cost money to renew after that point. I could be wrong though. It's not completely clear.
Deleted comment
>gain enough access to issue valid certificates for arbitrary domains to themselves, StartSSL
>said. The attackers were also unsuccessful in generating an intermediate certificate that
>would allow them to act as their own certificate authority, The Register reported.
Second, I just got a "Error 107 (net::ERR_SSL_PROTOCOL_ERROR): SSL protocol error." at https://auth.startssl.com
For a product that is supposed to be confidence inspiring, StartSSL is the opposite.
But that basically confirms my contention that the user experience is miserable.
Deleted comment
If it's for something where it's that much of a concern (and it IS a legitimate concern, no argument there) then you need a paid certificate anyway - you'd likely want a business name, not a personal one, etc etc......
If we're talking business, you wouldn't be using a free cert from them anyway.
Unfortunately, there isn't, and as a result self-signed certificates are useless to anyone running a HTTPS site that expects any visitors.
I'd personally be really happy to see something like http://perspectives-project.org/ instead of the current web of mistrust.
Currently, self-signed HTTPS is trusted less than unecrypted HTTP. We don't get a massive warning if visiting Facebook over HTTP, despite the MITM risk and the fact that data is being sent in clear to boot.