Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.
Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.
Dealing with Thawte was HORRIBLE, these guys are extremely pushy (their sales reps repeatedly called me at home to 'convince' me I really should renew my certificates with them and wouldn't take no for an answer). Contrast that with startSSL where I had some questions and Eddy Nigg personally replied within minutes.
In summary, I highly recommend giving startSSL a shot.
I can see why you may want something simpler if you need 10+ certificates, but if you just want to set up SSL for something then startSSL is fine.
Since you mentioned paying "a few dollars" to Namecheap, can you comment on the feasibility of their $8.95 "PositiveSSL" certificate? ( http://www.namecheap.com/ssl-certificates/comodo.aspx )
More generally: If you need to support mobile devices then read your CA's compatibility list closely (if you can find it...) and test, test, test. You'd think this shouldn't be an issue anymore in 2012, but it sadly still is.
[1] http://www.zimbra.com/forums/administrators/44675-new-geotru...
[2] https://support.servertastic.com/entries/426677-rapidssl-and...
The cross-root cert should work, but you need to make sure it's presented in the right order, I think.
FWIW, my latest RapidSSL-through-Namecheap certs were issued by:
issuer=/C=US/O=Equifax/OU=Equifax Secure Certificate Authority
And that's the "good"/trusted CA. I'm not sure when they made the switch, but I only got this cert issued a couple of months ago.
FWIW, we also support Docomo phones, and that is a huge pain in the ass. The only CA that works there is:
i:/C=US/O=VeriSign, Inc./OU=Class 3 Public Primary Certification Authority
If you don't need to support really old mobile devices, the best certs going are, IMHO, Digicert. They get chained all the way back to Entrust:
1 s:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV CA-1 i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA 2 s:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA i:/C=US/O=Entrust.net/OU=www.entrust.net/CPS incorp. by ref. (limits liab.)/OU=(c) 1999 Entrust.net Limited/CN=Entrust.net Secure Server Certification Authority
And the company has some of the best customer service going anywhere.
Not only that, they check your installed cert after you buy it and email you if you installed it incorrectly: http://www.digicert.com/help/
That said, once I registered with a new account, the client certificate worked great.
CACert does.