Show HN: TinyCert – Certificates as a service
tinycert.org
tinycert.org
Not being able to trust that you're talking to who you think to are seems like a serious example of "not safe".
Teaching users to click through the warning screen is a serious anti-pattern; the reason browsers keep making it scarier / harder is to try to stop the security theatre that occurs when using untrusted certs.
"For what would I use TinyCert certificates? Any place you would use (or should have used) self-signed certificates. Don't leave admin panels, such as phpMyAdmin, a CMS or a webmail install without some protection to keep your password from being intercepted. Use them to protect your test and development installations. Use them on your local POP or IMAP servers. Or use them to test your own code involving certificates." - https://www.tinycert.org/faq#use
I can't control what people do with the certificates, but I'm recommending against the use of TinyCert certificates for the public web. When used as intended, only people who have themselves generated and installed the TinyCert certificates (or their associates if so instructed) will see them and click past. Anybody else should get the big scary warning and will hopefully, rightfully, heed it.
1024-bit RSA certificates are considered deprecated, no longer issued, and if they don't already throw browser warnings then they will soon.
It's great utilities like this that can help introduce you as a developer in a crowded community.
I believe in karma - put something out there for others and it will come back in droves. So, really cool little tool, thank you! And thanks for making it free, I hope Karma treats you well!
Edit: formatting
The commands really aren't that complicated. You can (and really should) learn how to do this if you need to issue certificates.
Also, deleting CA's doesn't seem to work.
As for why to trust it... you won't know to trust me any more than a real CA. With a real CA you also only have their word. I've taken as many steps as I can to ensure that the private keys are not kept unencrypted anywhere where this is not needed (and they are only needed when signing something and when you request a download) and that the passphrase is in flight as short as possible.
While anything is theoretically possible with enough malicious intent, I've made the selling private keys or issuing certificates with your private key without your consent as exceedingly difficult as possible for myself.
It was just a front end to a back end that didn't exist yet, but it's brought back some nice memories. Thanks!
Same nickname as the OP and tweets about tinycerts.