So what you are saying is that because you can get an SSL cert free from startcom, that your hosting provider is paying you?
So what you are saying is that because you can get an SSL cert free from startcom, that your hosting provider is paying you?
https://forum.startcom.org/viewforum.php?f=8
After I saw the state of their forums/community I ran, not walked, away from their service. Which is rather scary considering they are a trusted CA...
I think really the only reasonable thing to do is pay $15/yr for any site that other people will use and use your own CA for your personal projects.
Getting CA certs into Android however is whole other issue...
I usually buy certs either through Gandi.net (which has a good "free certificate" program with its own domains), or COMODO through Namecheap as a reseller.
I understand they also have a pretty bad interface and terrible customer service.
They are not without fault, but they've much good for open source project and the like, and don't deserve the bad rap thrown at them in every thread that mentions SSL.
>If the CA or any of its designated RAs become aware that a Subscriber’s Private Key has been communicated to an unauthorized person or an organization not affiliated with the Subscriber, then the CA SHALL revoke all certificates that include the Public Key corresponding to the communicated Private Key.
There is no "if you pay them" condition to that. CAs are not supposed to make, or allow to stand, any signature on a compromised key—period.
Startcom's refusal to revoke all compromised public keys communicated to them after Heartbleed, and in fact their practice of charging for any revocation in general, is not in compliance with the baseline requirements for a CA.
As a result, Startcom should be removed from all browsers as a trusted CA. Let's Encrypt would be a very good replacement, especially if they also offer keys using ECC P-256 (and perhaps a subsequent replacement ECC algorithm).
> A certificate will be revoked when the information it contains is suspected to be incorrect or compromised.
and
> The subscriber’s key is suspected to be compromised;
>The technical content or format of the certificate presents an unacceptable risk;
StartCom (or any of CA) doesn't care about IP address.