Show HN: Fast and simple way to get EV SSL certificates
certsimple.com
certsimple.com
Creator of Certsimple here. I made CertSimple while applying for and waiting 3 weeks for GoDaddy to issue an EV certificate earlier this year. I looked around for existing companes that could verify and issue certificates without the complex steps. Every company I looked at had a hugely detailed registration process or didn't sell EV certificates - the ones that actually check your identity (like github, mozilla, stripe, and npm sites).
The main difference with Certsimple is the amount of work you have to do to get a certificate.The whole process of applying of a cert with CertSimple is now less than a minute.
This is because:
- We build the entire CSR command, including the subject for both Linux/Unix and Windows. There are no questions and answers. Just paste onto your server (using openssl or libressl on Unix and certreq on Windows) and paste the results. - We set correct the defaults for 2015 browsers (Chrome 41+ is now showing warnings for SHA1 certificates) - We automatically set the required encryption strength for an EV cert (2048 bits) - We check the CSR as soon as you paste it - We're quite specific about the information we ask for, don't repeatedly ask for the same thing, and a few other bits and pieces.
You won't really notice any of this, though: you'll just find it's really easy.
The best way to experience this is to try it - it only takes a few seconds we don't ask for payment until the process is complete.
10% of the profit from our certificates goes to The OpenBSD Foundation, GnuPG, the EFF or Open Rights Group (you pick your preferred source at the end of the order).
Mike
Given your donation to other projects being a big part of the endeavour, I think it would be good to show what your cost is, what the markup is and what ends up going to the other foundations. Although you don't have to put this up, I think it will help your conversion rate.
Is there anywhere in the site which lists what one should have before requesting the cert? Something like "have these documents at hand" (followed by a list of country-specific documents).
Certificates usually use the x509v3 object for 'Jurisdiction of Business Name' and this would point to the national / state level identifier. Ie, in the UK, Digicert looks up the company on Companies House and signs the UK company ID - the end-user doesn't supply the company ID, just the legal name, the verifying CA then checks the government authority to get the company ID. It would be similar in Brazil.
You can see the national company ID inside an EV cert from the browser, and also from openssl:
https://certsimple.com/blog/do-ev-ssl-certificates-have-bett...
One of the the things we're looking at is getting metrics on the parts that most people don't have, do better pre-arm people for verification.
That's backwards from what I'd expect. I'd expect to give the CNPJ, and the CA to get the company name from the government given the CNPJ.
- This is automatically in USD / EUR / GBP based on your IP location and country
- If you change the country it will update the pricing and also give you a local discount code
- I've added info on cert length to the front page too.
Clicking on "Get Started" scrolls up and expects me to start filling the form. Sleazy, very GoDaddy-ish, but OK, since it's on HN's frontpage, let's type in some junk and click the button -
{"err":"missing required field: preferredDonation"}
So not only doesn't the site show THE most important bit of information for the cert - the price - it apparently inflates it to offset the cost of the donation. Excellent. Apparently this is how one "promotes honesty in the SSL industry." --
EDIT - AH, apparently the prices are shown only if you come from HN. Lovely. Single domain EV certificates are €429,
multi domain certificates are €699.
Both last two years.
Vs. "$234 per year" of getting the cert directly from DigiCert - a price that can be knocked down by 10-15% by sending them a quick email. This works out to $421 or €399 and it includes direct support from them, which is pretty much what they are selling everyone as their primary competitive advantage.> Clicking on "Get Started" scrolls up and expects me to start filling the form. Sleazy, very sleazy.
Hi there - the only way to 'Get started' getting an EV cert is to start collecting the info for the CSR. I have the same opinion of GoDaddy as you do - if there's something I can do better here I'm open to suggestions.
I've adjusted the code to always show the prices on the first step without the HN link. Originally I used the drop down banner at the top because the banner is animated and prominent, but since it doesn't show up if there's no coupon code, I've moved it to the main page.
Digicert provide the verification and support (we also provide our own in addition). Your CertSimple order ID is a valid Digicert order ID, and you can call Digicert and quote the order ID we give you. We just make the application process simpler.
What browser/OS are you using? I'm having trouble replicating the bug you encountered.
Great work btw, I'm sure when the time comes for me to need EV cert, I will remember this and won't be shopping around. I wish you great success in this endeavour.
GeoTrust sells them for $125/yr[1].
Also a friendly reminder to everyone: Letsencrypt[2] will launch in mid-2015. From that point onwards SSL certificates are free.
[1] https://www.ssls.com/geotrust-ssl-certificates/true-business...
> $469 USD per year?
No. All certificates are two years - the big price is the total. I've made this more apparent on the front page.
If someone wants a non-EV cert we also recommend https://letsencrypt.org
We could easily sell non-EV certs - they can be generated in seconds as they don't require manual ID verification to make a quick buck, but I think poor identity verification is what got SSL into the current mess we're in. You'll note GitHub, Stripe, Mozilla and npm have EV certs. Make of that what you will.
Unfortunately letsencrypt doesn't do EV certs.
We compared Symantec (whose brands include GeoTrust) when deciding on a CA partner. We picked Digicert based on the issuance speed and business practices. Symantec upsell IE5-level export encryption as a security feature. We don't want to support that.
The CA we chose to partner with - Digicert - who we have the same prices as - sits in the middle of the market. They makes the certs for GitHub, Facebook, Intel, Yahoo, and Nintendo.
Didn't you rather mean to say "The DigiCert referral program pays us much better than GeoTrust"?
Or would GeoTrust somehow force you to participate in that IE5 upsell if you were to sell their EV-certs instead of DigiCerts?
> Or would GeoTrust somehow force you to participate in that IE5 upsell if you were to sell their EV-certs instead of DigiCerts?
Yes. The Symantec reseller agreement (remember, GeoTrust is a brand not a company) explicitly forbids you from contradicting their marketing.
Also: part of doing good in the world in not supporting people who trick others.
You state you only ask for payment at the end and it's $50 off for HN, but what is the regular price? It's nowhere on the site, which is quite intransparent.
Minor bug: after entering a server name I cannot edit, delete or reorder the entries anymore.
Major bug on submitting the form: {"err":"missing required field: preferredDonation"} This makes it look like you have not even tested the released version.
Hi there and thanks for the feedback!
You can enter as many server names as you like.
Wildcards aren't possible with EV certs - both of these are mentioned on the 'Server names' box. The feedback is appreciated though so I may make this information more prominent if I hear this repeatedly.
I'm currently looking into the bug you found - it hasn't shown up in testing. What browser/OS are you using?
Good job skirting this question. Trying to give you the benefit of doubt here, so mind giving us an answer on the regular price? Cheers
Feedback heard loud and clear - prices are now front and center on the site.
- I'm assuming you aren't signing the certificates yourself, so how do you as a business handle this? Do you do the actual verification of users, or do you just provide the basics then hand that off to your supplier?
- DigiCert (who I think are your supplier as they signed your certificate) charge $295 for a EV certificate, what the extra $174 your charge give me that they don't?
DigiCert are indeed our parter CA - they do Facebook, GitHub, Stripe and Yahoo's SSL certs. We looked at a number of CAs (and actually wrote code against their APIs when we were testing), and chose DigiCert based on a combination of EV verification time and business practices.
Our retail prices are the same as DigiCert's - I suspect you're looking at the 'per year' price on https://www.digicert.com/ev-ssl-certification.htm. With the HN discount, you get the ability to apply for a certificate in less than a minute combined with DigiCert's fast verification practices.
With CertSimple the big number is always the final price.
That includes unlimited server licenses, we don't try and upsell SGC, etc. We're actually really picky things like that, see: https://certsimple.com/about
We also provide customers with validation advice - eg, yesterday a customer was given various options by digicams but from experience doing a lot of EV validation I know one particular mechanism is much faster than the others. The certificate was turned around in 5 hours, for the same prices, with all the value CertSimple adds.
https://www.ssllabs.com/ssltest/analyze.html?d=certsimple.co...
Awesome concept, but agreed with the others that some basic details are lacking on the site.
http://monetizepros.com/blog/2014/5-trust-badges-that-can-in...
We're not a big fan of trust logos either - though if you do want one it's included. As well as the tests you mentioned, usertesting.com ran some tests where removing them aids conversion:
http://info.usertesting.com/OnDemandWebinarOptimizeYourWebFo... at 36:15
> This is a case study I borrowed from Pep at ConversionExcel, that tested this for one of his clients. This is the original one"
https://certsimple.com/images/blog/trust-seals-stop-conversi...
> I'll show you the variation here. He removed some from fields, he also treated the copy copy and he also removed the stuff over here (the trust seals), so there's multiple things going on.
https://certsimple.com/images/blog/removing-trust-seals-conv...
> What I want to show you is that =the version without all the other stuff and the trust seals converted better=.
https://certsimple.com/images/blog/removing-trust-seals-conv...
There's also another study (trying to find link) where they found making your own trust logo improved conversions.
As with the nature of user testing: other people's results may not apply to you. Measure yourself.
Can anyone tell me why certs can't work in the same way as DKIM, where you include the certificate fingerprint in a DNS text record? Is DNS not secure enough? and if not why is it good enough for email?
DKIM is vulnerable against that, but the impact of doing so is lower (breaking anti-spam vs being able to intercept HTTPS)
Just use StartSSL.
Free or $60 for two years if you need subdomain wildcards.
Class 1 certificates are limited to client and server certificates, whereas the later is restricted in its usage for non-commercial purpose only. Subscribers MUST upgrade to Class 2 or higher level for any domain and site of commercial nature, when using high-profile brands and names or if involved in obtaining or relaying sensitive information such as health records, financial details, personal information etc.
Also, isn't there any CA that gives away wildcard certs for free? It's the only reason I'm sticking with CACert...
http://www.startssl.com/?app=37
Revocations carry a handling fee, except for Extended Validation SSL Certificates
http://www.startssl.com/extended-validation-application-requ...
StartSSL don't do EV (edit: they do, just not for $60).
We only do EV, since we actually identifying companies is how SSL should have always been.
$60 is way too much to pay for non-EV, an automated process that doesn't check who you are. If you want a non-EV certificate, wait a couple of months and use https://letsencrypt.org
They say they do. See the page http://www.startssl.com/?app=40
Wildcards don't exist for EV (non-EV certs allow you to register *.whatever.com, then make github.com.whatever.com).
Totally agreed re SANS. I'd like that to change too. Once we switch to evergreen browsers, some of the newer CAs will hopefully shake up the market a little.
Side note: all certificates these days are SANS (ie, nearly everyone has non-www and www, and the actual CN isn't looked at except as a fallback in old IE).
The CA handles the verification, hence the difference in price. Symantec/Verisign is the most expensive, Digicert is in the middle, Comodo and the Symantec budget brands are the cheapest.
As mentioned elsewhere, I do have code written against the Comodo API, and it would be a lot more profitable to use them. However I (and the tech companies I'm targeting, eg, Stripe, GitHub) use Digicert certs, mainly for reasons of verification speed but also business practice compared to competitors, eg, Comodo: https://blog.hboeck.de/archives/866-PrivDog-wants-to-protect...