SSLMate – Buy SSL certs from the command line
sslmate.com
sslmate.com
It looks like my dream is coming true!
Edit for anyone else curious about this: No, the letsencrypt CA isn't ready yet; there are test builds available for all of the software, but any certs you get will not be properly signed, and your users will get nasty browser warnings. Something to keep an eye on in the future, I guess.
It will matter if StartCom is abused to print certificates for foreign domains. Even if your domain isn't targeted, browsers and OS vendors will probably react by invalidating all StartCom CA certs. That means no green bar.
So, I doubt they would treat StartSSL any worse than they treated China.
A friend of mine got validated and he send me signed and working wildcard cert with multiple domains a few days ago - so it's a real thing I believe.
I was thinking of building an app which would be under two domains like heroku.com/herokuapps.com and github.com/github.io and I rather not spend hundreds of dollars on two wildcard certs. Guess I'll just buy one and not use subdomains on the main site.
A wildcard cert wouldn't cover both heroku.com and herokuapps.com anyway. https://en.wikipedia.org/wiki/Wildcard_certificate
For a large business with multiple sub-domains (mail..com, blog..com, info..com, anything.com, etc...), if the business purchases individual SSL certificate for each sub-domain it need to spend more money, and the process will be so long as generation of new CSR, private key, certificate installation, etc...
A Wildcard SSL secures unlimited sub-domains which saves time and money as well.
$150 is much higher for a wildcard SSL certificate, Visit CheapSSLSecurity (https://www.cheapsslsecurity.com) where you can get Wildcard SSL certificate at $60/year for Domain Validation and $108/year for organization validation.
Domain Validated (DV) certificates (the free ones, or cheap in sslmate's case) are just proof someone - we don't know who they are - has control of a domain. Hence Domain Validated - someone did something to prove they had control of the domain and was given a DV certificate.
They don't include your company name, company ID or physical address in the subject because there is no requirement for the CA to verify those things. Here's HN's DV certificate:
https://certsimple.com/images/blog/non-ev-subject.png
Now visit http://github.com - who have an EV certificate. It shows 'GitHub Inc' in a green bar on every web browser. Click the green bar, and compare the certificate details:
https://certsimple.com/images/blog/ev-subject.png
- you can actually see GitHub's registered in Delaware, with company ID 5157550, which matches their state registration: http://businessprofiles.com/details/github-inc/US-DE-5157550
- you can also see GitHub's office in San Francisco
That info has been manually verified by a CA - that's the extended validation in 'EV' - and that's why browsers show 'GitHub Inc' in green.
You can also see the difference using openssl:
openssl x509 -in example.com.crt -noout -text | grep Subject
DV cert: Subject: OU=Domain Control Validated, CN=billing.example.com
DNS:billing.example.com, DNS:www.billing.example.com
EV (green bar with company name) cert: openssl x509 -in example.com.crt -noout -text | grep Subject
Subject: 1.3.6.1.4.1.311.60.2.1.3=GB/businessCategory=Private Organization/serialNumber=09378892, C=GB, ST=City of London, L=London, O=example Limited, CN=billing.example.com, DNS:billing.example.com, DNS:www.billing.example.com
Disclaimer: I sell EV certs at https://certsimple.com. I specifically /don't/ sell DV certs, and we send people to https://letsencrypt.org if they really want a DV cert.Why do you charge 300$ for 2 characters? Like the "*." for a wildcard cert?
Wildcards are explicitly banned by browsers and CAs when making the EV requirements: otherwise you get *.company.com being used for bankofamerica.com.company.com like what happened with DV certificates.
See https://certsimple.com/blog/wildcard-ev-certificate
Edit, replying to BukhariH due to rate limit: that's an excellent question, and illustrates why server names are manually reviewed by a human. A company called 'Company' who asked for an EV cert for bankofamerica.com.company.com would be rejected during validation.
That doesn't make sense because the whole point of the green badge is that it shows the identity of who controls the website you're on.
So, even if someone were to do: bankofamerica.com.foobar.com; the green badge wouldn't say "Bank of America Corporation" so the user would know they're not on BoA...
CAs explicitly deny issuance to domains that have popular brand names in them - issuing a certificate for comodo.ian.sh would not be possible in most circumstances. I doubt the CA/B Forum wanted that workaround for EV as well.
That requirement only is so incredibly stupid and gives no more safety than not being there. Who draftet this crap, seriously?
What popular is changes rapidly, sometimes overnight.
That's correct. CAs also check for TLDs in unusual places (and unicode hacks, etc) in the requested SANs (Subject Alt Names, practically server names) during verification.
Name validation is supposed to, and generally does, forbid "." in the part represented by the .
DOMAIN=example.com sh -c 'openssl req -sha256 -nodes -new -newkey rsa:2048 -keyout "${DOMAIN}.key" -out "${DOMAIN}.csr" -subj "/C=US/CN=${DOMAIN}"'Thanks for the feedback about the credit card processing information. I'll think about how to make that information more prominent.
Where is the SSL key generated? If I create my own certificate and key, can I pass the signing request over sslmate to get it signed?
I couldn't find the answers to these questions on your FAQ or in the documentation.
Which is good, as sending you a key would be egregious incompetence from a cert vendor.
And at 15usd/year that is infinitively more expensive than lets encrypt.
So while I might use it today, I don't see how they plan to have much of a future.