193 karma · joined April 10, 2024
Nikhef in Amsterdam.
Both are good options.
SMIME will also get an ACME standard for issuing. Including a handful of CAs that will likely issue free Certificates for it.
My guess is that noting will happen for now. It’s mostly a decision that ICANN working groups have to figure out. But given the current size of the .io zone and that we already have a non existing cctld (.su for Soviet Unite), I’m pretty confident it will exist in the mid-term future.
But yes a smother signup, potentially coupled with a prepaid credit (via 3-D Secure) and or eID would be the easiest and safest solution for everyone.
Atleast if it’s clearly stated how and why that is required.
They have their own internal security team, that handles activation on a case by case basis. Some users need to verify at the beginning, some after a week and other do not have to verify at all.
As you can imagine, at that price point, people will abuse the sh* out of the platform. From public posts it lookalike the main indicators are: - country you provided - IP based Country - Payment method - Payment method returned country - order size - order pattern (something like spawn a server, abuse stuff, order new OR many servers at the beginning)
Sadly you just need to wait. I wish they would have other solutions. But for now that’s it :-/
Email Infrastructure (for renewal etc.) can be acquired over different services like postmark.
Validation of contact data can be expensive too. However maybe something like nominatim could do the trick.
Another thing is infrastructure for Whois/RDAP.
Then you need standard things like Whois privacy (there is a document by icann for requirements).
There are even some open source implementations for the backends.
Most expensive points are the required employees and the signup fees (and prepaid) for other registry’s like .xyz
e.g. example.new should forward to a website that allowed to create examples?
We want to establish an alternative to Let’s Encrypt that is taking the core features and values from ISRG. That’s not based on “bad US!1!”, more then a alternative would strengthen the ecosystem. This also means to create an alternative ecosystem like boulder.
The current challenges are mostly about incorporating the non-profit and structure it right. So that it’s as open as possible.
Motivation? To help shape the security landscape and bring much wanted features that are not viable for Let’s Encrypt to implement. Viable describes that boulder would require major rewrites for it to get implemented.
Specially we want to provide SMIME and .onion certificates.
Section is based in the UK. Also no wild card.
ZeroSSL is based in Austria. But they are technically a reseller from Sectigo (using a branded intermediate.)
The US part is based on legal framework. Based on stuff like politics and such. So another jurisdiction, das would allow the same model then let’s encrypt, would add to the ecosystem more, then another one in der US.