Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: Re: Good SSL providers
PostPosted: Sun Aug 25, 2013 1:47 pm 
Offline
Senior Member
User avatar

Joined: Tue Apr 13, 2004 6:54 pm
Posts: 833
Yeah, SSL Certs are similar to ssh keys, but they're X509 format.

You would have had to click a button to accept the certificate into your browser.

Wildcard SSL certificates will not do cross-domain; a cert for *.sturmkrieg.com will not work for *.ssu.it; you'll need at least two wildcard SSL certs for that.

_________________
Rgds
Stephen
(Linux user since kernel version 0.11)


Top
   
 Post subject: Re: Good SSL providers
PostPosted: Sun Aug 25, 2013 1:58 pm 
Offline
Senior Newbie

Joined: Fri Mar 08, 2013 5:47 am
Posts: 15
Inquisitor Sasha wrote:
That is stronger, but they do a poor job of explaining that, plus I failed to see where anything was being downloaded to.


It's explained on their enroll page and their FAQ details how to back up your certificate.

http://www.startssl.com/?app=32

http://www.startssl.com/?app=25#4


Top
   
 Post subject: Re: Good SSL providers
PostPosted: Tue Aug 27, 2013 1:21 pm 
Offline
Senior Member

Joined: Wed Jan 21, 2009 7:13 pm
Posts: 126
Location: Portugal
Just to let you know: http://lowendtalk.com/discussion/12984/ ... 2nd-intake


Top
   
 Post subject: Re: Good SSL providers
PostPosted: Tue Aug 27, 2013 4:46 pm 
Offline
Senior Member

Joined: Fri Jul 03, 2009 2:31 am
Posts: 54
ICQ: 897607
neo wrote:
Ox- wrote:
I use StartSSL for small un-important sites. Free is a great price and there's nothing wrong with the certs. I just wouldn't use them for security critical sites because StartSSL has been compromised in the past.


I think a few of you guys misunderstand how the whole system works. In order to impersonate your web site to the clients, all I need is a certificate for your web site issued by any of certificate providers. In other words, if I can compromise StartSSL, than I can impersonate your web site, no matter where you got your certificate from.


Correct, but (usually) a compromised CA is removed from root certificates. This, in affect, revokes your cert. I say usually because StartCOM seems to be an exception. I think they take security seriously, and I wouldn't even be surprised if they are more "hardened" than most CA's, but it still makes me hesitant to use them for a high security site.


Top
   
 Post subject: Re: Good SSL providers
PostPosted: Tue Aug 27, 2013 5:11 pm 
Offline
Senior Member

Joined: Sat May 02, 2009 12:44 am
Posts: 92
Ox- wrote:
neo wrote:
Ox- wrote:
I use StartSSL for small un-important sites. Free is a great price and there's nothing wrong with the certs. I just wouldn't use them for security critical sites because StartSSL has been compromised in the past.


I think a few of you guys misunderstand how the whole system works. In order to impersonate your web site to the clients, all I need is a certificate for your web site issued by any of certificate providers. In other words, if I can compromise StartSSL, than I can impersonate your web site, no matter where you got your certificate from.


Correct, but (usually) a compromised CA is removed from root certificates. This, in affect, revokes your cert. I say usually because StartCOM seems to be an exception. I think they take security seriously, and I wouldn't even be surprised if they are more "hardened" than most CA's, but it still makes me hesitant to use them for a high security site.

Many of certificate providers have been compromised over the years (not only StartCOM) and most of those are still in the browser's root certificates list.

The only security aspect of this system that actually does work (protection of client/server communication from anyone who can not compromise ANY of the providers), works equally well with certificate from ANY provider.


Top
   
 Post subject: Re: Good SSL providers
PostPosted: Tue Aug 27, 2013 7:05 pm 
Online
Senior Member
User avatar

Joined: Thu Nov 24, 2011 12:46 pm
Posts: 139
Location: Mesa AZ
nfn wrote:


Gave one a shot for a test domain. Just like any different process, but it was easy to use and install. Even without the promo, $10 a year for a wildcard low level cert is not bad.

_________________
Kevin a.k.a. Dweeber


Top
   
 Post subject: Re: Good SSL providers
PostPosted: Wed Aug 28, 2013 7:32 am 
Offline
User avatar

Joined: Wed Aug 28, 2013 6:41 am
Posts: 1
Website: http://i205.photobucket.com/albums/bb202/toshroger/4544636064_3ee171cbcd_o.jpg
Location: Germany
Had awful experience with godaddy in the past and their pricing policy is just strange. More recently I tried the same provider Ox- mentioned - getssl.me and had a great experience with them. However for non-profit/personal websites startssl is a no-brainer.

_________________
freebsd geek


Top
   
 Post subject: Re: Good SSL providers
PostPosted: Thu Aug 29, 2013 12:45 am 
Offline
Senior Member
User avatar

Joined: Wed Jun 26, 2013 1:53 am
Posts: 118
nfn wrote:


Looks like that's good. $10 per year for a wildcard SSL. That's doable with pricing also, with just 4-5 domains.

_________________
Homepage www.sturmkrieg.com
Social network Gamernet
Development website Sashaweb Development
Imageboard img.sturmkrieg.com
WikiHub free wiki host Community Wiki


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: Dweeber and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group