cacert.org is trying just that for a long time. The hard part is the paperwork and procedures that give OS and browser vendors the trust to add you in their default config.
Well, that is with good reason. A rogue or insecure root CA which is trusted by major browsers/OS'ses would basically invalidate the whole CA system (see the DigiNotar affair from 2011).
Comments
cacert.org is trying just that for a long time. The hard part is the paperwork and procedures that give OS and browser vendors the trust to add you in their default config.
Well, that is with good reason. A rogue or insecure root CA which is trusted by major browsers/OS'ses would basically invalidate the whole CA system (see the DigiNotar affair from 2011).
The CNNIC root is still trusted by most browsers/OSes.
Sure, but it goes counter to "I wish someone could do a genuinely free SSL CA with "reasonable" procedures".
So bad news: it's hard. good news: people are trying.
More bad news: They're failing pretty hard. CACert have been around for a long time, and still haven't managed to get themselves audited.
There was an interesting thread on the subject on the crypto-list last year ("How much does it cost to start a root CA ?"), see eg:
http://lists.randombit.net/pipermail/cryptography/2013-Janua...
http://lists.randombit.net/pipermail/cryptography/2013-Janua...
http://lists.randombit.net/pipermail/cryptography/2013-Janua...
And for good measure, on the subject of certs and trust, the thread after:
"another cert failure" (2011)
http://lists.randombit.net/pipermail/cryptography/2013-Janua...