Skip to content

Comment on StartCom charges for reissuing SSL certs due to Heartbleedparent

Comments

cacert.org is trying just that for a long time. The hard part is the paperwork and procedures that give OS and browser vendors the trust to add you in their default config.

Well, that is with good reason. A rogue or insecure root CA which is trusted by major browsers/OS'ses would basically invalidate the whole CA system (see the DigiNotar affair from 2011).

A rogue or insecure root CA which is trusted by major browsers/OS'ses would basically invalidate the whole CA system

The CNNIC root is still trusted by most browsers/OSes.

Sure, but it goes counter to "I wish someone could do a genuinely free SSL CA with "reasonable" procedures".

So bad news: it's hard. good news: people are trying.

So bad news: it's hard. good news: people are trying.

More bad news: They're failing pretty hard. CACert have been around for a long time, and still haven't managed to get themselves audited.

There was an interesting thread on the subject on the crypto-list last year ("How much does it cost to start a root CA ?"), see eg:

http://lists.randombit.net/pipermail/cryptography/2013-Janua...

http://lists.randombit.net/pipermail/cryptography/2013-Janua...

http://lists.randombit.net/pipermail/cryptography/2013-Janua...

And for good measure, on the subject of certs and trust, the thread after:

"another cert failure" (2011)

http://lists.randombit.net/pipermail/cryptography/2013-Janua...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.