Comment on StartCom charges for reissuing SSL certs due to HeartbleedparentComments−dtech12yWell, that is with good reason. A rogue or insecure root CA which is trusted by major browsers/OS'ses would basically invalidate the whole CA system (see the DigiNotar affair from 2011).−cynix12yA rogue or insecure root CA which is trusted by major browsers/OS'ses would basically invalidate the whole CA systemThe CNNIC root is still trusted by most browsers/OSes.−pgeorgi12ySure, but it goes counter to "I wish someone could do a genuinely free SSL CA with "reasonable" procedures".So bad news: it's hard. good news: people are trying.−M2Ys4U12ySo bad news: it's hard. good news: people are trying.More bad news: They're failing pretty hard. CACert have been around for a long time, and still haven't managed to get themselves audited.−e12e12yThere was an interesting thread on the subject on the crypto-list last year ("How much does it cost to start a root CA ?"), see eg:http://lists.randombit.net/pipermail/cryptography/2013-Janua...http://lists.randombit.net/pipermail/cryptography/2013-Janua...http://lists.randombit.net/pipermail/cryptography/2013-Janua...And for good measure, on the subject of certs and trust, the thread after:"another cert failure" (2011)http://lists.randombit.net/pipermail/cryptography/2013-Janua...
Comments
Well, that is with good reason. A rogue or insecure root CA which is trusted by major browsers/OS'ses would basically invalidate the whole CA system (see the DigiNotar affair from 2011).
The CNNIC root is still trusted by most browsers/OSes.
Sure, but it goes counter to "I wish someone could do a genuinely free SSL CA with "reasonable" procedures".
So bad news: it's hard. good news: people are trying.
More bad news: They're failing pretty hard. CACert have been around for a long time, and still haven't managed to get themselves audited.
There was an interesting thread on the subject on the crypto-list last year ("How much does it cost to start a root CA ?"), see eg:
http://lists.randombit.net/pipermail/cryptography/2013-Janua...
http://lists.randombit.net/pipermail/cryptography/2013-Janua...
http://lists.randombit.net/pipermail/cryptography/2013-Janua...
And for good measure, on the subject of certs and trust, the thread after:
"another cert failure" (2011)
http://lists.randombit.net/pipermail/cryptography/2013-Janua...