Comment on StartCom charges for reissuing SSL certs due to HeartbleedparentComments−pgeorgi12ySure, but it goes counter to "I wish someone could do a genuinely free SSL CA with "reasonable" procedures".So bad news: it's hard. good news: people are trying.−M2Ys4U12ySo bad news: it's hard. good news: people are trying.More bad news: They're failing pretty hard. CACert have been around for a long time, and still haven't managed to get themselves audited.−e12e12yThere was an interesting thread on the subject on the crypto-list last year ("How much does it cost to start a root CA ?"), see eg:http://lists.randombit.net/pipermail/cryptography/2013-Janua...http://lists.randombit.net/pipermail/cryptography/2013-Janua...http://lists.randombit.net/pipermail/cryptography/2013-Janua...And for good measure, on the subject of certs and trust, the thread after:"another cert failure" (2011)http://lists.randombit.net/pipermail/cryptography/2013-Janua...
Comments
Sure, but it goes counter to "I wish someone could do a genuinely free SSL CA with "reasonable" procedures".
So bad news: it's hard. good news: people are trying.
More bad news: They're failing pretty hard. CACert have been around for a long time, and still haven't managed to get themselves audited.
There was an interesting thread on the subject on the crypto-list last year ("How much does it cost to start a root CA ?"), see eg:
http://lists.randombit.net/pipermail/cryptography/2013-Janua...
http://lists.randombit.net/pipermail/cryptography/2013-Janua...
http://lists.randombit.net/pipermail/cryptography/2013-Janua...
And for good measure, on the subject of certs and trust, the thread after:
"another cert failure" (2011)
http://lists.randombit.net/pipermail/cryptography/2013-Janua...