Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

StartSSL's free cert don't support wildcards and the revocation of a cert is $25 per, which can be a problem (it was during Heartbleed).

I understand they also have a pretty bad interface and terrible customer service.



What would you expect if you are not paying for the cert? For me revocation was not an issue. I just got a new cert under a different subdomain as I don't use subdomains on my personal site and the main domain is added as an alt name.


What I would expect is for every CA to comply with the CAB/Forum Baseline Requirements, § 10.2.4:

>If the CA or any of its designated RAs become aware that a Subscriber’s Private Key has been communicated to an unauthorized person or an organization not affiliated with the Subscriber, then the CA SHALL revoke all certificates that include the Public Key corresponding to the communicated Private Key.

There is no "if you pay them" condition to that. CAs are not supposed to make, or allow to stand, any signature on a compromised key—period.

Startcom's refusal to revoke all compromised public keys communicated to them after Heartbleed, and in fact their practice of charging for any revocation in general, is not in compliance with the baseline requirements for a CA.

As a result, Startcom should be removed from all browsers as a trusted CA. Let's Encrypt would be a very good replacement, especially if they also offer keys using ECC P-256 (and perhaps a subsequent replacement ECC algorithm).


Interesting case. This seems to contradict their own CPS as well, 4.1.9:

> A certificate will be revoked when the information it contains is suspected to be incorrect or compromised.

and

> The subscriber’s key is suspected to be compromised;

>The technical content or format of the certificate presents an unacceptable risk;


There was never any conformation that all/most/any startcom used/issued keys/certs were leaked so they were never under any obligation really.


That's not a correct response to Heartbleed... It could have been easily exploited to get your private key and certificate, and not revoking it leaves it valid.


I don't "expect" anything, I'm giving reasons why startssl might not be an option.


It's quite reasonable pricing. It's less than most CAs does for a one year certificate, and revoking it is more work than issuing it in the first place.

They are not without fault, but they've much good for open source project and the like, and don't deserve the bad rap thrown at them in every thread that mentions SSL.


There was no bad rap in the thread until btreecat decided to be an ass. The only other subthread mentioning startssl is https://news.ycombinator.com/item?id=8904105 which only notes that as far as he can see letsencrypt is similar to startssl's delivery/validation process and seems to be vulnerable to mitm.


No need for rude personal attacks thank you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: