BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] free certs everywhere
- Subject: [Discuss] free certs everywhere
- From: tmetro+blu at gmail.com (Tom Metro)
- Date: Mon, 22 Dec 2014 22:43:13 -0500
- In-reply-to: <BN3PR0401MB12045A735E9E5C80725C5D26DC560@BN3PR0401MB1204.namprd04.prod.outlook.com>
- References: <549251AB.8070607@horne.net> <54932731.1060401@gmail.com> <5493283A.6010407@horne.net> <CA+h9Qs63QnWrktgHaRstzAa9yLNPVVL1QUegx7sQwRXeymajqQ@mail.gmail.com> <5497701D.90103@horne.net> <CAFq0N1x37HaQkKD3gWEP8=CNQFnpvqupNsmVBmgKwQp5XL3S5Q@mail.gmail.com> <BN3PR0401MB12042C738604A70CDADFB62CDC560@BN3PR0401MB1204.namprd04.prod.outlook.com> <CAFv2jcZkz3pK-2OxLDZ75V7Bfs81s1M=YhY2e1R1Ji+LtDE3EQ@mail.gmail.com> <BN3PR0401MB1204EBCF93E4073CBD100C5BDC560@BN3PR0401MB1204.namprd04.prod.outlook.com> <CAFv2jcbUpP97QwwXVya4O0GXX8OCRS2cNWOeyPjk30KF_Onqrg@mail.gmail.com> <549883E1.7050605@gmail.com> <CAFrp2J0+G5tHFqEX5PHs-zNx0ExapO52SJ+FXQgYXTp5QQaF4A@mail.gmail.com> <CAMdng5vtCb=zqhAXXRqhbmhY4=Px_EQ4E6-0yOO0hnn3ujmV8w@mail.gmail.com> <BN3PR0401MB12045A735E9E5C80725C5D26DC560@BN3PR0401MB1204.namprd04.prod.outlook.com>
Edward Ned Harvey (blu) wrote: > If that argument holds, then *no* certificate authority should be > able to charge for issuing certs. That's a good idea. No, seriously. It doesn't appear that a central organization holds sway over CAs, unlike they way ICANN rules over domain registries, but if there is such an organization, they could have mandated that the requirements for becoming a CA included that they offer free basic certs (but could charge what they like for more advanced certs and add-ons). If all CAs had to do this, the burden of providing basic certs would be spread evenly across the industry (or at least proportional to their respective marketing budgets). Unlike domains, there is an unlimited supply of certs. No need to create an artificial scarcity. As StartSSL proved, automation can vastly reduce the cost of supplying such certs. Probably a big reason this never happened is that when CAs were being established, all that existed were basic certs. The extended validation certs and other value added services were only thought up later. Once the industry was established, hard to correct for that lost opportunity. There is always the possibility that if free certs from "Let's Encrypt CA"[1] become popular and widely accepted, commercial CAs will see a significant loss in basic cert business, and choose to offer free certs as a loss-leader to get customers in the fold. 1. http://www.mail-archive.com/discuss%40blu.org/msg09949.html Gordon Marx wrote: > Which is why the free cert, pay for revocation model makes so much > sense -- signing a CSR takes a one-time hit of some tiny amount of CPU > and bandwidth, whereas hosting an OCSP responder or equivalent takes a > lot more money and effort. Cert revocation is hard, and when things > are hard to do companies can often charge money to do them :--) Sure, but that's an artifact of the revocation infrastructure being poorly designed. Reality today, but it doesn't need to stay that way. (OCSP is comparatively the "high tech" way to do it, but by default I don't think any mainstream browser makes use of it (I have it enabled in my browsers). Due to stubbornness or belief that OCSP fails to adequately solve the problem (it does have issues), browsers stuck with unscalable certificate revocation lists (CRLs). "Security Now" spent an episode or two on current cert revocation tech and alternatives.) -Tom -- Tom Metro The Perl Shop, Newton, MA, USA "Predictable On-demand Perl Consulting." http://www.theperlshop.com/
- Follow-Ups:
- [Discuss] free certs everywhere
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free certs everywhere
- References:
- [Discuss] Who sells the least expensive SSL certs right now?
- From: bill at horne.net (Bill Horne)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: bill at horne.net (Bill Horne)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: jabr at blu.org (John Abreau)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: bill at horne.net (Bill Horne)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: jack at coats.org (Jack Coats)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Who sells the least expensive SSL certs right now?
- From: abreauj at gmail.com (John Abreau)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Who sells the least expensive SSL certs right now?
- From: abreauj at gmail.com (John Abreau)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: gcmarx at gmail.com (Gordon Marx)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: mark at buttery.org (Shirley Márquez Dúlcey)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Who sells the least expensive SSL certs right now?
- Prev by Date: [Discuss] Who sells the least expensive SSL certs right now?
- Next by Date: [Discuss] Who sells the least expensive SSL certs right now?
- Previous by thread: [Discuss] Who sells the least expensive SSL certs right now?
- Next by thread: [Discuss] free certs everywhere
- Index(es):