BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Who sells the least expensive SSL certs right now?
- Subject: [Discuss] Who sells the least expensive SSL certs right now?
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- Date: Tue, 23 Dec 2014 18:32:07 +0000
- In-reply-to: <CAJFsZ=qa62RkgX53W0t2rJrpAkT3bGVHuJ-E8Q=FRvBQnxcH_g@mail.gmail.com>
- References: <549251AB.8070607@horne.net> <54932731.1060401@gmail.com> <5493283A.6010407@horne.net> <CA+h9Qs63QnWrktgHaRstzAa9yLNPVVL1QUegx7sQwRXeymajqQ@mail.gmail.com> <5497701D.90103@horne.net> <CAFq0N1x37HaQkKD3gWEP8=CNQFnpvqupNsmVBmgKwQp5XL3S5Q@mail.gmail.com> <BN3PR0401MB12042C738604A70CDADFB62CDC560@BN3PR0401MB1204.namprd04.prod.outlook.com> <CAFv2jcZkz3pK-2OxLDZ75V7Bfs81s1M=YhY2e1R1Ji+LtDE3EQ@mail.gmail.com> <BN3PR0401MB1204EBCF93E4073CBD100C5BDC560@BN3PR0401MB1204.namprd04.prod.outlook.com> <CAFv2jcbUpP97QwwXVya4O0GXX8OCRS2cNWOeyPjk30KF_Onqrg@mail.gmail.com> <549883E1.7050605@gmail.com> <CAFrp2J0+G5tHFqEX5PHs-zNx0ExapO52SJ+FXQgYXTp5QQaF4A@mail.gmail.com> <CAMdng5vtCb=zqhAXXRqhbmhY4=Px_EQ4E6-0yOO0hnn3ujmV8w@mail.gmail.com> <BN3PR0401MB12045A735E9E5C80725C5D26DC560@BN3PR0401MB1204.namprd04.prod.outlook.com> <CAJFsZ=qa62RkgX53W0t2rJrpAkT3bGVHuJ-E8Q=FRvBQnxcH_g@mail.gmail.com>
> From: Bill Bogstad [mailto:bogstad at pobox.com] > > However, I am not sure why I would ever > bother to > revoke a certificate for a general purpose web site. Depends on your website. For https://nedharvey.com, I wouldn't bother with revocation. But for *.microsoft.com, if I were the admin there, you can bet your sweet buns I would follow through with revocation. Because if the private key were compromised, and some bad guys want to perform MITM attacks to compromise high value assets - that should be taken seriously. > As for someone > else spoofing my site with the stolen cert, I thought that it was > still possible to get certificates signed for almost any domain from > some of the CAs. In general, no, no random schmos out there can get a CA validated cert for a random domain. I'm not sure where you got your information, but it's almost completely rubbish in this case... The tiny grain of truth, which the above quote has conflated beyond sanity or reason, is this: The actual individuals who operate the CA, of course, could generate certs for any domain they don't own. Also, it's likely the President of China, probably has some way of getting a cert from Hong Kong Post. Which is a real thing that's really on Apple's and Mozilla's CA trust list. I'm guessing the POTUS and the CIA probably have ways of getting certs out of Verisign and others. Also, there have existed situations where some root CA sold intermediates to customer companies - the owners of those intermediates would then be able to sign stuff they didn't actually own. Speaking of Hong Kong Post - The list of root CA's distributed by Microsoft has 43 roots in it, all of which seem at least moderately trustworthy IMHO. Linux, Mozilla's and Apple's root trusts are over 140 roots, including various foreign governments (I named Hong Kong Post as an example. There are many others.)
- Follow-Ups:
- [Discuss] Who sells the least expensive SSL certs right now?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] Who sells the least expensive SSL certs right now?
- References:
- [Discuss] Who sells the least expensive SSL certs right now?
- From: bill at horne.net (Bill Horne)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: bill at horne.net (Bill Horne)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: jabr at blu.org (John Abreau)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: bill at horne.net (Bill Horne)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: jack at coats.org (Jack Coats)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Who sells the least expensive SSL certs right now?
- From: abreauj at gmail.com (John Abreau)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Who sells the least expensive SSL certs right now?
- From: abreauj at gmail.com (John Abreau)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: gcmarx at gmail.com (Gordon Marx)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: mark at buttery.org (Shirley Márquez Dúlcey)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Who sells the least expensive SSL certs right now?
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] Who sells the least expensive SSL certs right now?
- Prev by Date: [Discuss] Who sells the least expensive SSL certs right now?
- Next by Date: [Discuss] Who sells the least expensive SSL certs right now?
- Previous by thread: [Discuss] Who sells the least expensive SSL certs right now?
- Next by thread: [Discuss] Who sells the least expensive SSL certs right now?
- Index(es):