
{"id":2415,"date":"2017-06-12T00:34:32","date_gmt":"2017-06-12T04:34:32","guid":{"rendered":"http:\/\/www.ikriv.com\/blog\/?p=2415"},"modified":"2017-06-12T00:34:32","modified_gmt":"2017-06-12T04:34:32","slug":"startcom-free-ssl-certificates-go-bust","status":"publish","type":"post","link":"https:\/\/ikriv.com\/blog\/?p=2415","title":{"rendered":"StartCom free SSL certificates go bust"},"content":{"rendered":"<p>StartCom certificate authority that hands out free SSL certificates, <a href=\"https:\/\/en.wikipedia.org\/wiki\/StartCom\">is no longer recognized by major browsers<\/a>. I&#8217;ve got their certificate back in May 2016, and it worked fine, but in October 2016 StartCom became involved in some sort of scandal, and their new certificates are not trusted by Mozilla, Chrome and Apple.<\/p>\n<p>The next best option I found is $5\/year &#8220;PositiveSSL&#8221; certificate from Comodo, obtained via <a href=\"https:\/\/www.ssls.com\">https:\/\/www.ssls.com<\/a>. If you know how to create a CSR, it takes about 10 minutes to get a certificate, and it appears to work fine.<\/p>\n<p>To be frank, the whole deal about SSL certificates is quite annoying. If you want an HTTPS web site, you need to get a domain name and a certificate. Domain names registrars are quite well regulated and the prices are uniform and stable: a regular domain costs $11-$15 a year, and it&#8217;s been on that level for a long time. On the other hand, the world of SSL certificates feels like Wild West and a big headache. In theory, Certificate Authorities are supposed to be the epitome of honesty and trust, but the reality is quite different.<\/p>\n<p>The sin of StartCom was that it was bought by WoSign, that engaged in some questionable practices, like back-dating issued certificates to avoid SHA1 decommission deadline. Additionally, both StartCom and WoSign kept denying the fact of purchase, which finally led for their removal from the list of CAs by Mozilla and others.<\/p>\n<p>Astonishingly, StartCom <a href=\"https:\/\/www.startcomca.com\/\">continues to sell SSL certificates<\/a>, some\u00a0for as high $200\/year. Their web site does not mention the scandal, or the fact that their certificates won&#8217;t work on Chrome, Firefox or Safari. There is a half-assed message at the bottom of the web page declaring that &#8220;<em>StartCom\u2122 \/ StartSSL\u2122 is supported by (Edge) (IE) (Android) (Microsoft Windows)<\/em>&#8220;, but it is intentionally ambiguous. In fact, I initially interpreted it as &#8220;Edge\/IE\/Windows and Android are our sponsors&#8221; (whatever that might mean).<\/p>\n<p>Regardless of StartCom story, it does not take much to obtain a fraudulent certificate: all you need is access to one of several e-mails associated with the domain: either <strong>admin@domain.com<\/strong>, or the one registered in whois.\u00a0Of course, lack of checks makes obtaining a certificate quick and cheap, but it also dilutes trust in the system.<\/p>\n<p>The price of the low-grade certificates varies greatly. The <a href=\"https:\/www.ssls.com\/\">ssls.com<\/a> web site, that sells certificates for $5\/year is affiliated with <strong>namecheap.com<\/strong>. <a href=\"https:\/\/www.namecheap.com\/security\/ssl-certificates.aspx\">Namecheap.com<\/a>\u00a0sells exactly the same certificates for $9\/year. The certificates are issued by neither ssls.com nor namecheap.com; they are issued by Comodo security authority. The cheapest certificate I could find on <a href=\"https:\/\/ssl.comodo.com\/comodo-ssl-certificate.php\">Comodo web site<\/a>\u00a0costs $77\/year.<\/p>\n<p>Such volatility, lack of transparency and great variation in prices is rarely a tell-tale sign of an honest business. And remember, once you switch your web site to HTTPS, there is no going back: you can redirect transparently from HTTP to HTTPS, but redirect in the opposite direction won&#8217;t happen unless you have a valid SSL certificate.\u00a0If your certificate is broken, the users will see &#8220;your connection is not secure&#8221; page, before the redirect to HTTP would get a chance to kick in. If your web site is HTTPS, you will have to renew your certificate, or lose your customers\/audience. If certificate prices went up, too bad, you will have to pay up or suffer the consequences.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>StartCom certificate authority that hands out free SSL certificates, is no longer recognized by major browsers. I&#8217;ve got their certificate back in May 2016, and it worked fine, but in <a href=\"https:\/\/ikriv.com\/blog\/?p=2415\" class=\"more-link\">[&hellip;]<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"Layout":"","footnotes":""},"categories":[1],"tags":[],"class_list":["entry","author-ikriv","post-2415","post","type-post","status-publish","format-standard","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/ikriv.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2415","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ikriv.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ikriv.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ikriv.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ikriv.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2415"}],"version-history":[{"count":1,"href":"https:\/\/ikriv.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2415\/revisions"}],"predecessor-version":[{"id":2416,"href":"https:\/\/ikriv.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2415\/revisions\/2416"}],"wp:attachment":[{"href":"https:\/\/ikriv.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2415"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ikriv.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2415"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ikriv.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2415"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}