Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've used StartSSL in the past. I will never do so again.

Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.



Not my experience at all. It's easy and straightforward (really takes less than 10 mins). I have a bunch of startSSL certs in use. Before I started using startSSL certs I used Thawte certs.

Dealing with Thawte was HORRIBLE, these guys are extremely pushy (their sales reps repeatedly called me at home to 'convince' me I really should renew my certificates with them and wouldn't take no for an answer). Contrast that with startSSL where I had some questions and Eddy Nigg personally replied within minutes.

In summary, I highly recommend giving startSSL a shot.


I also found startSSL to be fine. It's not the most user friendly of websites, but by no means horrible.

I can see why you may want something simpler if you need 10+ certificates, but if you just want to set up SSL for something then startSSL is fine.


This hasn't been my experience. Their web site is ugly and lame but once you're logged in it's about a 3-step process to apply for the cert. Both times I was emailed within 10 minutes that my cert was ready, and it works fine.


I'll just chime in saying that my experience was smooth like this. I'd use them in the future myself.


Also worked super for us. Getting the cert. was a smooth process.


I second this experience, and "Lovecraftian" is indeed an excellent way to describe it. It's not just that the process was difficult, it's that my confidence dwindled through every strange and baffling step.

Since you mentioned paying "a few dollars" to Namecheap, can you comment on the feasibility of their $8.95 "PositiveSSL" certificate? ( http://www.namecheap.com/ssl-certificates/comodo.aspx )


The best (in terms of browser compatibility) cheap cert that Namecheap sell is the RapidSSL cert at http://www.namecheap.com/ssl-certificates/geotrust-ssl-certi...


Be aware though that GeoTrust and Thawte certs don't work[1] on android devices. There are claims that it can be fixed by adding a cross-root cert[2] but for me that didn't work out.

More generally: If you need to support mobile devices then read your CA's compatibility list closely (if you can find it...) and test, test, test. You'd think this shouldn't be an issue anymore in 2012, but it sadly still is.

[1] http://www.zimbra.com/forums/administrators/44675-new-geotru...

[2] https://support.servertastic.com/entries/426677-rapidssl-and...


Sigh. I spent way too much time picking these particular certs and they've gone and messed it up. :)

The cross-root cert should work, but you need to make sure it's presented in the right order, I think.

FWIW, my latest RapidSSL-through-Namecheap certs were issued by:

issuer=/C=US/O=Equifax/OU=Equifax Secure Certificate Authority

And that's the "good"/trusted CA. I'm not sure when they made the switch, but I only got this cert issued a couple of months ago.

FWIW, we also support Docomo phones, and that is a huge pain in the ass. The only CA that works there is:

i:/C=US/O=VeriSign, Inc./OU=Class 3 Public Primary Certification Authority

If you don't need to support really old mobile devices, the best certs going are, IMHO, Digicert. They get chained all the way back to Entrust:

1 s:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV CA-1 i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA 2 s:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance EV Root CA i:/C=US/O=Entrust.net/OU=www.entrust.net/CPS incorp. by ref. (limits liab.)/OU=(c) 1999 Entrust.net Limited/CN=Entrust.net Secure Server Certification Authority

And the company has some of the best customer service going anywhere.


If you don't need to support really old mobile devices, the best certs going are, IMHO, Digicert. They get chained all the way back to Entrust:

Not only that, they check your installed cert after you buy it and email you if you installed it incorrectly: http://www.digicert.com/help/


So does StartSSL.


This sites checks for SSL issues, including cert-related issues: https://www.ssllabs.com/ssldb/index.html


More precisely, older Android devices.


Not really. We've had the issues on Froyo devices, too...


I read it is pre-2.3 devices.


on my 2.3 android phone, I have this problem with a Comodo cheap certificate


actually fixed it now by installing the intermediate certificate chain


I have a Comodo certificate purchased through cheapssl.com. There is one problem: some older android 2.3 phones don't recognize it as valid and refuse to download any non-html data files.


fixed it by installing the intermediate chain on my server


Can you extrapolate on what you mean by feasibility, I use positive SSL on a few domains it works fine with no issues and isn't that hard to setup (basically you just need to be able to receive email on your domain).


I find their service excellent. The website doesn't have the latest hip look, but the service is solid, and they are very responsive and helpful in case you run into an issue. For a free service, that's impressive.


their support is excellent too, I've had Eddy Nigg (the founder) respond to emails within 10 minutes on several occasions.


My experience too. Excellent service and very fast turn-around.


The only complication is the fact that they use client side SSL certificates for authentication. I don't know of any other site which does this. Although I like that they're dog fooding, it probably would have been better if they'd stuck with a traditional username/password/cookie scheme for logging in, from a business/usability perspective.


It confused me a lot because I used to have an old username/password account with them and when I tried to sign in and got a very generic SSL error from Firefox.

That said, once I registered with a new account, the client certificate worked great.


> I don't know of any other site which does this.

CACert does.


We tried them but had to change to a different vendor because the Blackberries didn't recognize their certificates and they had no plans to rectify that. We don't have much BB traffic, but didn't want to exclude BB users just because we wanted to be cheap.


I disagree also. Their process is fine with me and very quick. I haven't had to contact them in a while, but when I did, got fast, intelligent response. StartCom/StartSSL is a breath of fresh air.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: