Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


[not working solution] 5 year WildCard SSL for 0.1BTC (~37usd) - Page 4
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

[not working solution] 5 year WildCard SSL for 0.1BTC (~37usd)

124»

Comments

  • NeoXiDNeoXiD Member
    edited December 2014

    @deadbeef said:
    I notice that a lot are concerned about re-issuing? Why do you need to re-issue if the cert is not ip bound?

    • Changing the domain
    • Losing your private key(s)
    • Someone breached into one of your systems, keys might be stolen
    • Be dumb and issue a SHA1 certificate, which is going to be deprecated soon.

    These are the things that come to my mind.

    Thanked by 1deadbeef
  • Thank you for your answers.

    Tbh, I don't see how any of these reasons is of plausible concern for a wildcard ssl that costs ~$7/year. I mean, how often does one lose his sensitive files or get the pk stolen. Certainly it may happen, but the $32 is hardly the most significant problem in those cases.

    I didn't know you could re-issue to a different domain though, thanks for mentioning it.

  • @NeoXiD said:
    These are the things that come to my mind.

    changing the domain isn't possible and it's SHA 256 by default. So if you store your private key securely, I don't think a reissue is needed.....

  • I was talking about reissueing in general. There are some companies within the certificate mafia which allow some changes to the domain name.

    Also, SHA256 is unfortunately still not set as default everywhere. Some companies still sign with SHA1 if not specified otherwise in the CSR.

  • Nah, what I meant by it is that I rather have full control over things. If I ever needed the ability to reissue for whatever reason, I like having the options. I had to reissue SSL's after the recent SHA1 issues, but that's all. So, if you buy a 5 year SSL and you bought it let's say two months ago, you can't get it reissued so you have to go and buy another one. Seems legit I guess if you like throwing away $32. Sad thing is that Globalsign themselves allow you to reissue so I'm not sure why it isn't possible with them. By the way, I do sell GlobalSign SSL's and I have the ability to do it for my customers. Thanks.

  • @NeoXiD said:
    I was talking about reissueing in general. There are some companies within the certificate mafia which allow some changes to the domain name.

    Also, SHA256 is unfortunately still not set as default everywhere. Some companies still sign with SHA1 if not specified otherwise in the CSR.

    You're right. Not everyone issue SHA 256 by default, although that's not the case here. But after thinking about what @XFS_Duke said, like after a year or two, if there is any major upgrade like this, and if I can't reissue, what will I be doing with it? :(

  • NeoXiDNeoXiD Member
    edited December 2014

    @emdad SHA2 is available since years and for a long time, no one cared. Same thing goes for the MD5-->SHA1 migration, it took ages. It will be completely deprecated in 2017, luckily Google now started with pushing sysadmins to SHA2 earlier. I highly doubt though, that there's going to be any breaking changes within the next 5 years, which would render your cert unuseful.

    Thanked by 1emdad
  • Come on you guys...

    Why are you thinking about issues that might come up in the near future.
    The price of this 5-year Wildcard SSL is lower then almost all 1-year Wildcard SSL prices.
    And it is already SHA256.

    So if something happens on the 2st of January 2016 and you have to "re-issue", then you did not throw any money away, because this is still cheaper.

    Thanked by 2NeoXiD deadbeef
  • henkb said: So if something happens on the 2st of January 2016 and you have to "re-issue", then you did not throw any money away, because this is still cheaper.

    Nope.
    http://www.lowendtalk.com/discussion/47292/wildcard-ssls-from-issl-asia-and-probably-from-sslcertificate-cn-too-revoked

  • henkbhenkb Member

    That's a shame :(

  • M66BM66B Veteran
    edited March 2015

    @M66B said:

    I am wondering if this thread will turn into a complain thread after one year when everybody has to renew his certificate.

    What did I say? It seems to be even worse.

  • Yeah I got revoked my wildcard ssl today

  • I think we should rather do further discussion in the thread that was created today instead of reviving that offer thread. Makes it easier to follow what's going on.

    http://lowendtalk.com/discussion/47292/important-wildcard-ssls-from-issl-asia-sslcertificate-cn-ssl-so-etc-revoked#latest

This discussion has been closed.