Free SSL/TLS Certificate Authority

But with no Windows XP support, even latest SP3 is not supported :/.

Sorry if my sarcasm detector is broken - but if not...

I wonder why? Surely it can't be due to the fact that it is a dead operating system that had support for over 12 years before Microsoft pulled the plug! I understand legacy applications exist in many environments, but continuing to navigate on the internet using Windows XP is an absolutely AWFUL idea.

If you have to do this you should be using firefox as your browser, as I believe it has its own SSL system built in that may allow the use of letsencrypt as a CA.

If you don't want to pay for a new OS, look into something like http://linuxmint.com or http://www.ubuntu.com/desktop
 
or ask all those WinXP users to switch to Firefox as it has it's own internal SSL implementation so doesn't rely on WinXP systems one :)
I hope I can contact them? :) What if they are guest user's :).
I will still support XP until GA reports 5% below usage.
 
An fyi, but it is possible that wosign is going to get a large number of certs blacklisted due to a complete lack of security in their SSL cert issue system.

http://www.percya.com/2016/08/chinese-ca-wosign-faces-revocation.html
https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/k9PBmyLCi8I
https://www.schrauger.com/the-story-of-how-wosign-gave-me-an-ssl-certificate-for-github-com

In July 2016, it became clear that there was some problems with the
StartEncrypt automatic issuance service recently deployed by the CA
StartCom. As well as other problems it had, which are outside the scope
of this discussion, changing a simple API parameter in the POST request
on the submission page changed the root certificate to which the
resulting certificate chained up. The value "2" made a certificate
signed by "StartCom Class 1 DV Server CA", "1" selected "WoSign CA Free
SSL Certificate G2" and "0" selected "CA 沃通根证书", another root
certificate owned by WoSign and trusted by Firefox.

Yikes!
 
Last edited:
If you use WHM, then you have free SSL via autoSSL, and if you use Cloudflare as your DNS, then you have like 15 year free TLS at a time, so no renewals every year or two.
 
Firefox is now proposing to de-trust new certs from Wosign and StartCom for a year, with provisiongs to totally de-trust both CA's if they backdate certs. (ref)
 
I also have a Certficate from Startcom,
It's valid for one more year. Is it going to work for one more year or is Firefox going to block my certificate in a few months?

I will not renew with Startcom but can I use the certificate for one more year without problems?
That's not really clear to me...
 
I will not renew with Startcom but can I use the certificate for one more year without problems?
Assuming wosign/startcom aren't caught backdating certs you should be fine. If they are, Mozilla/Firefox plan to de-trust the entire CA chain.
 
Assuming wosign/startcom aren't caught backdating certs you should be fine. If they are, Mozilla/Firefox plan to de-trust the entire CA chain.
Ok, thanks :)
I just noticed my class 2 certification expires in March so I will switch to Comodo then.
I don't trust Startcom anymore. But it was easy and cheap to have all my domains on 1 certificate.
 
Top Bottom