nailer 11 years ago

Hi HN,

Creator of Certsimple here. I made CertSimple while applying for and waiting 3 weeks for GoDaddy to issue an EV certificate earlier this year. I looked around for existing companes that could verify and issue certificates without the complex steps. Every company I looked at had a hugely detailed registration process or didn't sell EV certificates - the ones that actually check your identity (like github, mozilla, stripe, and npm sites).

The main difference with Certsimple is the amount of work you have to do to get a certificate.The whole process of applying of a cert with CertSimple is now less than a minute.

This is because:

- We build the entire CSR command, including the subject for both Linux/Unix and Windows. There are no questions and answers. Just paste onto your server (using openssl or libressl on Unix and certreq on Windows) and paste the results. - We set correct the defaults for 2015 browsers (Chrome 41+ is now showing warnings for SHA1 certificates) - We automatically set the required encryption strength for an EV cert (2048 bits) - We check the CSR as soon as you paste it - We're quite specific about the information we ask for, don't repeatedly ask for the same thing, and a few other bits and pieces.

You won't really notice any of this, though: you'll just find it's really easy.

The best way to experience this is to try it - it only takes a few seconds we don't ask for payment until the process is complete.

10% of the profit from our certificates goes to The OpenBSD Foundation, GnuPG, the EFF or Open Rights Group (you pick your preferred source at the end of the order).

Mike

  • bulte-rs 11 years ago

    So, when the process is complete... how much will you bill me?

    • nailer 11 years ago

      Edit: since a number of people have asked, I have added pricing to the first step - ie, the front page of the site.

      - This is automatically in USD / EUR / GBP based on your IP location and country

      - If you change the country it will update the pricing and also give you a local discount code

      - I've added info on cert length to the front page too.

      • detaro 11 years ago

        per what time frame? You really are missing BASIC information in your communications.

        • nailer 11 years ago

          Edit: prices in local currency and cert length are now on the front page of the site.

          • detaro 11 years ago

            Checkout (after generating a CSR etc) is really a bit late for that information.

            • nailer 11 years ago

              You're right. Fixed.

      • selectnull 11 years ago

        Those prices should really be published on the homepage, be loud and clear.

        Great work btw, I'm sure when the time comes for me to need EV cert, I will remember this and won't be shopping around. I wish you great success in this endeavour.

      • huhtenberg 11 years ago

        Erm ... I don't see the price anywhere on the linked page.

        Clicking on "Get Started" scrolls up and expects me to start filling the form. Sleazy, very GoDaddy-ish, but OK, since it's on HN's frontpage, let's type in some junk and click the button -

          {"err":"missing required field: preferredDonation"}
        

        So not only doesn't the site show THE most important bit of information for the cert - the price - it apparently inflates it to offset the cost of the donation. Excellent. Apparently this is how one "promotes honesty in the SSL industry."

          --
        

        EDIT - AH, apparently the prices are shown only if you come from HN. Lovely.

          Single domain EV certificates are €429, 
          multi domain certificates are €699. 
          Both last two years.
        

        Vs. "$234 per year" of getting the cert directly from DigiCert - a price that can be knocked down by 10-15% by sending them a quick email. This works out to $421 or €399 and it includes direct support from them, which is pretty much what they are selling everyone as their primary competitive advantage.

        • mikemaccana 11 years ago

          (Mike here, replying with my old openid account as I'm submitting too fast)

          > Clicking on "Get Started" scrolls up and expects me to start filling the form. Sleazy, very sleazy.

          Hi there - the only way to 'Get started' getting an EV cert is to start collecting the info for the CSR. I have the same opinion of GoDaddy as you do - if there's something I can do better here I'm open to suggestions.

          I've adjusted the code to always show the prices on the first step without the HN link. Originally I used the drop down banner at the top because the banner is animated and prominent, but since it doesn't show up if there's no coupon code, I've moved it to the main page.

          Digicert provide the verification and support (we also provide our own in addition). Your CertSimple order ID is a valid Digicert order ID, and you can call Digicert and quote the order ID we give you. We just make the application process simpler.

          What browser/OS are you using? I'm having trouble replicating the bug you encountered.

        • nailer 11 years ago

          PS. the missing field error is now resolved.

      • bulte-rs 11 years ago

        Thanks for the update; much appreciated. Will keep this in mind for the next time I need an EV.

  • alex_hitchins 11 years ago

    Really like the site and will probably use it when the next needing an EV cert.

    Given your donation to other projects being a big part of the endeavour, I think it would be good to show what your cost is, what the markup is and what ends up going to the other foundations. Although you don't have to put this up, I think it will help your conversion rate.

    • nailer 11 years ago

      Thanks! That's a great idea and I'm looking to publish some stats after the first month.

  • cesarb 11 years ago

    I'm not interested in an EV cert at the moment, but just for curiosity: which information is required for an EV cert? The front page only has "business name", "country", "city", "state", and server names. I'd expect it to ask at least for a CNPJ (the Brazilian tax identifier, every company has one, it's the "primary key" for businesses in this country) when the selected country is Brazil, for instance.

    Is there anywhere in the site which lists what one should have before requesting the cert? Something like "have these documents at hand" (followed by a list of country-specific documents).

    • mikemaccana 11 years ago

      Official guidelines are here: https://cabforum.org/wp-content/uploads/EV-V1_5_2Libre.pdf

      Certificates usually use the x509v3 object for 'Jurisdiction of Business Name' and this would point to the national / state level identifier. Ie, in the UK, Digicert looks up the company on Companies House and signs the UK company ID - the end-user doesn't supply the company ID, just the legal name, the verifying CA then checks the government authority to get the company ID. It would be similar in Brazil.

      You can see the national company ID inside an EV cert from the browser, and also from openssl:

      https://certsimple.com/blog/do-ev-ssl-certificates-have-bett...

      One of the the things we're looking at is getting metrics on the parts that most people don't have, do better pre-arm people for verification.

      • cesarb 11 years ago

        > the end-user doesn't supply the company ID, just the legal name, the verifying CA then checks the government authority to get the company ID.

        That's backwards from what I'd expect. I'd expect to give the CNPJ, and the CA to get the company name from the government given the CNPJ.

moe 11 years ago

$469 USD per year? (EDIT: The actual price is $234/yr, as clarified by mike below)

GeoTrust sells them for $125/yr[1].

Also a friendly reminder to everyone: Letsencrypt[2] will launch in mid-2015. From that point onwards SSL certificates are free.

[1] https://www.ssls.com/geotrust-ssl-certificates/true-business...

[2] https://letsencrypt.org/

  • mikemaccana 11 years ago

    Mike from CertSimple here, from my old openid account (as I'm replying too fast with my other one):

    > $469 USD per year?

    No. All certificates are two years - the big price is the total. I've made this more apparent on the front page.

    If someone wants a non-EV cert we also recommend https://letsencrypt.org

    We could easily sell non-EV certs - they can be generated in seconds as they don't require manual ID verification to make a quick buck, but I think poor identity verification is what got SSL into the current mess we're in. You'll note GitHub, Stripe, Mozilla and npm have EV certs. Make of that what you will.

    Unfortunately letsencrypt doesn't do EV certs.

    We compared Symantec (whose brands include GeoTrust) when deciding on a CA partner. We picked Digicert based on the issuance speed and business practices. Symantec upsell IE5-level export encryption as a security feature. We don't want to support that.

    The CA we chose to partner with - Digicert - who we have the same prices as - sits in the middle of the market. They makes the certs for GitHub, Facebook, Intel, Yahoo, and Nintendo.

    • moe 11 years ago

      We compared [..] GeoTrust [..] when deciding on a CA partner. [...] Symantec upsell IE5-level export encryption as a security feature. We don't want to support that.

      Didn't you rather mean to say "The DigiCert referral program pays us much better than GeoTrust"?

      Or would GeoTrust somehow force you to participate in that IE5 upsell if you were to sell their EV-certs instead of DigiCerts?

      • mikemaccana 11 years ago

        No, not really. I have code written for the Comodo API from before I spoke to Digicert. I would get a MUCH larger cut for that than I do Digicert.

        > Or would GeoTrust somehow force you to participate in that IE5 upsell if you were to sell their EV-certs instead of DigiCerts?

        Yes. The Symantec reseller agreement (remember, GeoTrust is a brand not a company) explicitly forbids you from contradicting their marketing.

        Also: part of doing good in the world in not supporting people who trick others.

  • Buge 11 years ago

    EV certificates will not be free.

raimue 11 years ago

Nice project, but while the design has a appealing simplicity, the details on the site are poor. What kind of certificate do I get (wildcard possible, how many domain names, ...)? How will the business and domain owner be verified? And most important: what is the price tag?

You state you only ask for payment at the end and it's $50 off for HN, but what is the regular price? It's nowhere on the site, which is quite intransparent.

Minor bug: after entering a server name I cannot edit, delete or reorder the entries anymore.

Major bug on submitting the form: {"err":"missing required field: preferredDonation"} This makes it look like you have not even tested the released version.

  • nailer 11 years ago

    Edit: I've now added pricing to the front page of the site, in the currency (USD/EUR/GBP) matching your IP location. I've also added certificate length too.

    Hi there and thanks for the feedback!

    You can enter as many server names as you like.

    Wildcards aren't possible with EV certs - both of these are mentioned on the 'Server names' box. The feedback is appreciated though so I may make this information more prominent if I hear this repeatedly.

    I'm currently looking into the bug you found - it hasn't shown up in testing. What browser/OS are you using?

    • izolate 11 years ago

      > ...what is the regular price? It's nowhere on the site, which is quite intransparent.

      Good job skirting this question. Trying to give you the benefit of doubt here, so mind giving us an answer on the regular price? Cheers

      • mikemaccana 11 years ago

        Mike, openid account here:

        Feedback heard loud and clear - prices are now front and center on the site.

  • nailer 11 years ago

    Just following up: that missing field bug is now resolved.

lucaspiller 11 years ago

Looks interesting, but I have a couple of questions:

- I'm assuming you aren't signing the certificates yourself, so how do you as a business handle this? Do you do the actual verification of users, or do you just provide the basics then hand that off to your supplier?

- DigiCert (who I think are your supplier as they signed your certificate) charge $295 for a EV certificate, what the extra $174 your charge give me that they don't?

  • mikemaccana 11 years ago

    (Mike here: posting from my old openid account because 'you're submitting too fast')

    DigiCert are indeed our parter CA - they do Facebook, GitHub, Stripe and Yahoo's SSL certs. We looked at a number of CAs (and actually wrote code against their APIs when we were testing), and chose DigiCert based on a combination of EV verification time and business practices.

    Our retail prices are the same as DigiCert's - I suspect you're looking at the 'per year' price on https://www.digicert.com/ev-ssl-certification.htm. With the HN discount, you get the ability to apply for a certificate in less than a minute combined with DigiCert's fast verification practices.

    With CertSimple the big number is always the final price.

    That includes unlimited server licenses, we don't try and upsell SGC, etc. We're actually really picky things like that, see: https://certsimple.com/about

  • nailer 11 years ago

    Oh and to answer the other part of your question: we provide certificate application, CSR verification, and order validation before using digicert for EV verification.

    We also provide customers with validation advice - eg, yesterday a customer was given various options by digicams but from experience doing a lot of EV validation I know one particular mechanism is much faster than the others. The certificate was turned around in 5 hours, for the same prices, with all the value CertSimple adds.

dankohn1 11 years ago

There's little evidence that Extended Validation improves conversion (while appallingly, adding a Symantec logo seems to).

http://monetizepros.com/blog/2014/5-trust-badges-that-can-in...

shawabawa3 11 years ago

SSL Certs are the biggest racket on the internet.

Can anyone tell me why certs can't work in the same way as DKIM, where you include the certificate fingerprint in a DNS text record? Is DNS not secure enough? and if not why is it good enough for email?

  • detaro 11 years ago

    DNS is not secured in any way (by default, DNSSEC is not that widely deployed yet and also not without flaws), therefore putting the fingerprint in DNS does nothing for protection against man-in-the-middle attacks.

    DKIM is vulnerable against that, but the impact of doing so is lower (breaking anti-spam vs being able to intercept HTTPS)

ck2 11 years ago

Stop supporting the SSL cartel.

Just use StartSSL.

Free or $60 for two years if you need subdomain wildcards.

http://www.startssl.com/?app=40

  • currysausage 11 years ago

    NB: On p. 12, section 3.1.2.1, the policy [1] states:

    Class 1 certificates are limited to client and server certificates, whereas the later is restricted in its usage for non-commercial purpose only. Subscribers MUST upgrade to Class 2 or higher level for any domain and site of commercial nature, when using high-profile brands and names or if involved in obtaining or relaying sensitive information such as health records, financial details, personal information etc.

    [1] http://www.startssl.com/policy.pdf

  • Ao7bei3s 11 years ago

    And $24.90 if you need a certificate revoked. Very helpful. Not.

    Also, isn't there any CA that gives away wildcard certs for free? It's the only reason I'm sticking with CACert...

  • detaro 11 years ago

    Don't use StartSSL, they are shady and often a hassle to deal with. If you don't need EV certs, hope that "let's encrypt" comes of the ground quickly.

    • mhb 11 years ago

      That has not been my experience. What issues did you have?

  • mikemaccana 11 years ago

    Mike from CertSimple here (using old openid account as my other one is replying too fast):

    StartSSL don't do EV (edit: they do, just not for $60).

    We only do EV, since we actually identifying companies is how SSL should have always been.

    $60 is way too much to pay for non-EV, an automated process that doesn't check who you are. If you want a non-EV certificate, wait a couple of months and use https://letsencrypt.org

feld 11 years ago

You can impress me by not charging a ridiculous extra amount for wildcard or UCC certificates. They cost you nothing to generate. It's a scam.

  • mikemaccana 11 years ago

    Mike from CertSimple, replying from ye-olde-openid account:

    Wildcards don't exist for EV (non-EV certs allow you to register *.whatever.com, then make github.com.whatever.com).

    Totally agreed re SANS. I'd like that to change too. Once we switch to evergreen browsers, some of the newer CAs will hopefully shake up the market a little.

    Side note: all certificates these days are SANS (ie, nearly everyone has non-www and www, and the actual CN isn't looked at except as a fallback in old IE).

    • feld 11 years ago

      I didn't notice that CertSimple was EV-cert only. I can't imagine anyone requiring an EV cert for a wildcard... :-)

detaro 11 years ago

$50 off from what?

freerk 11 years ago

gogetssl.com sells Comodo EV certs for 126$/1y or 221$/2y. certsimple costs more than twice as much. And I am not sure if there is actually such a big difference between the verification process since both are just resellers of another CA...

  • mikemaccana 11 years ago

    Mike here using old openid account, as I'm replying too fast.

    The CA handles the verification, hence the difference in price. Symantec/Verisign is the most expensive, Digicert is in the middle, Comodo and the Symantec budget brands are the cheapest.

    As mentioned elsewhere, I do have code written against the Comodo API, and it would be a lot more profitable to use them. However I (and the tech companies I'm targeting, eg, Stripe, GitHub) use Digicert certs, mainly for reasons of verification speed but also business practice compared to competitors, eg, Comodo: https://blog.hboeck.de/archives/866-PrivDog-wants-to-protect...

eps 11 years ago

The site is unusable on iPhone.