Where to get an SSL certificate for a small business
-
My wife and I are trying to start a business together and are developing a website for it. I know you can get free certificates from Lets Encrypt, but my understanding is that they're only meant for personal sites, not businesses. Where should I be going for a certificate suitable for a business but as cheap as possible given there's no revenue yet?
-
I've had a somewhat good sapie experience with The SSL Store but keep in mind you'll need to be sure your DUNS information is correct. That probably applies to most places, actually.
-
@Jaloopa I like CBT Solutions, they're cheap and seem to care. When I forgot about a DV certificate until the day before he stayed on the phone with Comodo for an entire hour to ram my order though in under a day.
Edit: Sorry @Tsaukpaetra, that was supposed to be a topic reply, must have fat-fingered it.
-
@Jaloopa letsencrypt is free to anyone, commercial or private. Unless you need a wildcard or EV cert they'll be fine
-
@sloosecannon they do wildcards too now, as of about a year ago
-
If you're already using cpanel, they have an autoSSL thing that can also automatically provide/refresh certificates without cost.
-
Let's Encrypt is perfectly fine to use for a for-profit website.
-
@ydna said in Where to get an SSL certificate for a small business:
they do wildcards too now, as of about a year ago
But if LE start doing EV certs (which are supposed to have extended levels of verification of the entity certified) then they run the risk of losing their own CA certification. EV certs cost because you're paying for extra bureaucracy; that's their whole point.
But they shouldn't be necessary for a small startup in most industries.
-
@dkf EV are worth less than nothing after browser UI changes.
We're using letsencrypt for all our customers. We've got to have 2-300 of them. It works well. I'd recommend using win acme if you're on windows.
I still need a better way to handle updates of certs on all my custom boxes at home (routers, DIY Nas etc).
-
@swayde said in Where to get an SSL certificate for a small business:
EV are worth less than nothing after browser UI changes.
What have those idiots done this time?
-
@ben_lubar said in Where to get an SSL certificate for a small business:
Let's Encrypt is perfectly fine to use for a for-profit website.
Case in point (for some definition of "for profit"):
-
@ydna Welcome back!
-
@dkf said in Where to get an SSL certificate for a small business:
@swayde said in Where to get an SSL certificate for a small business:
EV are worth less than nothing after browser UI changes.
What have those idiots done this time?
It's really for the best:
Note that almost all CAs still are using old browser screenshots when selling, to scam their customers out of more cash.
-
@swayde said in Where to get an SSL certificate for a small business:
Due to the CAs not doing their job and doing actual validation, and due to the fact that there could exist two different companies named say 'stripe', they've changed the UI to be less assertive.
Ugh. The right approach is to blacklist the CAs that don't follow the rules. This fucks those CAs (and their customers) over massively, and strongly encourages people to actually do their fucking jobs.
-
@dkf But no rule got broken: you can have two companies named "Stripe, inc" and simply try to register a certificate for a domain name which the more well-known Stripe didn't bother to buy.
-
@swayde said in Where to get an SSL certificate for a small business:
they've changed the UI to be less assertive
I am still getting company name on the EV ones and just closed padlock on the DV ones. But the only one where I would ever care of the difference is the online banking. A small business does not really need EV.