Need a free SSL or mail certificate?

by Volker Weber

If you need a free Class 1 SSL or mail certificate, StartSSL is the way to go now. Thawte is closing down their freemail certificates, and Microsoft has just published a root certificate update which includes StartSSL root certificates. Other browsers and mail clients have had them for a while. So does Mac OS X:

startcomrootcert.png

If your visitors or mail receivers have the valid root cert, they will not be prompted to verify your certificate, a problem you often face with CAcert certificates.

More > (in german)

Comments

Huh? Thawte is closing their freemail certificates? Where did you get that information? I could not find any limitation on their homepage.

Ulf Jaehrig, 2009-09-26 18:14

@Ulf:
see
https://search.thawte.com/support/ssl-digital-certificates/index?page=content&id
=SO12658

Florian Steinel, 2009-09-26 19:15

Was there a notification to the notaries? I don't remember any.

I have a freemail certificate and I got an expiry notice, but I just thought I had to renew it (not done it yet)...
---
Expiry Date : 11/18/2009
Dear Alex Boschmans,
Your current thawte Personal E-mail Certificate/s are due to expire soon, details thereof as above.

If you would like to continue to use a thawte Personal E-mail Certificate, please request a new one, using your thawte ID and password to access your Personal E-mail Certification Account by logging in here.

thawte offers the following products in our SSL certificate range:
blablabla
---

Christopher: I am a Thawte Notary and got a notification of the shut-down on Thursday. Verisign are "giving away" a one year mail certificate to notaries, presumably in the hope that after a year we will forget the betrayal and start paying them money for nothing.

Alex: That's just the usual notice. Don't bother renewing; they are revoking the root authority in November.

Thanks, Simon, I am a notary too, just as vowe is, but I didn't get any notification. Maybe they aren't done sending them out yet.

I'm also a Thawte Notary and also got no notofication, anyway.

Sad, that you here only get Class 1 free and Class 2 (or Class 3) costs (even if they only cost 29,- anual fee) and even to become a StartSSL Notary you have to pay for the Class 2 Certificate. Understandable, but not necessary.

I'm also a Thawte notary and got no notification.

Anyhoo, I decided to try one of these StartSSL free certs on a Domino server - just to see if it works.

Skipped the first step in the process (generate private key) as Domino creates its own keyring and generates a certificate signing request.

Pasted the Domino CSR into the StartSSL Submit Certificate Request form and got this response:

MD5 Signature Algorithm Detected

* Your certificate request was created with a potentially weak signature algorithm.
* For more information please see this FAQ item.
* Please change the signature algorithm to SHA1 or better, create a new CSR and try it again!

This is on a Domino 8.0.1 server.

Anyone know if 8.5 or 8.5.1 implements a more secure signature algorithm for SSL?

Almost 2 weeks later I just got mail from Thawte about the discontinuation. They seem to be really slow with sending out their mails.

I am a Thawte Freemail user and a StartSSL notary. For Class 2, you don't *have* to pay if you are approved by an existing notary. Class 1 is still normal Freebies just like thawte. The only time that StartSSL asks that you pay for Class 2 is if you're wanting it *now* for professional reasons or if you want to be a Notary in a place where notaries aren't convenient.

So there are free options should you pursue it...

Don Fanning, 2009-10-12 22:17

And today I finally have my notification from Thawte. Slow is right.

Chris Linfoot, 2009-10-14 10:02

Me too. Strange. Can’t say I’ll miss the Notary process though; I got quite a lot of stick from strangers wanting me to travel all over the place for them.

123

gu xingjun, 2010-04-30 11:21

Post a comment











Shall I remember this for you?




Use your full name and a working email address. Unless you want your comment to be removed. No kidding.



Recent comments

john head on Which Notes client do you use? at 17:21
Kevan Emmott on Apple is having a bit of a problem with the iPhone at 16:18
Michael Kobrowski on Apple is having a bit of a problem with the iPhone at 14:34
Henning Heinz on Which Notes client do you use? at 14:33
Bryan McDade on Four generations of the iPhone at 12:44
Hanno Zulla on Lug und Trug von 1&1 at 11:41
Hubert Stettner on Apple is having a bit of a problem with the iPhone at 11:37
Stefan Domanske on Apple is having a bit of a problem with the iPhone at 11:32
Andreas Imnitzer on Which Notes client do you use? at 11:28
Volker Weber on Apple is having a bit of a problem with the iPhone at 11:26
Volker Weber on Apple is having a bit of a problem with the iPhone at 11:22
Andrew Dempster on Which Notes client do you use? at 11:22
Hubert Stettner on Apple is having a bit of a problem with the iPhone at 11:17
Martin Kautz on Apple is having a bit of a problem with the iPhone at 11:03
Albert Buendia on Which Notes client do you use? at 10:51
Reinhard Steurer on Which Notes client do you use? at 08:10
Maik Endler on Lug und Trug von 1&1 at 07:41
Detlev Buschkamp on Which Notes client do you use? at 06:04
Olaf Boerner on Which Notes client do you use? at 05:34
Bruce Elgort on Which Notes client do you use? at 01:05
Richard Moy on Which Notes client do you use? at 00:19
Timo Stamm on Lug und Trug von 1&1 at 23:46
Stephan Perthes on Four generations of the iPhone at 23:18
Andreas Braukmann on I think I want one at 23:05
Paul Mooney on Which Notes client do you use? at 22:50

Ceci n'est pas un blog

vowe.net is a personal website published by Volker Weber a.k.a. vowe. I am an author, consultant and systems architect based in Darmstadt, Germany.

rss Click here to subscribe

Hello

About me
Contact
Publications
Certificates
Frequently asked questions
Join the network

Twitter Updates

More >

Local time is 18:18

visitors.gif
159 visitors online

News

Other sources of news, imported into my own format to make them more accessible:

Schlagzeilen
Weather

Archives

As most of my articles roll off the front page rather quickly, I am making an archive of previous posts available here. You can also use the handy search box at the top of the page if you are looking for something particular.

Last 30 days
More archives

Got the T-shirt?

Got the T-shirt?

Systems Architecture

This site runs on an Apache web server on top of the Linux operating system. The content is managed with MovableType which is implemented in Perl. Last but not least the HTML code your browser sees is put together with PHP.

© 1992-2010 Volker Weber.
All Rights Reserved.

Impressum