• expired

(StartSSL) 100% Trusted SSL Certificates - Free Forever

22

Having seen a few "deals" for SSL certificates recently. I thought I would draw everyone's attention to StartSSL, who provide FREE (as in beer) SSL certificates — no strings attached, no deal expiry, completely free forever.

These certificates are trusted by all major browsers, across all major versions. My understanding is that the only product to not trust these StartSSL certificates (by default) is the Java Runtime Environment (JRE).

Security Note:
Whilst these certificates are completely free, and fully trusted by major browsers; I do not recommend them if your website handles credit card data, personally identifiable data or confidential information; this is because I do not believe that StartSSL do not offer the same level of 'trustworthiness' as larger SSL providers such as VeriSign, RapidSSL, etc. So please use at your own discretion.

Related Stores

startssl.com
startssl.com

closed Comments

  • +3

    Haven't these ALWAYS been free…?
    Not really a bargain :)

    I remember using these in the 90's but back then they were only accepted by some browsers…

    • +1

      Yes, they have always been free, but the "awareness" level in the community is fairly low.
      I've never had a problem with them being not accepted by browsers (although I'm sure this was not always the case).

      • StartSSL have an "interesting" history, stories of blackmail, fraud, etc. That was a number if years ago now, but I'd still never use them for anything production.

        Testing, personal use, sure, go crazy!

    • Their website looks like from back in the 90s as well but it works and is free!

  • +3

    Free, until you need to re-issue your certificate then they charge you $35+, not worth it when you can get basic SSL certificates for ~$5/yr.
    https://www.techdirt.com/articles/20140409/11442426859/shame…

    Edit: Always been 'free', not a bargain/deal

  • +2

    Might be alright for non-critical testing environments. Would never put them anywhere near serious production setups. You get what you pay for.

    Agree that these are not a bargain. Have always had a free product as far as I have known.

  • -1

    Always free. Not a bargain/deal

  • Doesn't have the same level as trustworthiness ??? Get what you pay for? it's an SSL cert.

    The only trust issue would be for the customer/user as there's little checking that you are who you say you are. But since your browser apparently accepts these without warning (?) then that'd be the concern for the customer/user. For the site owner, I can't see what it matters who you buy off, unless you want insurance.

    As for the cost. It's like people buying their domain names from the old MelbIT for $35/yr, apart from perception (& possibly better service), there's not difference to the $10 crazydomain one,it's a domain!

    • +3

      No, the other (and in my opinion, the more important) "trust" issue is that the StartSSL is generating the key pair…so what happens to that key pair later. Perhaps those keys become available to criminal groups, government agencies, etc.

      Private keys can be used to steal credit card data, etc. The whole foundation of the SSL system, is one of trust and if the certificate provider is 'dodgy' then that destroys the integrity of your SSL configuration.

    • It's like people buying their domain names….

      It's not the domain, it's the level of access to/control of the domain once it exists. If it's with a low-security registrar, there's a risk that the domain could be stolen and given to someone else. If you Google "domain theft", there's been a bunch of them over the years.

      I'm not endorsing Melbourne IT, though.

      • Remember: two-factor authentication is your friend.

        • Doesn't help you at all when it's the registrar that is holding the domain hostage …

Login or Join to leave a comment