Anonymous Monk has asked for the wisdom of the Perl Monks concerning the following question:

What have the monks experiences been with SSL certificate providers? Who do you feel is the top provider? verisign? thawte? What are some common pitfalls to look out for?

Any advice on getting started with SSL and acquiring certificates would be appreciated.

Replies are listed 'Best First'.
Re: SSL Certificate Providers
by jonnyfolk (Vicar) on Jul 14, 2003 at 06:56 UTC

    When I used an SSLprovider a long while ago, I went for Thawte as they were much cheaper. I believe that they are now owned by Verisign and if they are still cheaper then I don't think Verisign is worth extra.

    I did a quick check on Google and you might want to look at this link for a range of products, and there's some interesting (I think!) info here

      Excellent Links! Thanks! :)

      I was actually thinking just a few hours ago about why a very low cost CA hadn't been setup using an open group approach. Does anyone have any experience with FreeSSL? 128-bit certificates for $35 that are compatible with 96% of browsers sounds almost too good to be true :)

      Thanks again :)

        The problem is that certificates are not just meaningless strings of bytes. You can make one right now, for free, using openssl.

        What your paying for is someone actually researching and verifying that you are who your say you are. And that they are willing to vouch for your identity. Your also paying for having their trusted root installed in a variety of SSL implementations, so you don't have to worry about establishing the base trust.

        Given Verisign's problems w/ DNS, and a very high-profile case where they accidentally gave out a cert that was identified a non-MS'er as Microsoft Corperation, I'd stay away from them. Thawte, which I believe is still owned in part by verisign, seems to still be managed by themselves.

        Outside of Verisign & Thawte, there unfortunatly arn't that many providers that share that wide installed base as them.

Re: SSL Certificate Providers
by tcf22 (Priest) on Jul 13, 2003 at 23:00 UTC
    I would personally go with Verisign. That is who I use whenever I need a cert, and have never experienced a problem.

      How much is the standard cost for a single e-commerce site? I was under the impression it was ~300 but looking at verisign's site, it appears closer to 1200 for a 128-bit certificate. Thanks.

        Yeah, thats what a Verisign cert will cost you. Luckily, I've never bought one with my own money, its always been for my company.
Re: SSL Certificate Providers
by Mr_Person (Hermit) on Jul 14, 2003 at 16:12 UTC
    I've had good luck with InstantSSL. Prices start at $49 and they claim 99.3% browser compatibility.