▲ 343 ▼ Letsencrypt is under US jurisdiction. Is there a free-er alternative? (sopuli.xyz) submitted 1 week ago by Sibbo@sopuli.xyz to c/selfhosted@lemmy.world 155 comments fedilink hide all child comments I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?
[–] victorz@lemmy.world 21 points 1 week ago (6 children) commercial free certificates How do they make money? permalink fedilink source parent hideshow 6 child comments replies: [–] bjoern_tantau@swg-empire.de 36 points 1 week ago (5 children) Usually they make money with extended certificates where they not only offer a certificate for example.com but also certify that it belongs to Example Ltd. Those extended certificates used to show the company name next to address bars, but I don't think browsers do that anymore. permalink fedilink source parent hideshow 5 child comments replies: [–] victorz@lemmy.world 6 points 1 week ago (4 children) a certificate for example.com also certify that it belongs to Example Ltd. I thought that was the whole point of a certificate, to show that the website belongs to the company? Or nah? permalink fedilink source parent hideshow 4 child comments replies: [–] bjoern_tantau@swg-empire.de 29 points 1 week ago (1 child) Nah, the point is to encrypt the traffic and tell you what you are receiving really comes from example.com and not an evil third party. permalink fedilink source parent hideshow 1 child comment replies: [–] victorz@lemmy.world 7 points 1 week ago Ah, right. That's the primary purpose, thank you for the reminder! 🙏 permalink fedilink source parent [–] WhyJiffie@sh.itjust.works 12 points 1 week ago (1 child) It's actually to prove that a web server belongs to (or is trusted by for delivering their content) a specific website. qualified certificates go a step further, by proving that a web server belongs to a specific company or a real person. but that's costly, because verification is inherently more difficult. permalink fedilink source parent hideshow 1 child comment replies: [–] victorz@lemmy.world 4 points 6 days ago Thanks for the additional details! permalink fedilink source parent
[–] bjoern_tantau@swg-empire.de 36 points 1 week ago (5 children) Usually they make money with extended certificates where they not only offer a certificate for example.com but also certify that it belongs to Example Ltd. Those extended certificates used to show the company name next to address bars, but I don't think browsers do that anymore. permalink fedilink source parent hideshow 5 child comments replies: [–] victorz@lemmy.world 6 points 1 week ago (4 children) a certificate for example.com also certify that it belongs to Example Ltd. I thought that was the whole point of a certificate, to show that the website belongs to the company? Or nah? permalink fedilink source parent hideshow 4 child comments replies: [–] bjoern_tantau@swg-empire.de 29 points 1 week ago (1 child) Nah, the point is to encrypt the traffic and tell you what you are receiving really comes from example.com and not an evil third party. permalink fedilink source parent hideshow 1 child comment replies: [–] victorz@lemmy.world 7 points 1 week ago Ah, right. That's the primary purpose, thank you for the reminder! 🙏 permalink fedilink source parent [–] WhyJiffie@sh.itjust.works 12 points 1 week ago (1 child) It's actually to prove that a web server belongs to (or is trusted by for delivering their content) a specific website. qualified certificates go a step further, by proving that a web server belongs to a specific company or a real person. but that's costly, because verification is inherently more difficult. permalink fedilink source parent hideshow 1 child comment replies: [–] victorz@lemmy.world 4 points 6 days ago Thanks for the additional details! permalink fedilink source parent
[–] victorz@lemmy.world 6 points 1 week ago (4 children) a certificate for example.com also certify that it belongs to Example Ltd. I thought that was the whole point of a certificate, to show that the website belongs to the company? Or nah? permalink fedilink source parent hideshow 4 child comments replies: [–] bjoern_tantau@swg-empire.de 29 points 1 week ago (1 child) Nah, the point is to encrypt the traffic and tell you what you are receiving really comes from example.com and not an evil third party. permalink fedilink source parent hideshow 1 child comment replies: [–] victorz@lemmy.world 7 points 1 week ago Ah, right. That's the primary purpose, thank you for the reminder! 🙏 permalink fedilink source parent [–] WhyJiffie@sh.itjust.works 12 points 1 week ago (1 child) It's actually to prove that a web server belongs to (or is trusted by for delivering their content) a specific website. qualified certificates go a step further, by proving that a web server belongs to a specific company or a real person. but that's costly, because verification is inherently more difficult. permalink fedilink source parent hideshow 1 child comment replies: [–] victorz@lemmy.world 4 points 6 days ago Thanks for the additional details! permalink fedilink source parent
[–] bjoern_tantau@swg-empire.de 29 points 1 week ago (1 child) Nah, the point is to encrypt the traffic and tell you what you are receiving really comes from example.com and not an evil third party. permalink fedilink source parent hideshow 1 child comment replies: [–] victorz@lemmy.world 7 points 1 week ago Ah, right. That's the primary purpose, thank you for the reminder! 🙏 permalink fedilink source parent
[–] victorz@lemmy.world 7 points 1 week ago Ah, right. That's the primary purpose, thank you for the reminder! 🙏 permalink fedilink source parent
[–] WhyJiffie@sh.itjust.works 12 points 1 week ago (1 child) It's actually to prove that a web server belongs to (or is trusted by for delivering their content) a specific website. qualified certificates go a step further, by proving that a web server belongs to a specific company or a real person. but that's costly, because verification is inherently more difficult. permalink fedilink source parent hideshow 1 child comment replies: [–] victorz@lemmy.world 4 points 6 days ago Thanks for the additional details! permalink fedilink source parent
[–] victorz@lemmy.world 4 points 6 days ago Thanks for the additional details! permalink fedilink source parent