Answer the question
In order to leave comments, you need to log in
Why do some organizations give out SSL for free?
In the search engine, it gives out a lot of links to a request for issuing free SSL certificates, one of which (organization) is Let's Encrypt . Doesn't this system introduce security issues? And the question itself is in the title: is the sole purpose of the organization in standardization through the issuance of free certificates?
Answer the question
In order to leave comments, you need to log in
So the question is "why some..." or "why Lets Encrypt"?
The question "why some ..." is better considered from the other side - why do people buy certificates, and what do they gain by giving away their value.
The certificate itself is worthless - it's just an encrypted data file. The value is not a file, but the fact that a certain office guaranteesthat the organization or person holding the key to this file is in fact the one they claim to be. As it is checked - yes it is very simple. If the certificate is signed by another certificate, then it is issued by this organization. How is it verified that this organization can be trusted? There is a special list of "root" organizations, which is entered either when the system is installed or when it is updated. And in this list - just the whole dog. Anyone can issue certificates, but not everyone will be trusted. On most mobile devices, this list is not edited, so it (the device) will only trust certificates issued by organizations listed in the list, and these are usually large offices - VeriSign, Thawte, Comodo ... If the certificate of the organization that issued your certificate is in this there is no list - the device torments with suspicions,
Is Lets Encrypt on this list? And FIG knows. Maybe there is, maybe not. Maybe today it is, but tomorrow it won't be. Or if it is, it is not a fact that the certificates issued by him will be recognized. Lets Encrypt issues free certificates for a period of 3 months , after which it issues new ones. The Lets Encrypt user is expected to supply scripts developed there that automatically renew certificates.
Почему некоторые организации выдают SSL бесплатно?
У вас неверное понимание сертификатов и инфраструктуры PKI
Как минимум прослушайте https://events.yandex.ru/lib/talks/2335/ - там часть про PKI как раз.
Дополнительно, прочитайте https://letsencrypt.org/docs/faq/
И вообще, какие сертификаты выпускают УЦ, где и как они используются и тд и тп.
После чего - напишите свой ответ на ваш вопрос. Уверен, вам понравится :D
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question