Zentyal Forum, Linux Small Business Server

Zentyal Server => Installation and Upgrades => Topic started by: sixteenornumber on December 10, 2012, 03:28:22 am

Title: trusted cert?
Post by: sixteenornumber on December 10, 2012, 03:28:22 am
is there any possible way to to get trusted certs without paying for them?  This is for personal use only.  I'm tired of the constant security warnings.
Title: Re: trusted cert?
Post by: christian on December 10, 2012, 09:45:03 am
You don't need such "trusted" certificate  8)

There is something not well understood about certificates nowadays: trusting certificate is only matter of... trust  :)
I'm not joking: if you trust certificate exposed by server you access (here, e.g. your Zentyal server), you can easily add Zentyal CA in the list of trusted CA and you will jot be warned anymore.

Reason why you are not warned with most of the public CAs is that editors like Microsoft, Mozilla etc... include these CA in the list of trusted CA. This doesn't prevent to buy certificate from public CA company that is not in the list of default trusted CA.

So for personal use only, save some money and use your own CA that you trust  ;)
Title: Re: trusted cert?
Post by: sixteenornumber on December 10, 2012, 10:17:10 am
ok that's fine but I have yet to force firefox or chrome to "trust" them.  I was under the impression that it was hard coded to not accept them.
Title: Re: trusted cert?
Post by: christian on December 10, 2012, 10:47:59 am
there is nothing hardcoded but initial list of "trusted CAs" to which you can add your own.

The pity is that such list is not unique: I mean that on Windows (Microsoft) platform, IE, Firefox and Java  do not share the same list, so you may have to trust same CA multiple times.
Title: Re: trusted cert?
Post by: Marcus on December 10, 2012, 07:54:39 pm
Hello sixteenornumber,

> is there any possible way to to get trusted certs without paying for them?
Yes!  Please visit this website: https://www.startssl.com/

Best,

Marcus
Title: Re: trusted cert?
Post by: sixteenornumber on December 11, 2012, 09:54:39 pm
thx