Hacker News new | past | comments | ask | show | jobs | submit login

Will users be able to download their private keys for the provisioned cert?

If not, would CloudFlare ever consider provisioning free SSL certs for non-CloudFlare customers (i.e. let us uploade our crt file and you have your CAs sign it)? We desperately need an alternative to StartCom, since many devs don't trust them[1]. I've suggested AOL in another thread[2], but so far I can't find anyone who works there to talk to.

EDIT: To be clear, I'm very happy for this release and thanks to CloudFlare for stepping up.

[1] - https://bugzilla.mozilla.org/show_bug.cgi?id=1041087#c13

[2] - https://news.ycombinator.com/item?id=8374685




A private key should never be given to a third party (preferably not even a trusted one), and downloading the private key generated by CloudFlare would also negate the "private" feature. Furthermore, you don't upload a crt (certficate) file for a CA to sign, because that is the result of a CA's signature. You upload a certificate signing request (csr) after having generated a private key on the same machine where the key/certficate will be used; this way you are sure you have never lost control over the private key.

With respect to StartCom I don't really see the problem or why anyone would step up to offer something better for free. Certificates are a money making business and with StartCom you get the security you pay for ...


I believe the CEO said in their last post here that certificate pinning and custom certificates (even EV ones) would be supported by their new plans. (Can't remember if you have to pay $$$, though)

I imagine it will take a short amount of time after this change to realize that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: