Re: Certificates -Annoyed



There are cheaper alternatives to verisign such as RapidSSL. You can even get free ones by generating them yourself or using sompelace like StartCom.

It actually looks like you are mixing several different things. .Net code signing is different from a verisign SSL certificate.
You don't need to purchase a certificate from anyone to sign your code. Just generate your own key-value pair.

I agree that Verisign is overpriced. However, you aren't actually paying them for the certificate. What you're really paying them to do is to vouch for you. Depending on how much you pay, they do various levels of due diligence to ensure you are who you say you are.

A certificate you generate yourself for free is every bit as secure from an encryption standpoint.

Andrew Faust

"Miro" <miro@xxxxxxxxx> wrote in message news:#WJksf1lJHA.3876@xxxxxxxxxxxxxxxxxxxxxxx
Is it just me, or is it just easier and cheaper not purchase a certificate from someone like verisign.

Perhaps I am missing the full reason for them, but I think my simple 'new solution' is the correct train of thought.
Please let me know if I am wrong - as my solution would not verify that the software came from you.

To fork over another 500 bux or so for a 'certificate' is ridiculous.
It strikes me as odd, that code signing is still popular, and why something isn't invented that points back to your .com domain name, that can verify that the software is yours.
For example, you put a datafile on your webserver that gets hit by your installation with a secure password and login.
Only you know the password / login and location of this file.

When the installation loads, ( and in it you specify the file / login / password ) in your .com, the login would either pass or fail.
A pass means that the software is yours.
A fail, means it is not.

Seems pretty simple to me, and pretty hard for someone to fake - as you are the only owner of your .com domain.

----just me rambling...

I just seem a bit ticked off that other people are profiting off a little digital certificate that really could have been invented better so that it didnt need to be created in the first place.

Anyone know of the cheapest place to get a certificate?

Miro


.



Relevant Pages

  • Digital sign a driver for XP and Vista
    ... My company has just bought a Class 3 certificate from Verisign to digitally sign some drivers. ... The driver is made up by a .inf file, a .sys file and a .dll file. ... SHA1 hash: 8FBE4D070EF8AB1BCCAF2A9D5CCAE7282A2C66B3 ...
    (microsoft.public.development.device.drivers)
  • Re: RSA vs AES
    ... > Verisign, MS took the extra burden of issuing a critical patch to ... > those stolen root CAs. ... if any of these other keys ever got compromised ... ... BBN Certificate Services ...
    (sci.crypt)
  • Re: Your digital ID name cannot be found by the underlying security system
    ... This morning I received email from VeriSign indicating that apparently I ... Although I do not have a private key recovery feature, ... replaced the certificate 3 times already and still it will not work. ...
    (microsoft.public.outlook)
  • Re: [Full-Disclosure] PGP vs. certificate from Verisign
    ... What I wonder - will Verisign have set up CRL servers yet? ... PGP vs. certificate from Verisign ...
    (Full-Disclosure)
  • Re: RWW VPN security problem ?
    ... with PoP 3 mail, hosted sites and small, inexpensive routers (Linksys, ... Paul P ... > certificate I do get a login screen. ...
    (microsoft.public.windows.server.sbs)

Loading