Free SSL/TLS Certificates

So far, I see 3 ways to get free SSL certificates.

CAcert.org

As of March 2nd, 2016, https://www.cacert.org/ produces the error “This certificate was signed by an untrusted issuer”. Chrome’s Security Overview states “There are issues with the site’s certificate chain (net::ERR_CERT_AUTHORITY_INVALID).”.

This is probably related to the news item [Re-Signing Root Certificate CAcert Blog](http://blog.cacert.org/2015/12/re-signing-root-certificate/), which has apparently been postponed.

Conclusion: ccert.org is not a good option.

StartSSL™ Certificates & Public Key Infrastructure

I haven’t looked very closely, as I’m more interested in LetsEncrypt right now.

Well, I used this experimentally to create a cert that I didn’t really need. But I installed the cert anyway (in place of a wildcard cert), and it works perfectly. It’s an internal app, and not high traffic. Haven’t seen any problems with the cert over the last couple days.

For more insight into personal and organizational validation for startssl.com, see [Pitfall-Free Howto/Guide to StartCom/StartSSL Class 2 Organization Validation/Certification MuchTall.com](https://www.muchtall.com/2013/05/22/pitfall-free-howto-guide-to-startcom-startssl-class-2-organization-validation-certification/).

Let’s Encrypt - Free SSL/TLS Certificates

LetsEncrypt has significant public backing right now, and I think that goes a long way to ensuring its near-future reliability.

LetsEncrypt apparently allows up to 100 domain names on each certificate. This makes it especially attractive for our internal app and all the alternate and subdomains that 3rd parties use to communicate with the app.

Let’s Encrypt does have rate limits, but they appear to address certificate create rather than limits on client traffic for certificate validation. See Rate Limits for Let’s Encrypt.

A guide, some client scripts (because the official client may not be ideal), and a more comprehensive list of available clients:


And one more source for free ssl/tls certs I’ve come across from a Chinese company.

WoSign Free SSL Certificates