Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 23 Jan 2001 01:15:08 +0100
From:      Roelof Osinga <roelof@nisser.com>
To:        Ted Mittelstaedt <tedm@toybox.placo.com>
Cc:        cjclark@alum.mit.edu, "'Arcady Genkin'" <antipode@thpoon.com>, freebsd-questions@FreeBSD.ORG
Subject:   Re: imap and pop3 via stunnel (was: UW-IMAP server and secure  authentication)
Message-ID:  <3A6CCD0C.4ECBD8AD@nisser.com>
References:  <012f01c0846d$d1b55ec0$1401a8c0@tedm.placo.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Ted Mittelstaedt wrote:
> 
> ...
> However, I can say that in my capacity as the guy that gets asked
> the question at the ISP I work for, the single biggest reason that
> people DON'T pursue SSL is because they perceive that a SSL cert
> costs $100 or more.  Now, maybe to you that's not a lot of money (to me
> it's not a lot either) but it seems to be to most of the folks publishing
> websites on our servers that accept credit cards via forms and whatnot.
> Now, maybe we don't have SCORES of people with websites, but we
> have a far higher number of websites that take credit cards with
> no SSL at all, then sites that take cards and have SSL.  (and,
> please let's not go into how bad this is, I know and the site
> owners have been told but they do it anyway.  They probably also
> drive SUV's too.)

Quite a rant. My compliments <g>.

I fear you're not far of the mark. Though there's also disinterest
to calc in. So long as the manure hasn't hit the fan, who cares?

They look outside, see the sun shining and think that life ain't
so bad after all.

Also, they - the CA's that be - give a new meaning to red-tape.
I decided to bite the bullet and get meself a Real Certificate
instead of using a self-signed one (e.g. https://nisser.com/
or, for a sparkling new one, https://nl.nisser.com/).

Though they - Thawte in this case, I believe now part of VeriSign
hence NSI (yack, pshaw, phoeyee!) - claim to answer any and all
question they do not give the answer I want to hear <g>. Hence
that latest self signed one. Ah well.

In this case it was about me wanting a certificate for Nisser
though the company is called eBOA. No can do.

Period.

When I've got time I'll send them a whachacallit (the thing you
put into the front of the X.509 process) and see what happens.

Still (and to sum up :) this is another aspect. Like you said, those
$100 or so I can possibly spare. If only they would provide what
I'm looking for!

Roelof

-- 
----------------------------------------------------------------
Het Slakke Huis van de TGV op http://SlakkeHuis.com/
----------------------------------------------------------------
Home is where the (@) http://eboa.com/ is.
Nisser home -- http://www.Nisser.com/
Beveiligingsverwijzingen -- http://Nisser.com/links.htm
Overzicht bekende LijnMonitoren -
  http://www.SlakkeHuis.com/Werkgroepen/LM/monitoren.php3
----------------------------------------------------------------


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3A6CCD0C.4ECBD8AD>