Post Reply  Post Thread 
CaCert support for ssl
Author Message
tioan Offline
Junior Member
*

tioan
Junior Member
*


Posts: 22
Group: Registered
Joined: Dec 2006
Status: Offline
Reputation: 0
Post: #1
CaCert support for ssl
Hi,
for ssl support in ispcp Cacert will be a good solution because it support more than one Domain per IP with SubjectAltName. So we didnt need an ssl proxy or so to support ssl for every hosted domain, only an wrapper that use http://wiki.cacert.org/wiki/VhostTaskForce. I think the is better than every ssl proxy.

Using ispCP RC2 on Debian etch.
-----------------------
Make mod_f(ast)cgi more stable!
07-31-2007 10:19 PM
Visit this user's website Find all posts by this user Quote this message in a reply
ephigenie Offline
Administrator
*******
Administrators

ephigenie
Administrator
*******
Administrators


Posts: 666
Group: Administrators
Joined: Oct 2006
Status: Offline
Reputation: 12
Post: #2
RE: CaCert support for ssl
We're aware of free - certificates - but those you mentioned as well as some others are only supported by a minority of browsers.

Although in Germany 30+% use firefox/mozilla based browsers there're at 70% left with other browser where i guess that 65% is IE.
For the Rest of the World it looks equal.

For this website it looks a bit different - but i think its related to the fact, that most of us are somehow IT-related and have a natural annoyance against IE & co. Wink .

But we can not ignore our Customers and their Customers....

Even officially Multisite Certificates are not supported by most Browsers ...
(or wildcard certificates etc...)



FYI Browser distribution on isp-control.net
rank Name visits percent

1. Firefox 52.831 64,14%
2. Internet Explorer 18.130 22,01%
3. Opera 5.031 6,11%
4. Mozilla 3.969 4,82%
5. Safari 1.223 1,48%
6. Konqueror 847 1,03%
7. Camino 205 0,25%
8. gzip 57 0,07%
9. Netscape 31 0,04%
10. Mozilla Compatible Agent 18 0,02%
07-31-2007 10:37 PM
Visit this user's website Find all posts by this user Quote this message in a reply
tioan Offline
Junior Member
*

tioan
Junior Member
*


Posts: 22
Group: Registered
Joined: Dec 2006
Status: Offline
Reputation: 0
Post: #3
RE: CaCert support for ssl
ephigenie Wrote:Even officially Multisite Certificates are not supported by most Browsers ...
(or wildcard certificates etc...)

This are support by most browser ( Ie Firefox Opera Safari and so one, and yes Cacert isn“t allready in the browsers, but you only need to import one time the cacert root cert and every cacert cert work without problems.) And i think one time import of certs is better then some ssl proxy

Using ispCP RC2 on Debian etch.
-----------------------
Make mod_f(ast)cgi more stable!
08-01-2007 04:54 AM
Visit this user's website Find all posts by this user Quote this message in a reply
rbtux Away
Member
***

rbtux
Member
***


Posts: 1,200
Group: Registered
Joined: Feb 2007
Status: Away
Reputation: 22
Post: #4
RE: CaCert support for ssl
ssl proxy is the better way if you use some thirdparty trusted certificates...

do you know what a wildcard certificate of a trusted ca costs? too much!

OS: Debian Lenny
ispCP Version: Trunk r1033
Activated: AWStats dynamic, Dovecot, Avelsieve, Selective Greylisting, Bogus MX Filter,
No Webtools, Roundcube, Some own modifications
08-01-2007 05:14 AM
Visit this user's website Find all posts by this user Quote this message in a reply
ephigenie Offline
Administrator
*******
Administrators

ephigenie
Administrator
*******
Administrators


Posts: 666
Group: Administrators
Joined: Oct 2006
Status: Offline
Reputation: 12
Post: #5
RE: CaCert support for ssl
tioan Wrote:
ephigenie Wrote:Even officially Multisite Certificates are not supported by most Browsers ...
(or wildcard certificates etc...)
but you only need to import one time the cacert root cert and every cacert cert work without problems.) And i think one time import of certs is better then some ssl proxy

This only sentence is the whole thing between "trusted" certificates and selfmade ones.
08-01-2007 05:54 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply  Post Thread 

View a Printable Version
Send this Thread to a Friend
Subscribe to this thread |

Forum Jump:

| All rights reserved : isp-control.net |