作者: sonywong 時間: 2012-3-15 13:36 標題: [教學] 申請免費SSL cert
本帖最後由 sonywong 於 2012-3-15 13:41 編輯
http://xchenbinx.blog.163.com/blog/static/4179784420114123735290/
如果你有自己domain就一定申請啦,反正免費(但有效期一年)。
宜家 Startssl 要申請人send id copy 比佢地核實,不過我send完幾分鐘之後已經確認我嘅申請,都好快手。
作者: 小莉~ 時間: 2012-3-16 16:07
順帶一問:
SSL係咪自設server(包括NAS)先要自行申請的?普通hosting service係咪本身就有SSL唔洗set?
作者: Super169 時間: 2012-3-17 00:32
請問同自己整張 self-signed 既 cert 有乜分別?
作者: 133954202 時間: 2012-3-17 12:19
Trust SSL
作者: java2 時間: 2012-3-17 20:11
trusted cert vs non-trusted cert
作者: Super169 時間: 2012-3-17 20:53
請問大家所講既 Trust 係乜野意思?
係咪 Trust 應該唔係由個 CA 決定既, 應該係由 client side 自行決定.
就算一張 self-signed 既 cert, 你都可以 trust 佢個 CA (即係你自己).
我之前試野, 一向都係用自己出既 cert, 自己 confirm 裝張 cert.
就算由果個 site create 既 cert, 應該都唔會自己 trust 而裝既.
所以唔係好明有乜野分別?
作者: ted219 時間: 2012-3-17 21:19
分別在於 張 cert 係由 Trusted CA 發出, 由於其他人唔會有您 CA 既資料 (自己 import 除外), 所以會有警告話張 cert 既 CA 有問題, 叫您注意下.
一d 公認既 CA eg: Verisign, HK Post , Browser 本身會有 Trusted CA 既資料, 所以當您用 Trusted CA 發出既 Cert , 人家 connect 去您 server , 就唔會有警告話張 cert 既 CA 有問題 (因為 Trust CA , 所以 Trust 埋 由那些 CA 發出既 Cert.)
作者: Super169 時間: 2012-3-17 22:15
本帖最後由 Super169 於 2012-3-17 22:27 編輯
回復 7# ted219
oic, 剛剛 check 左, 原來 StartCom Certification Authority 係跟機黎自動加左入 Trusted Root Certification Authorities 既.
不過, 大家唔會覺得咁樣有危險嗎? 呢個 CA 咁隨便發 cert, 竟然係 Windows 自動 Turst 左既, Trusted CA 就變得無意義了.
其實咁樣應該算係呢個CA有問題, 定係 Microsoft 有問題呢?
經你一提, 為免信錯人, 自行在 list 中剷走左呢個 CA 了.
順便問埋, 我個 list 中, 仲有無邊個 CA 係隨便發 cert 既? (只有 Server Authentication 既唔計)
https://www.hkepc.com/forum/attachment.php?aid=1334108&k=5c16879077dfc761dd82c1c40ab3aeb8&t=1787231443&sid=g1xpF2qMbC

作者: markie 時間: 2012-3-17 22:27
它是否不是公認的 Authroity CA Centre ?
作者: Super169 時間: 2012-3-17 22:29
你試下開個 management console, 睇下佢係咪 Trusted Root Certification Authorites.
我個 list 就見到佢, 真係幾信唔過, 咁隨便發 cert, 咁都可以係公認 可信既?
作者: 133954202 時間: 2012-3-17 22:40
你試下開個 management console, 睇下佢係咪 Trusted Root Certification Authorites.
我個 list 就見到 ...
Super169 發表於 2012-3-17 22:29
你咁講都真係幾唔SECURE....不過有得玩下TRUST SSL 都係一件好事
作者: Niel 時間: 2012-3-18 04:05
請大家了解清楚CA的角色,StarCom沒有亂發Cert,Cert本身的作用是用於認証一個Entity的真偽。
StarCom發給各位的Cert是用於認証你的身份,而它也有做足確認的步驟(Check ID Card)。
如果它給你發一張認証你是其他entity (e.g.把你認証為Apple Inc.),那才是有問題。
作者: Super169 時間: 2012-3-18 10:05
請問佢係點樣做足確認的步驟(Check ID Card)? 我是旦打一個 ID 比佢, 佢點確認係我既?
作者: Phil_123 時間: 2012-3-18 11:00
回復 ted219
oic, 剛剛 check 左, 原來 StartCom Certification Authority 係跟機黎自動加左入 Trusted ...
Super169 發表於 2012-3-17 22:15
StartCom 所有免費 cert 顯示既公司名都會係 StartCom, 唔會俾人亂咁自定公司名.
如果 StartCom 信唔過, Microsoft 都唔會 add 佢做 trusted CA 啦, 其實 Microsoft 已經係信 StartCom 信得最遲既公司.
http://www.istartedsomething.com ... -authority-windows/
作者: Niel 時間: 2012-3-18 18:52
You need to provide a scanned copy of your ID Card
1.) Why do I have to provide my personal details?
The Terms and Conditions of StartCom and the StartCom Certification Policy requires* subscribers to provide the correct and complete personal details during registration. Without fulfilling this requirement, a subscriber (you) is not entitled for an account with StartSSL™. It is upon the subscriber to prove the validity of the details submitted should StartCom make such a request.
* Since StartCom must enforce adherence of the StartCom Certification Policies by all subscribers, the subscriber must provide his/her personal information.
http://www.startssl.com/?app=25
作者: 小煩仔 時間: 2012-4-4 23:37
登入果時 ssl_error_handshake_failure_alert
點解決?
作者: man0000 時間: 2012-4-5 13:23
send e-mail to startcom
you talk about this problem to startcom
e-mail :help@startcom.org


