(no title)
threesevenths | 10 months ago
The value in exiting providers is their reach; versign for example is deployed in practically every trusted root bundle. When GoDaddy wanted to enter the market, they bought Starfield who already had a root which was widely trusted and crossed that with their own.
The reason people will pay for you to compute a number based on a number they give you and your super secret number is that people trust what you’re doing with your super secret number. And that trust takes time.
viraptor|10 months ago
Some history here. http://wiki.cacert.org/InclusionStatus And that's before root stores had to deal with Honest Achmed's Used Cars and Certificates.
solardev|10 months ago
cpach|10 months ago
“Getting a new root trusted and propagated broadly can take 3-6 years. In order to start issuing widely trusted certificates as soon as possible, we partnered with another CA, IdenTrust, which has a number of existing trusted roots. As part of that partnership, an IdenTrust root ‘vouches for’ the certificates that we issue, thus making our certificates trusted.”
https://letsencrypt.org/2015/10/19/lets-encrypt-is-trusted/
https://letsencrypt.org/2016/08/05/le-root-to-be-trusted-by-...
https://letsencrypt.org/2023/07/10/cross-sign-expiration/
hulitu|10 months ago