Two Dumb Questions

Nikola Pavlović nzp at
Wed Sep 28 06:40:43 UTC 2016

On Mon, 26 Sep 2016 10:31:02 +0200
Matthew Seaman <matthew at> wrote:
> > 
> >
> > 


> Hmmm... their TLS certificate is issued by 'StartCom Class 1 DV Server
> CA'  This is a CA that prominently advertizes free SSL certificates,
> but otherwise looks like it charges just like any other CA.
> See:  No idea if this CA is any good but
> there's nothing to suggest any wrong doing just from their site.

Just an FYI regarding StartCom:  Mozilla is suspending their CA for
one year (and quite likely forever, it's unlikely they'll be able to
meet the requirements for reactivation).  Lots more info here in
Mozilla's investigation report:

PGP: 28CC 9078 8358 CE2D 6824  A5BC 2DB2 CD24 5BE7 8F06

More information about the freebsd-security mailing list