LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 01-14-2021, 03:04 PM   #1
mh4it
LQ Newbie
 
Registered: Apr 2020
Posts: 3

Rep: Reputation: Disabled
Need Recommendation for 1 Year SSL from a good FOSS Company


I'm helping a friend who hosts web sites on GoDaddy.
GoDaddy has Snubbed LetsEncrypts ACME 60 Day auto-renewal security system (because its free?)
With only Cpanel the next step is find a 1 year SSL certificate company to purchase from.
Ive purchased from Comodo in the past, but i want to find a moral and ethical company that represents the FOSS ideals. Any ideas?
 
Old 01-15-2021, 08:31 AM   #2
boughtonp
Senior Member
 
Registered: Feb 2007
Location: UK
Distribution: Debian
Posts: 3,623

Rep: Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555
Quote:
Originally Posted by mh4it View Post
i want to find a moral and ethical company that represents the FOSS ideals. Any ideas?
Then switch the hosting away from GoDaddy to any hosting provider that supports Let's Encrypt.

 
1 members found this post helpful.
Old 01-15-2021, 01:17 PM   #3
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
^ Aren't they saying that they don't want to use LetsEncrypt?
I'm a little confused.
Also I don't understand "Snubbed", or "With only Cpanel the next step".
 
Old 01-15-2021, 02:11 PM   #4
boughtonp
Senior Member
 
Registered: Feb 2007
Location: UK
Distribution: Debian
Posts: 3,623

Rep: Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555

By my reading, mh4it is saying:
1) they don't want Comodo certificates (aka Sectigo), due to unethical behaviour of that company
2) GoDaddy doesn't allow Let's Encrypt and/or ACME

I don't understand the "With only Cpanel..." bit either. Perhaps referencing that cPanel's default SSL provider is Sectigo/Comodo.
(It can be overridden to other providers, including Let's Encrypt, but I don't know if there's a specific API/whitelist of compatible providers.)

Snubbed is pretending someone doesn't exist - i.e. what GoDaddy is doing with regards Let's Encrypt.

 
1 members found this post helpful.
Old 01-15-2021, 03:09 PM   #5
mh4it
LQ Newbie
 
Registered: Apr 2020
Posts: 3

Original Poster
Rep: Reputation: Disabled
Thank you for addressing my question!
My friend is not tech savy and they are stuck with GoDaddy for at least 1 year. GoDaddy Cpanel is the only admin choice at the moment. The self signed certs arent any good, most of this is frustration
1.) GoDaddy charges alot for SSL but blocks ACME
2.) I use DevuanOS and always defer to FOSS solutions whenever possible but my internet search for a SSL provider came up with very little!!!
 
Old 01-16-2021, 02:35 AM   #6
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by mh4it View Post
1.) GoDaddy charges alot for SSL but blocks ACME
2.) I use DevuanOS and always defer to FOSS solutions whenever possible but my internet search for a SSL provider came up with very little!!!
I'm not really sure what ACME means, but if GoDaddy are blocking some cert providers, you have to find one that is accepted by them, says Cpt. Obvious.
AFAICS SSL cert providers are not "open source" in any way. They're all ultimately commercial entities (yes, letsencrypt too) and they don't provide source code, so it's not open source anyhow.
Personally, and because I live in Europe, I prefer a European solution, but I'm sure that's of no use to you.

I feel you though, I wish there was more projects like letsencrypt, which is unsuitable for me for various reasons.
 
Old 01-16-2021, 08:42 AM   #7
boughtonp
Senior Member
 
Registered: Feb 2007
Location: UK
Distribution: Debian
Posts: 3,623

Rep: Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555
Quote:
Originally Posted by ondoho View Post
ACME is Automated Certificate Management Environment, also RFC 8555 - i.e. the protocol designed by Let's Encrypt and implemented in Certbot (+others) which actually manages the certificates, but - being a protocol - it's not limited to Let's Encrypt; other CAs can and do use it.

Quote:
They're all ultimately commercial entities (yes, letsencrypt too) and they don't provide source code, so it's not open source anyhow.
Let's Encrypt is ISRG, a 501(c)(3) non-profit - founded by Akamai, Cisco, EFF, Mozilla and the University of Michigan - though it does have board members and technical advisors from others companies now (including Amazon, Facebook, Google): https://www.abetterinternet.org/about/

The Let's Encrypt CA software is on GitHub: https://github.com/letsencrypt/

Quote:
Personally, and because I live in Europe, I prefer a European solution
Wikipedia says GlobalSign is/was a CA based in Belgium, and they appear to support ACME.

 
Old 01-16-2021, 01:30 PM   #8
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
The cert itself is not software, in the sense of being a program or executable, and it's possible to install it without ACME or other software.
 
  


Reply

Tags
cpanel, secure, ssl, tip, web



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Red Hat - How An Open Source Software Company Became 34,000 Million Dollars Company LXer Syndicated Linux News 0 11-06-2018 04:11 PM
LXer: Microsoft is Pretending to be a FOSS Company in Order to Secure Government Contracts With Proprietary Software in ‘Open’ Clothing LXer Syndicated Linux News 0 03-23-2016 10:40 AM
LXer: How to talk to your company about FOSS LXer Syndicated Linux News 0 08-18-2015 11:22 AM
Can't open company website from outside only when inside the company lan perfectpol7 Linux - Server 6 01-16-2012 09:42 AM
LXer: Deciding whether your company needs FOSS insurance LXer Syndicated Linux News 0 12-19-2005 06:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration