OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [OT] SSL Cert recommendation

From: Vivek Khera (vivekkhera.org)
Date: Mon May 19 2008 - 11:37:20 CDT


On May 17, 2008, at 9:42 PM, Jason Fesler wrote:

> Apple's Mail.app does complain if the keys are self signed (unless
> you take great efforts to muck with Apple's certificate stuff).

At least for the SSL cert used in IMAP, Apple's "great efforts to muck
with" involve clicking the "view certificate" button, then checking
the "trust this certificate" checkbox, clicking "save".

I can't imagine it being more complicated for SMTP TLS certificates.

For a certificate vendor recommendation, you can buy RapidSSL
certificates from geotrust (you have to go to rapidssl.com though)
either directly, by signing up as a reseller, or use a high-volume low-
price reseller like http://www.rapidsslonline.com/ which sells them
for insanely cheap (cheaper then you'll ever get as a direct reseller
unless you do huge volumes).

I find the rapidssl certificates sufficient for web servers; I've
never set up email TLS/SSL.