Bitcoin Forum

Bitcoin => Development & Technical Discussion => Topic started by: Ewald on November 10, 2010, 12:05:28 PM



Title: Suggestion: bitcoin.org SSL cert from self-signed -> CAcert
Post by: Ewald on November 10, 2010, 12:05:28 PM
I am aware that this feature request may be rather low priority, but I wanted to put it out here anyway. My suggestion is to switch from the current self-signed SSL certificate to one from CAcert (http://cacert.org). This way we have the benefit of working with a more widely accepted certificate (yesyes, still not in most main browsers, however still better than self-signed) and working with a more open approach to SSL certificates.

Especially when browsing bitcoin.org using Tor, I prefer to use SSL (https://www.bitcoin.org) in order to prevent exit nodes from eavesdropping.


Title: Re: Suggestion: bitcoin.org SSL cert from self-signed -> CAcert
Post by: MagicalTux on November 10, 2010, 12:57:43 PM
Why not use startssl instead of CAcert? At least the certificate would be trusted by default, and is still free


Title: Re: Suggestion: bitcoin.org SSL cert from self-signed -> CAcert
Post by: JackSparrow on March 13, 2011, 06:01:43 PM
Why not just accept the self signed certificate?
Because any Man-in-the-Middle could create a self-signed cert.


Title: Re: Suggestion: bitcoin.org SSL cert from self-signed -> CAcert
Post by: Matt Corallo on March 13, 2011, 09:04:27 PM
Although one could trust the specific certificate which bitcoin.org uses, I think a CACert or startssl certificate would be really nice to have.


Title: Re: Suggestion: bitcoin.org SSL cert from self-signed -> CAcert
Post by: neptop on March 13, 2011, 10:59:55 PM
+1 for startssl :)