HN user

morgs

4 karma
Posts0
Comments4
View on HN
No posts found.

In 1999, Netscape started charging something like $100,000/year + $5000 per root cert, before there were any audit requirements. I think the idea was to weed out those who couldn't afford to run a CA worthy of browser inclusion.

I'm no longer in the SSL industry but I'm not aware of Mozilla charging. Perhaps it was dropped when Mozilla spun out of Netscape and the WebTrust audit came on the scene.

Complying with the audit is costly - both in direct costs to the auditors, and in implementing the infrastructure and policies and procedures to pass the audit.

AFAIK it was him - having developed the first non-US 128 bit crypto capable SSL web server called Sioux (basically, Apache + SSLeay) he was on all the same mailing lists as the Netscape crypto guys.

He then realised that the certs were more interesting than the web servers, and sold off Sioux to Stronghold so he could position Thawte as a CA instead of a software vendor.

Then with the browser war on the go, MSIE3.0 copied Netscape Navigator, right down to the list of CAs included...