Trust of sslforfree.com to generate private keys

WARNING - EDIT nov-2020 : some services mentioned have significantly changed. Advice may not be up to date!

Two older threads asked if it was secure to use it:

On both, the advice was to prefer https://gethttpsforfree.com/ (who doesn't generate private keys) but without details.
One suggested zerossl.com (who also generate private keys)

As a general advice, it's better to generate your private key and csr offline.

If you must generate it online you have to trust the service.

I see some red flags about sslforfree:

And, from a security point of view:

So I would not recommend that website to generate your private key.

Although it should be safe to use to generate a certificate if you already have a CSR (See #2)

Beware, that service also may ask for your ftp password:

Site note: Let's Encrypt apparently decided to stop listing browser based clients on ACME Client Implementations - Let's Encrypt : client-options: document inclusion/update policy. by cpu · Pull Request #377 · letsencrypt/website · GitHub

To compare with Free SSL Certificates and SSL Tools - ZeroSSL :

3 Likes

This isn't really safe either. Due to the fact that authorizations are re-usable (currently for 30 days), it opens the opportunity for sslforfree.com to just silently* issue an identical certificate under an alternate private key. This is because they control the ACME account key at all times.

(* mitigated by CT logs but most users are not savvy to that)

3 Likes

Thanks for pointing that out, corrected!

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.