[Board] [EXTERNAL] SSL Certificate Policy
Smith, Michael ERDC-RDE-CRREL-NH CIV
Michael.Smith at erdc.dren.mil
Sat May 7 08:01:58 PDT 2016
I'm certainly fine with just the DV certificate since we have not
identified any areas in which the OV certificate is needed. Its not a cost
differential that I care about but more in SAC time and effort, both of
which are valuable and appreciated. Anything that eases the burden on SAC
is worth almost any expense but here it seems we have something both
simpler to maintain and less expensive so I would say I endorse the DV
OSGeo Foundation Treasurer
treasurer at osgeo.org
From: Board <board-bounces at lists.osgeo.org> on behalf of Alex M
<tech_dev at wildintellect.com>
Reply-To: "tech at wildintellect.com" <tech at wildintellect.com>
Date: Friday, May 6, 2016 at 11:06 AM
To: OSGeo Board <board at lists.osgeo.org>
Cc: "sac >> System Administration Committee Discussion/OSGeo"
<sac at lists.osgeo.org>
Subject: [EXTERNAL] [Board] SSL Certificate Policy
Resent-From: Michael Smith <michael.smith at usace.army.mil>
>We recently renewed the SSL certificate for the *.osgeo.org domains. In
>doing so there's an unresolved policy question I'd like to get answered.
>Our old certificate was Org Validated (OV). All that means is that the
>certificate authority does a little extra checking on the org, it's
>slightly more expensive (~$150+/yr), and that it's harder to change
>anything in our account related to the certificate. The outward facing
>result is that if you read the certificate details the Organization(O)
>line is filled out.
>The new certificate (because we were on a time crunch) is a Domain
>Validated (DV). It's a little cheaper, and way easier to login and work
>with. It's also similar enough to Mozilla's new letsencrypt project that
>we might be able to switch to that later on.
>From a money perspective, I don't think the difference between $250 vs
>$400 a year is big difference. From a technical perspective both work,
>equally well. Other orgs seems to mostly use OV certificates. But I've
>found very few people who seem to care, and you can't really tell unless
>you open the certificate details.
>The only thing that would happen now if we change back to OV, is that it
>will take more volunteer hours to get the new one, cancel the current
>one (100% refund is not an issue in the 1st 30 days).
>Does the board have a position on if they want to use an OV or are
>people content with the DV certificates?
>Sys Admin Committee
>Board mailing list
>Board at lists.osgeo.org
More information about the Board