I'm looking for cheap SSL certs for running a personal website over https without triggering Firefox's "you may be facing a man-in-the-middle-attack" response that self signed certs provoke. Nothing particularly fancy, no EV, etc. Any recommendations/where do you get your certificates from?
Godaddy issues certificates pretty cheaply.
Edit - A little more info - $30/year to get a web server SSL certificate from GoDaddy. I don't think they do as rigorous verification as the older cert authorities (but that's why you buy an EV cert if you're a bank), but the really do a good job and have good customer service. I find their ads insulting, but they do their job well.
If you aren't hosting yourself, I would check your host as well as the other suggestions. I was told that sometimes, hosts give you a discount on their normal price for certificates if you both buy the cert from them and host through them, but I've never needed one, so I never looked myself.
Sign up as a reseller with resellone.net, and you can buy certs for as little as $10. You do need to pay a $99 setup fee to become a reseller, and you must have "Verified by Visa" or "Mastercard securecode" to make credit card payments.
Free one month or $79 for the year.
http://www.rapidssl.com/index_ssl.htm.
You can reissue monthly forever for free, it's just annoying.
At StartCom you can get free SSL certificates, that are signed by a certificate which is installed with Firefox 3 automatically if I am correct.
They are only valid one month though, so you have to renew them (for free) each month.
Check out http://cert.startcom.org/
We've been buying from Comodo (http://www.instantssl.com) for a number of years without any problems. $99 for one year. $65/year for a five year certificate.
I always use https://www.digitaltcertifikat.dk/en/ which is a geotrust thing. 750DKK = 150USD
You can get a RapidSSL SingleHost certificate from a reseller for 27 Euro ($40) for the year.
Like the GoDaddy Standard SSL certificate, it does Domain-only validation, i.e. the certificate only certifies the domain name and nothing more. Most important, the certificate won't contain information about the organization the certificate belongs to, since this kind of information can't be validated by the e-mail validation process used for these cheap certificates.
But, these certificates (signed by Equfax Secure Inc.) will be accepted without warning by all popular browsers, contrary to self-signed certificates.
StartCom offers free SSL certificates that work fine with Firefox 3. They're valid for 1 year (not 1 month). You do have to be using your own domain; you can't use a subdomain of somebody else (e.g. a dynamic DNS provider).
I just found this site: DigiCert
Don't know how good they are, but seem to be quite cheap.
I haven't used them, but namecheap.com currently resells rapidssl certs for $20 a year and comodo positivessl for $10 a year.
I'm buying Rapidssl certificates from Sslmatic (http://www.sslmatic.com) for only $19.99. They sell Geotrust and Verisign to very cheap prices too.
You can get free certificates at CACert. Unfortunately most browsers doesn't have their root certificate installed.
I got my Deluxe ssl certificates from http://www.thewebpole.com/ .This site provides the domain registrations service, web hosting packages ,domain appraisal etc., at cheap price.I recommended to this only.