<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://bitpost.com/w/index.php?action=history&amp;feed=atom&amp;title=StartCom</id>
	<title>StartCom - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://bitpost.com/w/index.php?action=history&amp;feed=atom&amp;title=StartCom"/>
	<link rel="alternate" type="text/html" href="https://bitpost.com/w/index.php?title=StartCom&amp;action=history"/>
	<updated>2026-05-09T08:50:30Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.3</generator>
	<entry>
		<id>https://bitpost.com/w/index.php?title=StartCom&amp;diff=5972&amp;oldid=prev</id>
		<title>M at 23:34, 19 February 2021</title>
		<link rel="alternate" type="text/html" href="https://bitpost.com/w/index.php?title=StartCom&amp;diff=5972&amp;oldid=prev"/>
		<updated>2021-02-19T23:34:55Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 23:34, 19 February 2021&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l20&quot;&gt;Line 20:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 20:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;             You can back this cert up, but honestly it&amp;#039;s only good for a year and more often it ends up of not much reuse value.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;             You can back this cert up, but honestly it&amp;#039;s only good for a year and more often it ends up of not much reuse value.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;             I try to stick with wimpy-windows firefox, and sometimes the key is cached and reworks.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;             I try to stick with wimpy-windows firefox, and sometimes the key is cached and reworks.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;            The last one I saved, I had used a password of &quot;borlando&quot; but not even sure where that was set.  Whatever.&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;3) From the Control Panel, validate each domain through the Validation wizard.  Requires email confirmation with webmaster@____&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;3) From the Control Panel, validate each domain through the Validation wizard.  Requires email confirmation with webmaster@____&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>M</name></author>
	</entry>
	<entry>
		<id>https://bitpost.com/w/index.php?title=StartCom&amp;diff=4209&amp;oldid=prev</id>
		<title>M at 01:28, 17 January 2017</title>
		<link rel="alternate" type="text/html" href="https://bitpost.com/w/index.php?title=StartCom&amp;diff=4209&amp;oldid=prev"/>
		<updated>2017-01-17T01:28:21Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 01:28, 17 January 2017&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;NOTE: THIS IS NOW DEPRECATED, see [[SSL certificate instructions]] instead.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;NOTE: THIS IS NOW DEPRECATED, see [[SSL certificate instructions]] instead.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Browser support for StartCom was dropped in 2017 after they were acquired by Chinese WoSign.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Browser support for StartCom was dropped in 2017 after they were acquired by Chinese WoSign.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;---&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;-------&lt;/ins&gt;---&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I am using free certificates from StartCom, http://startssl.com/&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I am using free certificates from StartCom, http://startssl.com/&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>M</name></author>
	</entry>
	<entry>
		<id>https://bitpost.com/w/index.php?title=StartCom&amp;diff=4208&amp;oldid=prev</id>
		<title>M: Created page with &quot;NOTE: THIS IS NOW DEPRECATED, see SSL certificate instructions instead. Browser support for StartCom was dropped in 2017 after they were acquired by Chinese WoSign. ---  I...&quot;</title>
		<link rel="alternate" type="text/html" href="https://bitpost.com/w/index.php?title=StartCom&amp;diff=4208&amp;oldid=prev"/>
		<updated>2017-01-17T01:28:02Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;NOTE: THIS IS NOW DEPRECATED, see &lt;a href=&quot;/wiki/SSL_certificate_instructions&quot; title=&quot;SSL certificate instructions&quot;&gt;SSL certificate instructions&lt;/a&gt; instead. Browser support for StartCom was dropped in 2017 after they were acquired by Chinese WoSign. ---  I...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;NOTE: THIS IS NOW DEPRECATED, see [[SSL certificate instructions]] instead.&lt;br /&gt;
Browser support for StartCom was dropped in 2017 after they were acquired by Chinese WoSign.&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
I am using free certificates from StartCom, http://startssl.com/&lt;br /&gt;
They have a 1-year validity and therefore require annual renewal.&lt;br /&gt;
&lt;br /&gt;
INSTRUCTIONS&lt;br /&gt;
------------&lt;br /&gt;
1) browse to https://www.startssl.com&lt;br /&gt;
2) click on Control Panel, Authenticate&lt;br /&gt;
      If the browser does not already have a valid certificate to identify you (from a previous session),&lt;br /&gt;
      you will not be authenticated.  To get a new certificate to identify you:&lt;br /&gt;
            Click Sign-up and re-enter details.&lt;br /&gt;
            Use webmaster@thedigitalmachine.com (or other valid domain).&lt;br /&gt;
            You&amp;#039;ll get a code to verify email, use it.&lt;br /&gt;
            Then, you might have to wait to get the browser certificate.&lt;br /&gt;
            You will receive a link and a passcode; click the link and enter the passcode and a cert will be installed in the browser.&lt;br /&gt;
            You can back this cert up, but honestly it&amp;#039;s only good for a year and more often it ends up of not much reuse value.&lt;br /&gt;
            I try to stick with wimpy-windows firefox, and sometimes the key is cached and reworks.&lt;br /&gt;
            The last one I saved, I had used a password of &amp;quot;borlando&amp;quot; but not even sure where that was set.  Whatever.&lt;br /&gt;
&lt;br /&gt;
3) From the Control Panel, validate each domain through the Validation wizard.  Requires email confirmation with webmaster@____&lt;br /&gt;
        Do domain name validations for these four base domain names:&lt;br /&gt;
          x ssl.thedigitalmachine.com&lt;br /&gt;
          x ssl.thedigitalage.org&lt;br /&gt;
          x ssl.abettersoftware.com&lt;br /&gt;
          x ssl.bitpost.com&lt;br /&gt;
&lt;br /&gt;
4) Create web server SSL/TLS Certificates&lt;br /&gt;
   It&amp;#039;s easy enough to let startssl generate the keys (but do it locally if you have time?  see below)...&lt;br /&gt;
            pw = (see private.txt)&lt;br /&gt;
            keysize = high (4096)&lt;br /&gt;
            algo = SHA1 (Default)&lt;br /&gt;
            generate private...&lt;br /&gt;
            save as ~m/config/StartCom/(site)/(year, eg 2014-)/ssl.withpassword.key&lt;br /&gt;
            create no-password key with: openssl rsa -in ssl.withpassword.key -out ssl.key&lt;br /&gt;
            wait for email re: approval, then get ssl.crt from toolbox, save to same place&lt;br /&gt;
          x ssl.abettersoftware.com&lt;br /&gt;
          x ssl.bitpost.com&lt;br /&gt;
          x ssl.thedigitalmachine.com&lt;br /&gt;
          x ssl.thedigitalage.org&lt;br /&gt;
   Put new ones here (eg): /home/m/config/StartCom/bitpost.com/2014-/&lt;br /&gt;
   Ideally we&amp;#039;d make them readable ONLY by apache, but I am keeping a backup in git, so use:&lt;br /&gt;
           sudo chmod -R 770 *&lt;br /&gt;
&lt;br /&gt;
5) Update apache to use new certs&lt;br /&gt;
   a) stop apache&lt;br /&gt;
   b) move existing certs in /home/m/config/StartCom/(domain)/ out to (eg) (domain)/2013-/... (this may not be needed if a copy is already there)&lt;br /&gt;
   c) move new certs from (eg) /2014-/... up one dir to the base (where apache is looking)&lt;br /&gt;
   d) restart apache and make sure it&amp;#039;s happy (watch startup warnings, browse to each site)&lt;br /&gt;
&lt;br /&gt;
   NOTE here is what Apache needs:&lt;br /&gt;
    SSLCertificateFile /home/m/config/StartCom/bitpost.com/ssl.crt&lt;br /&gt;
    SSLCertificateKeyFile /home/m/config/StartCom/bitpost.com/server.key&lt;br /&gt;
    SSLCertificateChainFile /home/m/config/StartCom/sub.class1.server.ca.pem&lt;br /&gt;
    SSLCACertificateFile /home/m/config/StartCom/ca.pem.crt&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
MORE NOTES&lt;br /&gt;
----------&lt;br /&gt;
&lt;br /&gt;
ALL 4 DOMAINS ARE NOW SYNCED for renewal in AUGUST/SEPT, try to remember dude&lt;br /&gt;
of course any new domains are going to be out of sync, pita, cest la vie&lt;br /&gt;
&lt;br /&gt;
here, we store common docs:&lt;br /&gt;
&lt;br /&gt;
    browser_cert_install_first.p12&lt;br /&gt;
        the browser cert that lets you log in to https://startssl.com&lt;br /&gt;
&lt;br /&gt;
    ca.pem.crt&lt;br /&gt;
    sub.class1.server.ca.pem&lt;br /&gt;
        the official certs for StartCom level 1&lt;br /&gt;
        you can get these from Control Panel-&amp;gt;Tool Box-&amp;gt;StartCom CA certificates&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
GENERATING YOUR OWN KEYS&lt;br /&gt;
------------------------&lt;br /&gt;
Note that you can generate your own keys.&lt;br /&gt;
Generally not worth it tho, I trust StartCom, and you have to give them the key anyway.&lt;br /&gt;
Plus, all the extra info you add to the key is discarded by StartCom since it&amp;#039;s an unvalidated owner (ie free).&lt;br /&gt;
But for completeness, here&amp;#039;s old notes on how to do it... (should it still be des3??)&lt;br /&gt;
&lt;br /&gt;
server.key generated with:&lt;br /&gt;
&lt;br /&gt;
openssl genrsa -des3 -out server.key 2048&lt;br /&gt;
&lt;br /&gt;
CSR generated as follows:&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
m@thedigitalmachine ~/config/StartCom/abettersoftware.com $ openssl req -new -key server.key -out server.csrEnter pass phrase for server.key:&lt;br /&gt;
You are about to be asked to enter information that will be incorporated&lt;br /&gt;
into your certificate request.&lt;br /&gt;
What you are about to enter is what is called a Distinguished Name or a DN.&lt;br /&gt;
There are quite a few fields but you can leave some blank&lt;br /&gt;
For some fields there will be a default value,&lt;br /&gt;
If you enter &amp;#039;.&amp;#039;, the field will be left blank.&lt;br /&gt;
-----&lt;br /&gt;
Country Name (2 letter code) [AU]:US&lt;br /&gt;
State or Province Name (full name) [Some-State]:NC&lt;br /&gt;
Locality Name (eg, city) []:Raleigh&lt;br /&gt;
Organization Name (eg, company) [Internet Widgits Pty Ltd]:A better Software&lt;br /&gt;
Organizational Unit Name (eg, section) []:&lt;br /&gt;
Common Name (eg, YOUR name) []:Michael Behrns-Miller&lt;br /&gt;
Email Address []:noreply@abettersoftware.com&lt;br /&gt;
&lt;br /&gt;
Please enter the following &amp;#039;extra&amp;#039; attributes&lt;br /&gt;
to be sent with your certificate request&lt;br /&gt;
A challenge password []:&lt;br /&gt;
An optional company name []:&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
then that gets pasted into StartCom form under the Certificates Wizard on the control panel&lt;br /&gt;
note from the form:&lt;br /&gt;
    All content of the certificate signing request is ignored except its public key.&lt;/div&gt;</summary>
		<author><name>M</name></author>
	</entry>
</feed>