History

The History of Free SSL Before Let's Encrypt Existed

Free SSL certificates weren't entirely new when Let's Encrypt launched in 2015 — smaller providers like StartCom's StartSSL had offered free, manually-issued DV certificates for years prior, and some resellers occasionally bundled a free first-year certificate as a promotional offer.

Why Let's Encrypt was still the turning point

What earlier free options lacked was automation and a fully open, standardized issuance process at real scale — Let's Encrypt's combination of being free, automated via ACME, and backed by a nonprofit with major industry sponsorship is what let free certificates become the default expectation rather than a niche, manually-managed option most site owners never discovered or trusted.

What eventually happened to StartSSL exactly

StartCom, the company behind StartSSL, was later swept up in a separate trust controversy of its own — following a change in ownership and subsequent mis-issuance concerns, browsers including Chrome and Firefox distrusted StartCom's root certificates around 2016-2017, effectively ending StartSSL as a viable free certificate option right around the same period Let's Encrypt was becoming firmly established.

Why free certificate options before Let's Encrypt never achieved comparable scale

Earlier free options like StartSSL required manual account setup and manual certificate renewal through a web interface, offered limited automation tooling, and were run by comparatively small organizations without the same infrastructure investment or industry backing — Let's Encrypt's combination of full ACME automation and backing from major sponsoring organizations gave it a scale and reliability earlier free options simply hadn't achieved.

What StartSSL's actual free tier offered compared to Let's Encrypt

StartSSL's free tier offered a single free DV certificate per validated identity with a longer validity period than Let's Encrypt's eventual 90-day default, but required manual account verification and manual renewal management through StartCom's own web portal — considerably more manual overhead than Let's Encrypt's fully automated ACME-based approach would later provide.

Other lesser-known free options that existed briefly during this period

A handful of other smaller providers experimented with limited free certificate offerings during the pre-2015 period, generally as promotional loss-leaders tied to broader hosting or domain registration services rather than a CA's primary product line — none achieved lasting significance or scale comparable to what Let's Encrypt would establish shortly after.

The lasting lesson from StartSSL's own eventual distrust

StartSSL's own later distrust, following a change in ownership and subsequent compliance concerns, is itself a small case study fitting the broader CA-distrust pattern discussed elsewhere in this section — reinforcing that trust, once granted to a CA, remains conditional on sustained compliance rather than a permanent status.

What this pre-history reveals about why timing mattered as much as the idea itself

The fact that free certificates existed in some form before Let's Encrypt, without achieving comparable impact, underscores that Let's Encrypt's success wasn't simply about the idea of free certificates, which wasn't new, but about the specific combination of full automation, credible institutional backing, and arriving at a moment when browser-level pressure toward HTTPS adoption was also beginning to build — timing and execution mattering as much as the underlying concept.

What earlier free efforts ultimately contributed despite their limited scale

Even though StartSSL and similar earlier efforts never achieved Let's Encrypt's scale, they helped establish that a viable market and genuine demand existed for free certificates well before Let's Encrypt launched, arguably making the case that later helped attract the institutional backing and sponsorship Let's Encrypt itself needed to get off the ground at a much larger scale.

Earlier free certificate efforts helped prove the demand existed, even if it took Let's Encrypt's scale and backing to fully capture it.

Comments

Loading comments…