I chatted about this with my programmer house mate and he said that it was perfectly possible to have HTTP and HTTPS running side by side and actually quite easy, though the forum software
might need some minor tweaking to keep people in the mode they started at. Having an "invalid" certificate would only start to scare people if they deliberately went to HTTPS, anyway.
Aside from the money, he said that certificates from Verisign and probably other certificate authorities filed a copy of each certificate with the police / intelligence agencies so that they could eavesdrop on HTTPS traffic. Doesn't sound good to me. Doing our own certificate would be more "Shadowrun".
His main negative for DS doing its own certificate is that it just gets people more used to clicking "Add Exception" when presented with a security warning and that few people would bother to check that the certificate was valid. But if HTTPS helps people use Dumpshock in certain environments, then I still see it as a positive thing. It would only come up for those people that typed in HTTP
S in the first place.
K.