Re: trust issues associated with Public Key Infrastructure?

What are the trust issues associated with Public Key Infrastructure?

The main issue is: how can you trust, that the public key you have really
is from the person you want to communicate with?

There are two different ideas for that topic: certification authorities
(with i.e. SSL/TLS, S/MIME) and the web of trust (i.e. OpenPGP).

Are the following PKI trust issues?...

CAs could issue certificates without checking owner identity
CAs could deliberately issues false certificates
Private keys could be disclosed by accident or on purpose
False certificates could be inserted into browsers
How to know that a revocation request is genuine (possible denial of service
Checking revoked certificates requires another secure channel
Liability issues for false or misused keys





