Re: PKI and Relying Parties

From: Citizen Fish (fishy@)
Date: 03/29/02


From: Citizen Fish <fishy@<tut tut>answer.me.uk>
Date: Fri, 29 Mar 2002 15:48:15 +0000

Paul Rubin coughed up the following:

> Citizen Fish <fishy@<tut tut>answer.me.uk> writes:
>> (In my opinion) Any public CA not providing 1) and a relying party
>> agreement against it is a waste of time. Essentially you need to strike
>> up relying party agreements with CAs (and their revocation lists) which
>> ensure that they carry liability for not meeting their advertised CPs,
>> which will include authentication process, crl publishing frequency and
>> process.
>
> Do these even exists? I've seen CA agreements that indemnify the
> cert holder in various ways, but I've never seen one that promised
> anything for relying parties.

Sure do, I am currently working for one in the UK.

Be-aware that these agreements provide liability against the CA process NOT
the identity itself, ie. they will pay if they do not follow their
authentication process.

-- 
Come inside boy - they call this fun!,..........



Relevant Pages

  • Re: PKI and Relying Parties
    ... >> Any public CA not providing 1) and a relying party ... I've seen CA agreements that indemnify the ... Be-aware that these agreements provide liability against the CA process NOT ... authentication process. ...
    (comp.security.misc)
  • Re: PKI and Relying Parties
    ... > agreement against it is a waste of time. ... > relying party agreements with CAs which ensure ... > include authentication process, ... I've seen CA agreements that indemnify the ...
    (comp.security.ssh)
  • Re: PKI and Relying Parties
    ... > agreement against it is a waste of time. ... > relying party agreements with CAs which ensure ... > include authentication process, ... I've seen CA agreements that indemnify the ...
    (comp.security.misc)
  • Re: PKI and Relying Parties
    ... I've seen CA agreements that indemnify the ... >> cert holder in various ways, but I've never seen one that promised ... > Be-aware that these agreements provide liability against the CA process NOT ... > authentication process. ...
    (comp.security.misc)