Re: Certificate trust

From: Lars Olaussen (Isolauss_at_hotmail.com)
Date: 09/13/04

  • Next message: cw: "reloading windows"
    Date: Mon, 13 Sep 2004 15:03:12 +0200
    
    

    "Craig" wrote...
    >
    > What about trusting the user? Is there anything
    > that indicates whether the user is trustworthy
    > to do business with?

    Craig,

    As you mentioned, the CA (or RA) performs (hopefully) the initial
    authentication of the user according to the Certificate Policy and
    Certification Practice Statement. So, if you trust the CA, you could
    also trust the identity of the user.

    Authentication is what most PKIs only provide. You would have to
    implement other systems to check the background of users you want to do
    business with.

    Some PKIs provide limited liability for losses caused by the use of a
    digital certificate, but your case would probably not be covered by
    this. An example of liability provided here:

    https://www.verisign.com/repository/rpa.html

    See section 12. The classes defines the trust you should put into the
    identification of the certificate subject.

    Note that VeriSign have already issued some certificates to people who
    were not who they claimed to be, so trusting them to perform an accurate
    authentication would be up to you.

    Regards,
    Lars Olaussen
    Isolauss@hotmail.com


  • Next message: cw: "reloading windows"

    Relevant Pages

    • Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name
      ... > certificates is not what drives commercial certificate authority business ... such, the business model. ... It's the same thing with client ... the question is whether you can trust them to moderate ...
      (Bugtraq)
    • Re: Certificate confusion?
      ... Anyone can be a CA (Certificate Authorithy). ... I am sure you trust your mother, ... same source as trusted we can do business :-). ... session between my IE and your web server will still be secure. ...
      (microsoft.public.win2000.security)
    • Re: Cingular Pink-Slips Customers Who Travel Too Much
      ... Experience tells you which companies you can trust or not. ... Trusting any company is dangerously naive. ... If a company is in business to make money, it should want to be trustworthy. ... not all are in business and make a profit by pleasing the many. ...
      (alt.cellular.cingular)
    • RE: Code signing certificate
      ... usually you are required to be a 'business' and ... usually a matter of trust, and my clients seem to trust my work, signed or ... I mean they've got to have trust in you to install your self-cert on ... I'm happy to pay for a certificate, but they seem VERY expensive for what ...
      (microsoft.public.excel.programming)
    • Re: Proposal for a new PKI model (At least I hope its new)
      ... That is say I trust Paul Rubin's public key. ... two basic reasons for the SSL server domain name certificate: ... certificates have to check with the domain name infrastructure to see ... CA/PKI industry is that public keys be registered with the domain name ...
      (sci.crypt)

  • Quantcast