Re: New Method for Authenticated Public Key Exchange without Digital Certificates

From: Michael Amling (nospam_at_nospam.com)
Date: 08/06/04


Date: Fri, 06 Aug 2004 14:30:39 GMT

Anne & Lynn Wheeler wrote:
>
> In fact, all the root trust keys ... even in PKI & digital
> certificates paradigm have this issue ... however, frequently they
> leave the issue of how the environment is initially populated with the
> initial root trust keys as an exercise for the student (or it is taken
> for granted as magically happening).

   The problem is certainly ignored in the downloading of web browsers.
I've never seen even https offered for downloading a browser, and even
if it were, how would the https connection be validated?
   Granted, you could spend a few dollars and get the browser on CD, but
I've never known anyone to do that. And it wouldn't answer the question
about which of the five dozen root certificates the browser recognizes
are worth trusting.

> at its simplest ... one could claim that the whole PGP environment
> implements such an infrastructure ... the ability to perform public
> key exchange w/o requiring certificates from certification authorities
> trust roots.
>
> as an aside ... i've long advocated "naked" public keys and that
> certificates frequently are redundant and superfluous.

--Mike Amling



Relevant Pages

  • Re: Self-signed security certificates.. (oh, the evil)
    ... >> and purpose of these certificates. ... and permissions. ... What is it supposed to do once it 'looks' at that policy file? ... It is *not* down to 'the browser' alone. ...
    (comp.lang.java.programmer)
  • Re: anti-malware progs ineffective
    ... >Mozilla is a very well done browser, that can be configured to block ... >consider checking out Mozilla. ... I always accept known certificates only temporarily. ... numbering to work halfway reliably. ...
    (sci.electronics.design)
  • Re: anti-malware progs ineffective
    ... >Mozilla is a very well done browser, that can be configured to block ... >consider checking out Mozilla. ... I always accept known certificates only temporarily. ... numbering to work halfway reliably. ...
    (sci.electronics.basics)
  • Re: sources for SSL certificates for SBS 2003
    ... certificates into their browser since some of them move around alot. ... There are some that offer basic validation that you own the domain for around $20pa. ... Steve Foster [SBS MVP] ...
    (microsoft.public.windows.server.sbs)
  • Re: How can I act as a Certificate Authority (CA) with openssl ??
    ... then putting that on a web site. ... problem if you were selling certificates using "Mickey Mouse" as the ... The browser maker and cert orgs like this since ...
    (comp.security.unix)

Quantcast