Re: Hacking PGP WoT onto X.509 systems



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Paul Rubin wrote:
"Peter S. May" <psmay@xxxxxxxxxxxx> writes:
Firstly, is anyone already trying this? Secondly, is there anything
fundamentally wrong with these notions?

Thawte did something like that for a while, as I remember.

What Thawte is doing is a pseudo-WoT system by which a user who has had
enough volunteer notaries certify his identity can have his own name on
a certificate issued by Thawte. While it's an interesting way to get a
certificate (I myself just became a notary for this system) it lacks an
important element of the WoT: From the sender/verifier's perspective,
there's only one "introducer"--Thawte--so the key user's trust
granularity is quite coarse.

The Thawte WoT cert program is also only for e-mail-only certs, but
CAcert.org applies a similar system to SSL-capable certs. Still,
neither is a real WoT in the useful sense.

PSM
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFFR5QEei6R+3iF2vwRAqtFAJ9JY3hTel11lkmUUJ9nrw39ZJ1JbwCgm134
VMjvImPuaqfJgwP6q3jzUyU=
=SrUK
-----END PGP SIGNATURE-----
.



Relevant Pages

  • Re: Cant install Thawte Certificate using Account Settings
    ... They expire in 2013. ... The two Thawte CA's show ... I try to select a certificate, and "Choose" just make the dialog go ... X509 expire in 2020-- different certs, ...
    (microsoft.public.mac.office.entourage)
  • Re: Thawte Digital Certificate Revocation List Issue
    ... > I am new to digital certificates and cannot get the Thawte certificate ... It's been awhile since I played with the Thawte certificates. ... Microsoft requires the cert ... CRL so Outlook doesn't know where to get ...
    (microsoft.public.security)
  • Re: exim4 SSL/TLS client: refusal to verify certificate
    ... >>trusted root certificate? ... > I concatenate all Thawte root certs ... > I find that a bit strange, since I cannot see why I should trust Thawte ...
    (Debian-User)
  • Re: Signing applets to load from any server
    ... certificate which can be served from any host/domain? ... Are you sure that these 'specific domain' certs. ... even for Thawte. ...
    (comp.lang.java.programmer)
  • Re: Harassment by SSL Provider?
    ... > this may be a ploy by Thawte to generate additional business. ... If they were sending you an email about an SSL certificate acquired ... It is *very* important to renew your SSL certificate if you are going to ...
    (Security-Basics)