Subject: CAcert Code Development list.
List archive
Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-)
Chronological Thread
- From: Mario Lipinski <mario AT cacert.org>
- To: cacert-devel AT lists.cacert.org
- Cc: Ian G <iang AT cacert.org>
- Subject: Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-)
- Date: Wed, 17 Mar 2010 23:41:33 -0700
- Authentication-results: lists.cacert.org; dkim=pass (1024-bit key) header.i= AT cacert.org; dkim-asp=none
- Organization: CAcert (Board member, Organisation Assurance Germany, Wiki/Issue admin)
Am 15.03.10 17:59, schrieb Ian G:
If we then move to the Orga Admin context, the member is the Org. In
which case the Org has many private keys which it gives out to its
employees (who are not members). So in this case, the Org is primarily
responsible for the usage of those keys ... just like the Org is
primarily responsible for the usage of the office computers or the
corporate seal for purchasing stuff.
So it should be up to the organisation. If orgs like to backup/store all keys, they should. If they want only their employees to know the private part, it should be also fine for us.
In that context it might be reasonable to have the Org pre-create all
the keys and then provision them into browsers. Indeed it might be
reasonable to suggest that the employees must not create their keys,
because they are not "us" ! But maybe we don't need to go that far if
it is clear that the Org is the responsible entity.
We sign certificates, not private keys. So management of the private keys should be up to the organisation.
--
Mit freundlichen Grüßen / Best regards
Mario Lipinski
Board member, E-Mail:
mario AT cacert.org
Organisation Assurer (Germany), Internet: http://www.cacert.org
Wiki/Issue admin
CAcert
Support CAcert: http://www.cacert.org/index.php?id=13
http://wiki.cacert.org/wiki/HelpingCAcert
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), (continued)
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Dieter Hennig, 03/16/2010
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Ian G, 03/17/2010
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Dieter Hennig, 03/17/2010
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Dieter Hennig, 03/17/2010
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Ian G, 03/17/2010
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Dieter Hennig, 03/16/2010
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Mathieu Simon, 03/16/2010
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Faramir, 03/17/2010
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Mathieu Simon, 03/17/2010
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Andreas Bäß, 03/17/2010
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Ian G, 03/20/2010
- Re: LibreSSL: Organisation User Certificates, maybe little change to improve a lot? :-), Dieter Hennig, 03/20/2010
Archive powered by MHonArc 2.6.16.