Subject: Policy-Discussion
List archive
- From: Philipp Gühring <pg AT futureware.at>
- To: Policy-Discussion <cacert-policy AT lists.cacert.org>
- Subject: Re: [CAcert-Policy] No Identity info in SSL server cert?
- Date: Sun, 13 May 2007 19:48:23 +0200
- List-archive: <http://lists.cacert.org/cgi-bin/mailman/private/cacert-policy>
- List-id: Policy-Discussion <cacert-policy.lists.cacert.org>
- Organization: Futureware 2001
Hi,
> OK, so as promised, let's check this bug out.
>
> I checked my certificate for SSL use and it has no
> identifying info in (for example) the OU field. (Whereas my
> individual email certs do have my name in them.) This
> matches the above claim made on the wiki as found by mfolimun.
Ok, I´ll try to explain it a again:
X.509 has 3 common fields for putting the name into:
CN (CommonName)
O (Organisation)
OU (OrganisationUnit, could be translated as department)
O and OU are reserved for organisations. (Some CA´s put other weird stuff in
those fields, but CAcert doesn´t want to abuse those fields)
CN is filled with the personal name for client certificates, and filled with
the servername for server certificates.
I personally guess that the X.509 designers originally didn´t thought that
individuals that are not associated with any organisation exist that would
ever have enough money to buy themself a server certificate.
> I checked one other CA's cert for some website, and the
> owner was identified in the OU field.
Yes, Peter Gutmann has a long list of weird X.509 practices in his
styleguide ...
> Why does CAcert's CA strip any identifying info from the
> other fields? Is there a reason why this is so?
* We haven´t found a field where we could put it into in a sane way.
* We didn´t want to create our own propietory extension
* There wasn´t enough demand for it yet
* Nobody reads the values in those fields anyway
Choose any 3 of the 4 options
> (I can imagine many myself ... but I want to hear the CA's
> reasons.)
Which ones did you imagine?
> Then, in the CPS, it states that:
>
> Relying Party Statement
> A relying party may rely on the User named in a certificate
> having been assured to at least 50 points.
> Now, we could argue that both ways, in comparison to the
> above. But for integrity of claim, we should be clear what
> we are intending to do here; and rewrite that relying party
> statement ... or the certs policy ... to match.
The Relying Party Statement does not say that we put the name of the user in
a
certificate in any case. It just says that you may rely in it if the user is
named.
> Comments?
Well, that´s why I pushed to have a standardisation officer to work on issues
like that, that X.509 is missing a PersonalName field.
(Which lead to funny situations like Firefox demanding Firefix Extensions to
be signed by Organisations, and claiming that extensions which are correctly
signed by individuals are "unsigned".)
Is anyone interested in representing CAcert in various standardisation bodies?
Best regards,
Philipp Gühring
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, (continued)
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, Greg Stark, 05/10/2007
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, Bernhard Froehlich, 05/10/2007
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, mfolimun, 05/11/2007
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, Ian G, 05/11/2007
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, mfolimun, 05/11/2007
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, Philipp Gühring, 05/13/2007
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, mfolimun, 05/13/2007
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, Philipp Gühring, 05/13/2007
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, mfolimun, 05/11/2007
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, Ian G, 05/13/2007
- [CAcert-Policy] No Identity info in SSL server cert?, Ian G, 05/13/2007
- Re: [CAcert-Policy] No Identity info in SSL server cert?, Philipp Gühring, 05/13/2007
- Re: [CAcert-Policy] No Identity info in SSL server cert?, Ian G, 05/14/2007
- Re: [CAcert-Policy] No Identity info in SSL server cert?, Philipp Gühring, 05/14/2007
- Re: [CAcert-Policy] No Identity info in SSL server cert?, Jac Kersing, 05/14/2007
- Re: [CAcert-Policy] No Identity info in SSL server cert?, Guillaume ROMAGNY, 05/14/2007
- Re: [CAcert-Policy] No Identity info in SSL server cert?, Philipp Gühring, 05/14/2007
- Re: [CAcert-Policy] No Identity info in SSL server cert?, Guillaume ROMAGNY, 05/14/2007
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, Ian G, 05/11/2007
- Re: [CAcert-Policy] Why is identity needed to authenticate domains?, Greg Stark, 05/10/2007
Archive powered by MHonArc 2.6.16.