Skip to Content.
Sympa Menu

cacert-policy - Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored]

Subject: Policy-Discussion

List archive

Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored]


Chronological Thread 
  • From: Ian G <iang AT systemics.com>
  • To: Policy-Discussion <cacert-policy AT lists.cacert.org>
  • Subject: Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored]
  • Date: Wed, 23 May 2007 16:50:32 +0200
  • List-archive: <http://lists.cacert.org/cgi-bin/mailman/private/cacert-policy>
  • List-id: Policy-Discussion <cacert-policy.lists.cacert.org>

Johan van Selst wrote:


If we need
to talk about algorithms in a policy (do we?),


One of the audit criteria, DRC_A.2.d, says:

For each class of certificate, the CA provides technical details of certificate generation:

   1. size
   2. algorithms
   3. allowed lifetime
   4. method of generation
   5. purpose indicators (e.g., site, mail, file signing)
   6. signing (by root or intermediate certificate)
   7. representation of domains
   8. ensuring uniqueness

The content seems to be located currently in the CPS, around 4.3.1:

http://www2.futureware.at/svn/sourcerer/CAcert/policy.htm#p4.3

(Whether that's a yes or a no or an ok, I'll leave to you :)

then why not just copy
from, or even better simply refer to  the NIST standards on what are
considered "good" algorithms and keysizes.


Well, it is a little more than that. The CA has to decide what profile it supports, then adjust all the code and doco to suit.

That could be quite a bit of work for CAcert's developers. Just copying from the NSA is only the first part, albeit an easy part as they have probably thought it out well, and their B List is likely solid for a while.

iang




Archive powered by MHonArc 2.6.16.

Top of Page