Subject: Policy-Discussion
List archive
- From: Ian G <iang AT systemics.com>
- To: Policy-Discussion <cacert-policy AT lists.cacert.org>
- Subject: Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored]
- Date: Wed, 23 May 2007 16:50:32 +0200
- List-archive: <http://lists.cacert.org/cgi-bin/mailman/private/cacert-policy>
- List-id: Policy-Discussion <cacert-policy.lists.cacert.org>
Johan van Selst wrote:
If we need
to talk about algorithms in a policy (do we?),
One of the audit criteria, DRC_A.2.d, says:
For each class of certificate, the CA provides technical details of certificate generation:
1. size
2. algorithms
3. allowed lifetime
4. method of generation
5. purpose indicators (e.g., site, mail, file signing)
6. signing (by root or intermediate certificate)
7. representation of domains
8. ensuring uniqueness
The content seems to be located currently in the CPS, around 4.3.1:
http://www2.futureware.at/svn/sourcerer/CAcert/policy.htm#p4.3
(Whether that's a yes or a no or an ok, I'll leave to you :)
then why not just copy
from, or even better simply refer to the NIST standards on what are
considered "good" algorithms and keysizes.
Well, it is a little more than that. The CA has to decide what profile it supports, then adjust all the code and doco to suit.
That could be quite a bit of work for CAcert's developers. Just copying from the NSA is only the first part, albeit an easy part as they have probably thought it out well, and their B List is likely solid for a while.
iang
- [CAcert-Policy] [Fwd: Re: 307 digit number factored], Iang, 05/22/2007
- Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored], Johan van Selst, 05/22/2007
- Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored], Ian G, 05/22/2007
- Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored], Johan van Selst, 05/23/2007
- Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored], Ian G, 05/22/2007
- Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored], Philipp Gühring, 05/22/2007
- Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored], Johan van Selst, 05/23/2007
- Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored], Ian G, 05/23/2007
- Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored], Johan van Selst, 05/23/2007
- Re: [CAcert-Policy] [Fwd: Re: 307 digit number factored], Johan van Selst, 05/22/2007
Archive powered by MHonArc 2.6.16.