Skip to Content.
Sympa Menu

cacert-policy - Re: [CAcert-Policy] Proposal to stop issuing code signing certificates

Subject: Policy-Discussion

List archive

Re: [CAcert-Policy] Proposal to stop issuing code signing certificates


Chronological Thread 
  • From: Iang <iang AT iang.org>
  • To: Policy-Discussion <cacert-policy AT lists.cacert.org>
  • Subject: Re: [CAcert-Policy] Proposal to stop issuing code signing certificates
  • Date: Thu, 13 Dec 2007 23:44:02 +0100
  • List-archive: <https://lists.cacert.org/cgi-bin/mailman/private/cacert-policy>
  • List-id: Policy-Discussion <cacert-policy.lists.cacert.org>

Bernhard Fröhlich wrote:
Hi there,

please don't hit me now, but I had another look at chapter 4.3 of the current CPS (https://www.cacert.org/cps.php#p4.3) and could not find a specification about issuing code signing certificates. All I found about code signing certificates in the CPS was the extensions they contain.

Hmmm...  I don't think that is really policy.

The WIP CPS at http://svn.cacert.org/CAcert/policy.htm#p4.2 is a bit more specific about them, but it still needs some work before reaching DRAFT status.

Yes, that document probably defers this question to a proper policy. When written, that policy will be referred to.

See a wip here: http://wiki.cacert.org/wiki/PolicyDrafts/CodesigningAssurancePolicy

(Note that this is a wip, therefore ... not a policy.)

Therefore I propose to stop issuing code signing certificates till we have a policy about when and how they are issued.


OK!  What votes are there on this interesting question.?

iang




Archive powered by MHonArc 2.6.16.

Top of Page