Subject: Policy-Discussion
List archive
- From: Teus Hagen <teus AT theunis.org>
- To: Policy-Discussion <cacert-policy AT lists.cacert.org>
- Subject: Re: [CAcert-Policy] Revocation
- Date: Tue, 18 Dec 2007 14:54:58 +0100
- List-archive: <https://lists.cacert.org/cgi-bin/mailman/private/cacert-policy>
- List-id: Policy-Discussion <cacert-policy.lists.cacert.org>
- Openpgp: id=85796A23
- Organization: Stichting NLnet
On 12/18/2007 02:37 PM,
Lambert.Hofstra AT ins.com
wrote:
>>> ....
>> Why should the certificates be revoked? Is there any good reason why we
>> want to retroactively invalidate all signatures that were made with
>> those certificates? This would clearly violate our current CPS.
>>
>>
> Well, that's easy, when you join CAcert, you can rely on CAcert certs and
> agree to be bound by arbitration.
>
you are bound to arbitration also after you "unjoin" CAcert community if
I read the CCA well.
> When you're not part of the community you cannot rely on CAcert and CAcert
> (members) cannot rely on you.
>
> So when you leave the community, but are allowed to use the certs after
> that moment, Cacert members will rely on that cert although the owner of
> the cert is not a member.
>
What is defined as "unjoining"?
If you end the CCA agreement you are ending also the CAcert services and
your certificates are revoked (see: termination in the CAcert Community
Agreement
http://svn.cacert.org/CAcert/RegisteredUserAgreement.html ).
> So I would say: revoke all certs at time of leave (date X).
> This does not invalidate the cert completely, it just says that anything
> signed after date X is not valid
>
agree
teus
> Lambert Hofstra
>
> _______________________________________________
> Have you subscribed to our RSS News Feed yet?
>
> CAcert-Policy mailing list
> CAcert-Policy AT lists.cacert.org
> https://lists.cacert.org/cgi-bin/mailman/listinfo/cacert-policy
>
- Re: [CAcert-Policy] Policy about code signing certificate, (continued)
- Re: [CAcert-Policy] Policy about code signing certificate, Lambert.Hofstra, 12/17/2007
- Re: [CAcert-Policy] Policy about code signing certificate, Iang, 12/17/2007
- Re: [CAcert-Policy] Policy about code signing certificate, Lambert.Hofstra, 12/17/2007
- Re: [CAcert-Policy] Policy about code signing certificate, Iang, 12/17/2007
- Re: [CAcert-Policy] Policy about code signing certificate, Lambert.Hofstra, 12/17/2007
- Re: [CAcert-Policy] Policy about code signing certificate, Iang, 12/17/2007
- Re: [CAcert-Policy] Policy about code signing certificate, Lambert.Hofstra, 12/17/2007
- Re: [CAcert-Policy] Policy about code signing certificate, Bernhard Froehlich, 12/18/2007
- [CAcert-Policy] Revocation, Philipp Gühring, 12/18/2007
- Re: [CAcert-Policy] Revocation, Lambert.Hofstra, 12/18/2007
- Re: [CAcert-Policy] Revocation, Teus Hagen, 12/18/2007
- Re: [CAcert-Policy] Revocation, Philipp Gühring, 12/18/2007
- Re: [CAcert-Policy] Revocation, Lambert.Hofstra, 12/18/2007
- Re: [CAcert-Policy] Revocation, Iang, 12/18/2007
- Re: [CAcert-Policy] Revocation, Philipp Gühring, 12/18/2007
- Re: [CAcert-Policy] Revocation, Iang, 12/18/2007
- Re: [CAcert-Policy] Revocation, Philipp Gühring, 12/18/2007
- Re: [CAcert-Policy] Revocation, Iang, 12/18/2007
- Re: [CAcert-Policy] Revocation, Jens Paul, 12/18/2007
- Re: [CAcert-Policy] Revocation, Lambert.Hofstra, 12/18/2007
- Re: [CAcert-Policy] Revocation, Bernhard Fröhlich, 12/18/2007
Archive powered by MHonArc 2.6.16.