Skip to Content.
Sympa Menu

cacert-policy - Re: proposal to stop issuing class3 certificates

Subject: Policy-Discussion

List archive

Re: proposal to stop issuing class3 certificates


Chronological Thread 
  • From: Alexander Prinsier <aphexer AT cacert.org>
  • To: cacert-policy AT lists.cacert.org
  • Cc: Philipp Guehring <philipp AT cacert.org>
  • Subject: Re: proposal to stop issuing class3 certificates
  • Date: Wed, 13 Jan 2010 18:25:21 +0100
  • Authentication-results: lists.cacert.org; dkim=pass (1024-bit key) header.i= AT cacert.org; dkim-asp=none

On 01/13/2010 06:14 PM, Philipp Guehring wrote:
> So the easier option I think would be to encode it in the end-user
> certificates, whether the certificate is an assured one, or not.
> The other advantage we have with the encoding in the end-user
> certificates is that we could even encode more details into it, like
> putting the actual amount of assurance points in it.

How well is this extra encoding supported by the Apache+PHP setup you
referred to? Then you need to be able to tell Apache/PHP to explicitly
check this attribute, I'm not sure how well that's supported.

Alexander

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature




Archive powered by MHonArc 2.6.16.

Top of Page