cacert-sysadm AT lists.cacert.org
Subject: CAcert System Admins discussion list
List archive
Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST
Chronological Thread
- From: Ian G <iang AT iang.org>
- To: Guillaume ROMAGNY <guillaume AT tiebogos.fr>
- Cc: cacert-sysadm AT lists.cacert.org
- Subject: Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST
- Date: Sun, 13 Sep 2009 20:15:25 +0200
On 13/09/2009 13:10, Guillaume ROMAGNY wrote:
http://bugs.cacert.org/view.php?id=775
I have checked (too quickly?) the CPS
http://svn.cacert.org/CAcert/policy.htm
and CAcert website
https://www.cacert.org/index.php?id=19
Hmmm... that page is annoying. I wonder if we can just drop it.
The overall is unclear because Orgs are not part of the audit.
CPS says 6 months or better 24 month if user is assured
CAcert website adds "Code signing certificates" is limited to 12 months.
Organisations are basically assured so the lifetime should be 24 months
(or 12 months for codesigning).
unless Ian interprets the texts in a more formal way.
I think your interpretation is about right. Without some special condition, the org certs should be "up to 24 months" as they are assured.
It's a CPS issue not an assurance issue I guess, so that saves is from having to worry about missing OA dox.
Audit probably doesn't care however if you can issue 24 months and only issue 12 months. This is more a business issue than a reliance issue.
So it's a matter of just fixing it whenever. There is also the issue of PGP signatures, which is also 12m instead of 24.
iang
- Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Wytze van der Raay, 09/09/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Guillaume ROMAGNY, 09/09/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Wytze van der Raay, 09/09/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Wytze van der Raay, 09/11/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Guillaume ROMAGNY, 09/11/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Wytze van der Raay, 09/13/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Guillaume ROMAGNY, 09/13/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Ian G, 09/13/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Guillaume ROMAGNY, 09/13/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Wytze van der Raay, 09/13/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Andreas Bürki, 09/11/2009
- RE: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Bas van den Dikkenberg, 09/12/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Guillaume ROMAGNY, 09/11/2009
- Re: Replacement of CAcert signing server - no service on Sep 11 14:00 - 22:00 CEST, Guillaume ROMAGNY, 09/09/2009
Archive powered by MHonArc 2.6.16.