Skip to Content.
Sympa Menu

cacert-sysadm - Re: two possible MD5 hashed certificates in a chain

cacert-sysadm AT lists.cacert.org

Subject: CAcert System Admins discussion list

List archive

Re: two possible MD5 hashed certificates in a chain


Chronological Thread 
  • From: Philipp Guehring <philipp AT cacert.org>
  • To: cacert-sysadm AT lists.cacert.org
  • Cc: Daniel Black <daniel AT cacert.org>, dieter.hennig AT id.ethz.ch, Mario Lipinski <mario AT cacert.org>
  • Subject: Re: two possible MD5 hashed certificates in a chain
  • Date: Wed, 13 Jan 2010 11:34:25 +0100
  • Authentication-results: lists.cacert.org; dkim=pass (1024-bit key) header.i= AT cacert.org; dkim-asp=none

Hi,

>> Is this good/better/bad/ugly and why?
> 
> I am using class3 certs. So just turning class 3 off just because of a
> senseless desire of some people is not an option imho.

My suggestion is that we add some warning messages to the web-interface,
that tells the users about the problems with the class3 certificate and
discourages them to use it, (and to automatically use class1 instead of
class3) but to still allow class3 for those users that still need it.

Is this acceptable for everyone?

Best regards,
Philipp Gühring

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature




Archive powered by MHonArc 2.6.16.

Top of Page