[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-core-devel
Subject:    Re: Root Certificate integration of DFN-PCA
From:       Matthias Welwarsky <matze () stud ! fbi ! fh-darmstadt ! de>
Date:       2002-02-21 23:44:11
[Download RAW message or body]

On Thursday 21 February 2002 22:07, George Staikos wrote:
> On Thursday 21 February 2002 14:29, Michael Matz wrote:
> > > and did not accept their request due to legal issues.  Basically we
> > > have no way to defend ourself if someone asks us to import their
> > > certificate and a konqueror user gets scammed from this.  Right now we
> > > just import the Netscape certificate database entries into our own
> > > database.
> >
> > This is a very questionable argument.  For what reason exactly would we
> > accept netscape's certificate DB, but not DFN's?  I for one would trust
> > DFN certainly more than netscape if I really had to choose.  Also the
>
>    Because Netscape has a thorough process, backed by lawyers, which ensure
> the integrity of these signers.  We do not.  What we are doing is riding
> off that process for free.

not really :-) You can import any signer into netscapes cert7.db without 
interference of lawyers, simply via the browser interface, no difference to 
KDE. The instructions on how to do so are on display at the DFN-PCAs handbook 
to OpenSSL, which is very complete and has been a great help for me in the 
past.

regards,
	Matze
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic