NODE 7cde8078Cypherpunk Certification Authority
Aleph One <aleph1@dfw.net>Sun, 26 Nov 1995 04:51:44 +0800
Since now Netscape allows for user defined certification authorities
I would like to hear some ideas for a Cybpherpunk CA. Probably run by one
of the respected member in the group such as Sammer, Perry or Tim. I would
like to hear some discussion about creating the certificates based on
the web of trust of your PGP key, etc. Any takers?
Aleph One / aleph1@dfw.net
http://underground.org/
KeyID 1024/948FD6B5
Fingerprint EE C9 E8 AA CB AF 09 61 8C 39 EA 47 A8 6A B8 01
NODE 78fd8b32Re: Cypherpunk Certification Authority
"Perry E. Metzger" <perry@piermont.com>Sun, 26 Nov 1995 00:57:25 +0800
Aleph One writes:
> Since now Netscape allows for user defined certification authorities
> I would like to hear some ideas for a Cybpherpunk CA. Probably run by one
> of the respected member in the group such as Sammer, Perry or Tim. I would
> like to hear some discussion about creating the certificates based on
> the web of trust of your PGP key, etc. Any takers?
Hmmm. If someone is willing to find out what is needed to become a
C.A. and to run one, and it turns out not to be particularly onerous,
I or one of my corporate alter egos might be willing. I must say,
though, that being an anti-fan of X.509 the situation would be ironic...
Perry
NODE 5f5bcf69Re: Cypherpunk Certification Authority
sameer <sameer@c2.org>Sun, 26 Nov 1995 01:45:59 +0800
> though, that being an anti-fan of X.509 the situation would be ironic...
>
> Perry
Speaking of ironic situations, my sister recently
mentioned that her fiancee is a good friend of Jim Bidzos and asked
me if I wanted a job with RSADSI. If I wasn't planning on leaving
the employed-by-others arena I would have seriously considered it. ;-)
In terms of being a CA. I have considered making Community
COnneXion a CA for its customers, but I haven't done much research
into what is involved in doing that.
--
sameer Voice: 510-601-9777
Community ConneXion FAX: 510-601-9734
The Internet Privacy Provider Dialin: 510-658-6376
http://www.c2.org/ (or login as "guest") sameer@c2.org
NODE 6bb53de6Re: Cypherpunk Certification Authority
Andreas Bogk <andreas@artcom.de>Sun, 26 Nov 1995 03:03:26 +0800
-----BEGIN PGP SIGNED MESSAGE-----
>>>>> "Perry" == Perry E Metzger <perry@piermont.com> writes:
Perry> become a C.A. and to run one, and it turns out not to be
Perry> particularly onerous, I or one of my corporate alter egos
Perry> might be willing. I must say, though, that being an
Perry> anti-fan of X.509 the situation would be ironic...
;).
Ten easy steps to become a C.A.:
1. get a copy of SSLeay (try ftp://ftp.cert.dfn.de/pub/tools/net/ssleay)
2. install it
3. generate a key using 'genrsa -idea -rand
/dev/random:/var/adm/messages:/etc/utmp:/proc/net/dev -out
cypherpunks.key 1024'. Substitute a higher number than 1024 depending
on your paranoia. Choose an inconvenient pass phrase.
4. Use your favourite secret splitting method and send key and pass
phrase to respected members of the cypherpunks community.
5. Generate your X.509 certificate using makecert.
6. Sign other people's certificate using x509.
7.-10. Get yourself a decent beer and Applied Crytography 2nd Ed.
Sorry, I'd love to give you details for 5 and 6, but I'm out of
time. I'll deliver them tomorrow.
Andreas
-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
Comment: Processed by Mailcrypt 3.4, an Emacs/PGP interface
iQCVAgUBMLdlB0yjTSyISdw9AQEs5QP/T5K8qdD0lX9NrqsYxcudpUSPBoAOuzUb
oy2IllKpliviJaGZCb5o6ga1jgoCObyhe6HNaaQINOHhWyP09Gzs+jdNxMsqcK1z
Vxt9NOH+cHyBC67rPU77vDwB27dXNIob+u1KwKldWkSB3Id+qLR+Pz5yXylYAMhI
ccuVcA0BpOU=
=iGp+
-----END PGP SIGNATURE-----
NODE 40004a42Re: Cypherpunk Certification Authority
Michael Froomkin <froomkin@law.miami.edu>Sun, 26 Nov 1995 04:29:09 +0800
Alas, certain critical social steps have been elided in the proposed
protocol. As it happens, I'm working on an article, to be published in
the Oregon Law Review next year, on "The Importance of Trusted Third
Parties in Electronic Commerce". It's mostly about the care and feeding
(and legal liability!) of a CA. Unfortunately for this discussion, I'm
only part way through my thinking about what the liability of a CA might
be so I don't have carefully considered conclusions to offer you. Try me
again in a few weeks.
In the absence of legislation...
[PLUG: if you haven't already done so, RUSH to my homepage
http://www.law.miami.edu/~froomkin
and click on the link to the ABA draft of the digital signature
guidelines. This mis-named document is actually all about CA liability.
Comment period now extended to mid-January.]
...you need to worry about who might *use* the certificates, and what they
might to do the CA in the case of mis-certification or other misfortune.
At the very least, there is a tort claim for "negligent
mis-representation" the first time an inaccurate certificate, or an
accurate certificate referencing a compromised key, is used in a
transaction that goes sour.
I don't give legal advice on line, ever, so I can't tell you how to avoid
liability. I'm not even sure that this is possible absent legislation. I
can, however, mention techniques that at this writing seem to me to be an
essential part of any liability-reduction strategy, without any claim that
these alone suffice to protect you to the level that I would want to be
protected (I'm a cautious guy).
Repeat: I do claim that pending further thought these steps seem necessary,
**not** that they are sufficient:
A) Establish a clear certification policy document, describing in detail
what checks are made before issuing a certificate, how quickly CRLs are
posted, and where. This doesn't mean onerous checks are necessary, just
that you need to be clear as to what checking a certficiate from you
emboidies. Publish this document.
B) Reference this policy document in every certificate.
C) Don't settle for less than X.509 ver 3, because this allows the
certificate to carry within it a reference to the location of the CRL
list. Use that feature.
D) Establish a very reliable mechanism to ensure CRLs are posted where
and when they should be.
E) Use a secure, trusted, computer system.
Again, I note that this is NOT a complete list of what you need to do.
For more inspiration consult the ABA document referenced above.
A. Michael Froomkin | +1 (305) 284-4285; +1 (305) 284-6506 (fax)
Associate Professor of Law |
U. Miami School of Law | froomkin@law.miami.edu
P.O. Box 248087 | http://www.law.miami.edu/~froomkin
Coral Gables, FL 33124 USA | It's warm here.
NODE ee7d7e3eRe: Cypherpunk Certification Authority
Adam Shostack <adam@lighthouse.homeport.org>Sun, 26 Nov 1995 05:09:38 +0800
| C) Don't settle for less than X.509 ver 3, because this allows the
| certificate to carry within it a reference to the location of the CRL
| list. Use that feature.
Does X.509 version 3 fix the problem that Ross Anderson points
out in his 'Robustness Principles' paper? (Crypto '95 proceedings, or
ftp.cl.cam.ac.uk/users/rja14/robustness.ps.Z)
Its an excellent paper, well worth reading, but the basic
problem is that X.509 encrypts before signing.
Adam
--
"It is seldom that liberty of any kind is lost all at once."
-Hume
NODE a02716a7Re: Cypherpunk Certification Authority
chen@intuit.com (Mark Chen)Sun, 26 Nov 1995 10:26:44 +0800
> | C) Don't settle for less than X.509 ver 3, because this allows the
> | certificate to carry within it a reference to the location of the CRL
> | list. Use that feature.
>
> Does X.509 version 3 fix the problem that Ross Anderson points
> out in his 'Robustness Principles' paper? (Crypto '95 proceedings, or
> ftp.cl.cam.ac.uk/users/rja14/robustness.ps.Z)
I don't believe that it does.
For those who missed it, the problem is that the encryptor in an
encrypt-before-signing protocol is able to use his knowledge of the
factorization of the encryption modulus to compute a discrete log, and
forge another message for which the signature is also valid (after
registering the new exponent).
- Mark -
--
Mark Chen
chen@intuit.com
415/329-6913
finger for PGP public key
D4 99 54 2A 98 B1 48 0C CF 95 A5 B0 6E E0 1E 1D
NODE 22980da9Re: Cypherpunk Certification Authority
Aleph One <aleph1@dfw.net>Sun, 26 Nov 1995 04:33:08 +0800
On Sat, 25 Nov 1995, Perry E. Metzger wrote:
> Hmmm. If someone is willing to find out what is needed to become a
> C.A. and to run one, and it turns out not to be particularly onerous,
> I or one of my corporate alter egos might be willing. I must say,
> though, that being an anti-fan of X.509 the situation would be ironic...
>
> Perry
Well from Netscape perspetive as far as I know you need nothing. Basicly
when the browser finds a new CA that it does know about it promts
the user and through a series of dialog boxes the user chooses to trust
it or not. (Well that is theory, and what netscape release notes say, since
I dont have access to an SSL server right now, and would need to figure
out how to make my own certificate, I havent tried it).
Aleph One / aleph1@dfw.net
http://underground.org/
KeyID 1024/948FD6B5
Fingerprint EE C9 E8 AA CB AF 09 61 8C 39 EA 47 A8 6A B8 01
NODE 86950aa9Re: Cypherpunk Certification Authority
Jeff Weinstein <jsw@netscape.com>Mon, 27 Nov 1995 19:20:22 +0800
Alex Strasheim wrote:
>
> > Basicly when the browser finds a new CA that it does know about it promts
> > the user and through a series of dialog boxes the user chooses to trust it
> > or not.
>
> Is anyone running an ssl web server that would let us see how this works?
A little bird pointed me toward https://www.secret.org. I have no
idea who they are...
--Jeff
--
Jeff Weinstein - Electronic Munitions Specialist
Netscape Communication Corporation
jsw@netscape.com - http://home.netscape.com/people/jsw
Any opinions expressed above are mine.
NODE 0e735763Re: Cypherpunk Certification Authority
Jyri Kaljundi <jk@digit.ee>Tue, 28 Nov 1995 00:37:11 +0800
On Mon, 27 Nov 1995, Jeff Weinstein wrote:
> Alex Strasheim wrote:
> >
> > > Basicly when the browser finds a new CA that it does know about it promts
> > > the user and through a series of dialog boxes the user chooses to trust it
> > > or not.
> >
> > Is anyone running an ssl web server that would let us see how this works?
>
> A little bird pointed me toward https://www.secret.org. I have no
> idea who they are...
Another way to see the dialog boxes is to delete one of the CA's that
came with Netscape Navigator and then connect to for example
https://www.netscape.com/
What software there is available (preferably non-commercial) to become a
CA? Is for example the SSLeay package enough?
Jri Kaljundi
jk@digit.ee
Digiturg http://www.digit.ee/
NODE 081891e0Re: Cypherpunk Certification Authority
Eric Young <eay@mincom.oz.au>Tue, 28 Nov 1995 01:39:42 +0800
On Mon, 27 Nov 1995, Jyri Kaljundi wrote:
> What software there is available (preferably non-commercial) to become a
> CA? Is for example the SSLeay package enough?
I'm just making a quick comment on this point. The current SSLeay setup,
I would say no. You can do it but you need to write more stuff to do it
correctly. It is a bit of an evil cludge.
The next version should be able to do this (I hope, depending on time).
The next version has (will have) several different ways to 'retrieve'
certificates which can be added via an run time API (the application can
'push' new methods into the library during startup). I will probably not
have time to put in a 'socket' based certificate server but it should be
simple enough for this to be written by other people. It should also be
simple enough for other people to write some routines that conform to the
API so that the netscape DB files can be accessed by SSLeay (along with
the current SSLeay 'hash directories' and the socket based lookup (if it
gets put in)).
The most importaint change is that I will support CRL if they are
present and probably generate an 'warning' if there is no CRL. I still
need to write a simple application to do a basic 'keep track of issued
certificates' and generate a CRL if required. The library routines to
write a CA are present, they just need to be glued to a simple database
(which I will probably do in my demo case via ascii files in directories).
This version will also hopefully support the concept of selecting a
certificate/private key from a set of certificates, attempting to pick a
certificate that is in the same 'tree' as another certificate.
This concept of multiple certificates for a person is useful for
SSLtelnet, so that each 'host domain' can issue it's own certificates (and
keep track of it's own CRL). To let some-one login, just issue them with
a 'certificate' for that 'host domain'.
eric
--
Eric Young | Signature removed since it was generating
AARNet: eay@mincom.oz.au | more followups than the message contents :-)
NODE 4d388bbeRe: Cypherpunk Certification Authority
sameer <sameer@c2.org>Tue, 28 Nov 1995 01:08:16 +0800
You can also snag the apache/ssl webserver and set one up for
yourself, to see what it looks like. Non-commercial use only, as
limited by the RSAREF license.
The SSL webserver on c2.org is "verisign blessed", so you
can't use it for testing. (Hm, someone should think up a suitably
derisive term of that..)
>
> Alex Strasheim wrote:
> >
> > > Basicly when the browser finds a new CA that it does know about it promts
> > > the user and through a series of dialog boxes the user chooses to trust it
> > > or not.
> >
> > Is anyone running an ssl web server that would let us see how this works?
>
> A little bird pointed me toward https://www.secret.org. I have no
> idea who they are...
>
> --Jeff
>
> --
> Jeff Weinstein - Electronic Munitions Specialist
> Netscape Communication Corporation
> jsw@netscape.com - http://home.netscape.com/people/jsw
> Any opinions expressed above are mine.
>
--
sameer Voice: 510-601-9777
Community ConneXion FAX: 510-601-9734
The Internet Privacy Provider Dialin: 510-658-6376
http://www.c2.org/ (or login as "guest") sameer@c2.org
NODE 34a28992Re: Cypherpunk Certification Authority
Alex Strasheim <cp@proust.suba.com>Sun, 26 Nov 1995 05:48:21 +0800
> Basicly when the browser finds a new CA that it does know about it promts
> the user and through a series of dialog boxes the user chooses to trust it
> or not.
Is anyone running an ssl web server that would let us see how this works?
NODE f49540a0Re: Cypherpunk Certification Authority
Laurent Demailly <dl@hplyot.obspm.fr>Tue, 28 Nov 1995 04:39:16 +0800
Jeff Weinstein writes:
> > Is anyone running an ssl web server that would let us see how this works?
>
> A little bird pointed me toward https://www.secret.org. I have no
> idea who they are...
For those that want to know what's there without wasting their time
'upgrading' to netscape 2.x,etc....
There is (currently?) very little, the only thing interesting I found
is that 'they' claim to give away free CA if you mail at
<ca@secret.org> (their 'Project7'/'666 Crypto' route...)
Regards
dl
--
Laurent Demailly * http://hplyot.obspm.fr/~dl/ * Linux|PGP|Gnu|Tcl|... Freedom
Prime#1: cent cinq mille cent cinq milliards cent cinq mille cent soixante sept
Marxist SEAL Team 6 jihad break mururoa explosion smuggle