NODE 80b92400X.509 certs that don't guarantee identity
Alex Strasheim <cp@proust.suba.com>Mon, 26 Feb 1996 13:28:37 +0800
On the 23rd, Jeff Weinstein said this concerning the natural
semi-anonymity of the net:
> Given that verisign and others will soon begin issuing large numbers of
> certificates that do not guarantee the identity of the key holder, it seems
> that this tradition will continue even with the wide deployment of X509
> certs.
This has been bugging me since I read it. I'm not sure I understand the
plan; it only makes sense to me if "anonymous" X.509 certs are issued
for user authentication only, not for server authentication. Is that
what this is about?
(If anonymous certs are issued for servers, why should such a cert be
treated any differently than one I generate on my own, which causes
warning screens about an unknown CA to pop up?)
NODE b6a142bbRe: X.509 certs that don't guarantee identity
Tom Weinstein <tomw@netscape.com>Fri, 1 Mar 1996 08:03:17 +0800
Michael A. Atzet wrote:
> Jeff Weinstein wrote:
> >
> > The navigator will not be configured to automatically trust the
> > verisign level 1 and 2 certificates for SSL servers. You will get
> > the same warning dialog with these certs as you do with one you
> > generate on your own.
> >
> How will Navigator differentiate between the different level certs? I
> am not aware of any fields in the cert itself that designate what
> level it is. I know that the subject info would "look" different for
> a persons name vs. email address vs commom name.
The different levels of certificate are signed by different CA certs.
--
Sure we spend a lot of money, but that doesn't mean | Tom Weinstein
we *do* anything. -- Washington DC motto | tomw@netscape.com
NODE 8f74d461Re: X.509 certs that don't guarantee identity
Jeff Weinstein <jsw@netscape.com>Fri, 1 Mar 1996 11:45:05 +0800
Michael A. Atzet wrote:
> How will Navigator differentiate between the different level certs? I am not
> aware of any fields in the cert itself that designate what level it is.
> I know that the subject info would "look" different for a persons name vs.
> email address vs commom name.
The navigator will not differentiate them. We build in a default set of
CA certificates into the navigator, and then allow the user to modify them as
they see fit based on their local trust policy. The default set of CAs that
we ship with our product will not include the verisign level 1&2 CAs as trusted
SSL Server CAs.
--Jeff
--
Jeff Weinstein - Electronic Munitions Specialist
Netscape Communication Corporation
jsw@netscape.com - http://home.netscape.com/people/jsw
Any opinions expressed above are mine.
NODE 093f701dRe: X.509 certs that don't guarantee identity
"Michael A. Atzet" <atzet@vnet.ibm.com>Sat, 2 Mar 1996 15:34:58 +0800
Jeff Weinstein wrote:
>
> Alex Strasheim wrote:
> >
> > On the 23rd, Jeff Weinstein said this concerning the natural
> > semi-anonymity of the net:
> >
> > > Given that verisign and others will soon begin issuing large numbers of
> > > certificates that do not guarantee the identity of the key holder, it seems
> > > that this tradition will continue even with the wide deployment of X509
> > > certs.
> >
> > This has been bugging me since I read it. I'm not sure I understand the
> > plan; it only makes sense to me if "anonymous" X.509 certs are issued
> > for user authentication only, not for server authentication. Is that
> > what this is about?
> >
> > (If anonymous certs are issued for servers, why should such a cert be
> > treated any differently than one I generate on my own, which causes
> > warning screens about an unknown CA to pop up?)
>
> The navigator will not be configured to automatically trust the verisign
> level 1 and 2 certificates for SSL servers. You will get the same warning
> dialog with these certs as you do with one you generate on your own.
>
> --Jeff
>
> --
> Jeff Weinstein - Electronic Munitions Specialist
> Netscape Communication Corporation
> jsw@netscape.com - http://home.netscape.com/people/jsw
> Any opinions expressed above are mine.
How will Navigator differentiate between the different level certs? I am not
aware of any fields in the cert itself that designate what level it is.
I know that the subject info would "look" different for a persons name vs.
email address vs commom name.
--
Michael A. Atzet IBM AIX Systems Center Roanoke, Texas
*** All opinions above are mine and not necessarily that of IBM. ***
atzet@vnet.ibm.com
NODE 443a4fd9Re: X.509 certs that don't guarantee identity
Bob Snyder <rsnyder@janet.advsys.com>Sat, 2 Mar 1996 17:25:58 +0800
> The navigator will not differentiate them. We build in a default set of
>CA certificates into the navigator, and then allow the user to modify them as
>they see fit based on their local trust policy. The default set of CAs that
>we ship with our product will not include the verisign level 1&2 CAs as
>trusted
>SSL Server CAs.
With the level 1&2 CA certs be include but not enabled, or will users have
to go pull them themselves?
Bob
NODE 103cbcabRe: X.509 certs that don't guarantee identity
Jeff Weinstein <jsw@netscape.com>Thu, 29 Feb 1996 15:02:26 +0800
Alex Strasheim wrote:
>
> On the 23rd, Jeff Weinstein said this concerning the natural
> semi-anonymity of the net:
>
> > Given that verisign and others will soon begin issuing large numbers of
> > certificates that do not guarantee the identity of the key holder, it seems
> > that this tradition will continue even with the wide deployment of X509
> > certs.
>
> This has been bugging me since I read it. I'm not sure I understand the
> plan; it only makes sense to me if "anonymous" X.509 certs are issued
> for user authentication only, not for server authentication. Is that
> what this is about?
>
> (If anonymous certs are issued for servers, why should such a cert be
> treated any differently than one I generate on my own, which causes
> warning screens about an unknown CA to pop up?)
The navigator will not be configured to automatically trust the verisign
level 1 and 2 certificates for SSL servers. You will get the same warning
dialog with these certs as you do with one you generate on your own.
--Jeff
--
Jeff Weinstein - Electronic Munitions Specialist
Netscape Communication Corporation
jsw@netscape.com - http://home.netscape.com/people/jsw
Any opinions expressed above are mine.
NODE 4372797eRe: X.509 certs that don't guarantee identity
djw@vplus.com (Dan Weinstein)Tue, 27 Feb 1996 12:47:58 +0800
On Sun, 25 Feb 1996 22:48:51 -0600 (CST), you wrote:
>On the 23rd, Jeff Weinstein said this concerning the natural
>semi-anonymity of the net:
>
>> Given that verisign and others will soon begin issuing large numbers of
>> certificates that do not guarantee the identity of the key holder, it seems
>> that this tradition will continue even with the wide deployment of X509
>> certs.
>
>This has been bugging me since I read it. I'm not sure I understand the
>plan; it only makes sense to me if "anonymous" X.509 certs are issued
>for user authentication only, not for server authentication. Is that
>what this is about?
>
>(If anonymous certs are issued for servers, why should such a cert be
>treated any differently than one I generate on my own, which causes
>warning screens about an unknown CA to pop up?)
Verisign will offer a number of levels of certificates. The
certificate that Jeff refered to requires only a unique email address
and is available for free. For obvious reasons you should not trust
theses keys for credit card information or anything else that you feel
is confidential. This is why Navigator allows you configure what keys
you accept as well as what certifications you will accept.
Dan Weinstein
djw@vplus.com
http://www.vplus.com/~djw
PGP public key is available from my Home Page.
All opinions expressed above are mine.
"I understand by 'freedom of Spirit' something quite definite -
the unconditional will to say No, where it is dangerous to say
No.
Friedrich Nietzsche