Google 그룹스는 더 이상 새로운 유즈넷 게시물 또는 구독을 지원하지 않습니다. 과거의 콘텐츠는 계속 볼 수 있습니다.

CAs and country restrictions

조회수 0회
읽지 않은 첫 메시지로 건너뛰기

Gervase Markham

읽지 않음,
2007. 5. 24. 오전 9:39:5607. 5. 24.
받는사람
There are currently two CAs who have applied for inclusion in the NSS
store but their audits were done by their respective governments and are
classified, and/or they are directly controlled by those governments.

They are:

KISA (South Korea, .kr)
https://bugzilla.mozilla.org/show_bug.cgi?id=335197
DCSSI (France, .fr)
https://bugzilla.mozilla.org/show_bug.cgi?id=368970

I am told that later this year, it will be technically possible in NSS
to add additional restrictions to roots in the store. This comes with
the SQLite port of the back-end database that Bob Relyea is doing.

My proposal is that we accept such CAs, but use this technical
capability to restrict them to signing certificates for domains under
the appropriate TLD. The logic is that citizens of those countries have
to trust their government anyway, but that citizens of other countries
should not be forced to.

Note that both CAs have been accepted, unrestricted, into the Microsoft
Root Program, on the basis of "trust us, we did the audit" letters
written by the respective governments.

A useful thought experiment might be to ask what would happen if a CA
from North Korea were to apply for inclusion under the same types of
condition.

Comments?

Gerv

새 메시지 0개