Michael Nahrath
Thu Dec 5 14:09:02 2002

Kyle Hasselbacher <> schrieb am 2002-12-04 20:27
> Looking through Google, I found a thread here from a few months back that
> mentions the concept of a "Robot CA".  It's basically certificate authori=
> that verifies only the email address on a key.
> I've created such a beast.  There's information on it here:

> I'm interested to hear opinions on this.

Sorry I don't have time for deeper testing. Looks quite interesting.
Here just some short ideas after a first glimpse:

Verifying nothing but mail adresses can be valid for a limited time.
Mail addresses cange more often than real-life-identities.
Your signature should reflect this in some way.

Either you give signatures that expire after a certain time (eg 6 months).
I don't know if this is possible and if it doesn't raise a bunch of
compatibility problems.
Or you let the signing key expire (eg after 1 year).

IMHO one encrypted communication path is mandatory. That would verify that
the holder of the mail address is also in posess of the secret key and the
Not everybody will want your robot to sign all UIDs.

OK, they don't need to import all the signatures
but some easier way to choose would be preferable.

At least you might provide advice haow to export ones key striped to one
UID from a local GPG installation before sending it to the robot.

Another way of reducing the load and traffic was to reduce signing only to
mail adresses that are the Sender of the mail that sends the key.
That idea conflicts with the cgi-interface as it makes the ability to
_send_ mail from an address another verification critereia.

Rather include a
    RedirectPermanent /robotCA
    RedirectPermanent /RobotCA
to your website's .htaccess file. This will be a common mistyping :-)
Greeting, Michi
