AW: Robot CA at toehold.com

Adrian 'Dagurashibanipal' von Bidder avbidder@fortytwo.ch
Sat Dec 7 12:43:02 2002


--=-kISuUV01Xww6svo/NwS4
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

[no cc:s please - no, my MUA can't set custom headers :-( ]
On Fri, 2002-12-06 at 17:37, Kyle Hasselbacher wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>=20
> On Fri, Dec 06, 2002 at 10:38:01AM +0100, Adrian 'Dagurashibanipal' von B=
idder wrote:
>=20
> >Yes. IMHO the robotCA should=20
> > - only sign uids consisting of an email adress *only* (no realname, no
> >comment). Yes, people would have to get an additional uid, so what. But
> >then anyone looking at the key can see what was certified.
> > - with 0x11 signature (I see you're going to do that, good).
> > - add a policy URL
> > - have, as Ralf said, a uid comment warning that only the email address
> >has been checked on the signing key.
>=20
> If I never sign a UID with a real name or comment (only email address),
> then I don't need to yell so loud (or at all) that that's all I'm
> checking--that's all there is to check.

You'll still need to yell. And most people still wouldn't know or care
about the meaning of it. But with the Granny scenario, it wouldn't
matter much, I agree with you in this point.

> The down side to doing that is, there aren't so many keys that have just
> that.  People have to make a special UID to get signed.  I'd rather work
> with what's there now.  That having been said, I certainly see the securi=
ty
> advantage to doing it your way.

Hmmm. In the Granny scenario, I guess most people would generate the
first key in their life. And if it's integrated in a MUA installer, then
the key could be generated that way.

> Ultimately I'd like to be merely the first of many robot CAs that run.  I=
f
> others want to have a different (better?) policy on what they sign, I'd
> encourage that.
>=20
> [periodic challenges]
> >Of course, requirements here are
> > - a db of the uids that have been signed.
> > - publication of the key with revoked signatures.
>=20
> If I keep a list of UIDs that I've signed, I'd have to check the key
> servers to see which actually have my signature before I start challengin=
g
> them.  Just a detail.

I agree that as soon as someone is going to implement this, more
problems will appear.... I like my proposal, but I can see that it's
absolutely not easy to implement.

cheers
-- vbi

--=20
this email is protected by a digital signature:  http://fortytwo.ch/gpg

NOTE: keyserver bugs! get my key here: https://fortytwo.ch/gpg/92082481

--=-kISuUV01Xww6svo/NwS4
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iHMEABECADMFAj3x3w4sGmh0dHA6Ly9mb3J0eXR3by5jaC9sZWdhbC9ncGcvZW1h
aWwuMjAwMjA4MjIACgkQi6Qxi+Wn99ZtvwCfeZasan1Zw720bIC421WjWlYZToMA
n0PiU3dRtIixxKPuKo8miXrBzBr4
=ZJFK
-----END PGP SIGNATURE-----
Signature policy: http://fortytwo.ch/legal/gpg/email.20020822

--=-kISuUV01Xww6svo/NwS4--