AW: gpg certificate authorities

JanuszA.Urbanowicz JanuszA.Urbanowicz
Mon Feb 18 17:09:02 2002

Huels, Ralf SCORE wrote/napisa=B3[a]/schrieb:
> > The problem is more social than technical - to have working CAs, they m=
> > be CAs that most people in the web of trust trust.=20
> Also, some people argue that X.509 is more interesting for commercial tru=
> centers than OpenPGP because the hierarchical PKI calls for a central tru=
> authority in a way the web of trust approach does not.

The CA trust is simply hardcoded into X509-aware apps. There is nothing that
prevents a subset of OpenPGP users to use a modified GnuPG that has hadcoded
trust for some key. It would give the same outcome. The only difference is
that absolute truth for some key is a requirement for X509 PKI while it is
note for OpenPGP.

OpenPGP for example allows such a situation: I am a Thawte WOT notary so I
trust their signing key. I set this key to have high (or even ultimate
trust). Other people who also trust the key may set this similarly. But
there's no way to enforce the setting. This is IMO the main disadvantage of
OpenPGP - that it requires user activity and dedication to function

