Re: EV certs: Doing more of what we already know doesn't work

2008-10-24 Thread Stefan Kelm
Cool! ;-) Verisign's CPS has been an inspiration for me for quite a few years now. E.g., this statement has been in there for a number of years: The Certificate, however, provides no proof of the identity of the Subscriber. Taken from page 12 of the current version, obviously (?) referring

EV certs: Doing more of what we already know doesn't work

2008-09-23 Thread Peter Gutmann
Inspired by Ian Grigg's comment (in the subject line) and various remarks made in a recent thread, I had a look at the Verisign 1.0 CPS from 1996 and the very latest Verisign CPS from June 2008, twelve years later. Here's the authentication requirements for businesses. One is from the 1.0 CPS,