Re: A mighty fortress is our PKI

2010-07-25 Thread Paul Tiemann
to participate in the discussion. We're very open to considering the risks, and not afraid to make changes based on feedback like this. From my call with Edgecast I can tell you they feel the same way, and they're willing to make changes to improve. All the best, Paul Tiemann CTO, DigiCert, Inc

Re: A mighty fortress is our PKI, Part II

2010-07-27 Thread Paul Tiemann
, would the bad guy be able to backdate the signature? Paul Tiemann (DigiCert) - The Cryptography Mailing List Unsubscribe by sending unsubscribe cryptography to majord...@metzdowd.com

Re: A mighty fortress is our PKI

2010-07-27 Thread Paul Tiemann
operations from more perspectives than just dollars and cents. When I read that nist.gov link, the joke about the spherical cow popped into my head. Paul Tiemann (DigiCert) - The Cryptography Mailing List Unsubscribe by sending

Re: A mighty fortress is our PKI

2010-07-27 Thread Paul Tiemann
money. Looks like at least one site is out there: http://ie6update.com/ but has no Paypal donate button, and doesn't offer newcomers the reasons they should switch to something more modern. Maybe this is too utopian. But laughing does work, sometimes. Paul Tiemann (DigiCert

Re: A mighty fortress is our PKI

2010-07-27 Thread Paul Tiemann
around when this happened, but maybe revoking for Key compromise was considered just as good. And maybe it's rare enough not to need its own special if() statement in all the browsers. The browsers don't really do different things based on the reason code anyway (to my knowledge) Paul

Re: A mighty fortress is our PKI

2010-07-27 Thread Paul Tiemann
not actually sure what the fix would be for this, or even if there is a fix that needs to be made. Thus the hope to get it discussed on the list. Well, if nothing else, the smaller certificates might at least help whatever PKI library was getting the segv. Paul Tiemann (DigiCert

Re: A mighty fortress is our PKI

2010-07-28 Thread Paul Tiemann
/present/view?id=df9sn445_206ff3kn9gs Great slides! The TOFU/POP is nice, and my favorite concept was to translate every error message into a one sentence, easy-to-understand statement. Paul Tiemann (DigiCert) - The Cryptography

Re: A mighty fortress is our PKI

2010-07-28 Thread Paul Tiemann
--it felt like my chance to talk to a rock star. All the best, Paul Tiemann (DigiCert) - The Cryptography Mailing List Unsubscribe by sending unsubscribe cryptography to majord...@metzdowd.com

Re: A mighty fortress is our PKI, Part II

2010-07-28 Thread Paul Tiemann
that base themselves on CRL. Paul Tiemann (DigiCert) - The Cryptography Mailing List Unsubscribe by sending unsubscribe cryptography to majord...@metzdowd.com