Josselin Mouette wrote:
> On mar, 2008-03-25 at 02:11 +0100, Vincent Danjean wrote:
>> Hi,
>>
>> I CC other french DD that I know so that they can verify my information
>> and send it to this bug report too.
>> I hope these certificates will be included in Lenny :-)
> 
>> Note: SHA1 fingerprints have been taken from the french government document:
>> http://www.legifrance.gouv.fr/jopdf//jopdf/2007/0217/joe_20070217_0041_0126.pdf
>> (this is a "printed" version of the certificates)
>> I downloaded the certificates, look at their fingerprints with
>> openssl x509 -inform DER -fingerprint [-md5|-sha1] -in cert_igca_[d|r]sa.crt
>> The SHA1 fingerprint was the same as the one in the PDF document
>> I wrote the MD5 fingerprint that I got with openssl.
> 
> This is not enough to guarantee the validity of these fingerprints. Do
> you know whether it it possible to obtain them physically from an
> administration?

Buy the JO (official journal where French law are published) ?
What will tell you that the postmail service will not switch the document ?
What will tell you that the employee will give you the correct document ?

SHA1 fingerprint are published on two different official (government) web wites.
One of them publishes all laws (ie the JO). I hope its security is correct.

An different source could be a recent version of IE7 (but I cannot find it
around me...) as it should include these certificates (according to the
microsoft document[1] I cited earlier in this bug report).
  Can someone having access to IE7 up-to-date check this ?

  Regards,
    Vincent

[1] http://support.microsoft.com/default.aspx/kb/931125/en-us



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to