Hello Volker,

Volker Kuhlmann wrote:
> On Mon 24 Sep 2007 14:20:48 NZST +1200, Raffael wrote:
> 
>> I found out, that there are no CAcert assurer listed here in
>> Christchurch. How come? Everyone using GnuPG? You can get you key signed
>> by CAcert!
> 
> Their website suffers from a common problem: it seems to have a lot of
> content, but doesn't tell me in 2 sentences what it is all about and
> what it does for me. Perhaps you could summarize? 

CAcert provides digital certificates for code signing, S/MIME, servers
(https, vpn) at no costs. But with a Web of Trust, that enables you to
receive points through assurance. For more information on the point
system, see: https://www.cacert.org/index.php?id=19

> I note their site cert
> isn't recognised by my browser, I can make the same sort of cert for the
> same price (i.e. $00.00) any time myself.
> 
That is a question of whom you trust :) One of CAcert's main goals is
the inclusion into mainstream browsers.

As a side note: I don't think that browsers / systems should include
root certificates at all. But thats probably not going to happen...

> Btw you seem to be mixing up gpg with ssl certificates. Maintain the
> distinction, they're for different purposes although use similar
> technology.

Sorry, for the lack of explanation: You can get you gpg/pgp key signed
by the CAcert key. See: http://wiki.cacert.org/wiki/PgpSigning

There is a downside on cacert: The documentation could be better and
they do not publish their source code under an open source license :/

Hope I could clear things up,
 Raffael


Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to