Re: Idea: Using GPG signatures for SSL certificates

2003-12-12 Thread Thomas Shaddack
> Thomas Shadduck writes: - cute :) Though I am more often called Shaddup. > > The problem that makes me feel uneasy about SSL is the vulnerability of > > the certification authorities when they get compromised, everything > > they signed gets compromised too. > > Technically th

Re: Idea: Using GPG signatures for SSL certificates

2003-12-12 Thread Anonymous
Thomas Shadduck writes: > The problem that makes me feel uneasy about SSL is the vulnerability of > the certification authorities when they get compromised, everything > they signed gets compromised too. Technically this is true, but the only thing that the CA signs is other keys. So it merely me

Idea: Using GPG signatures for SSL certificates

2003-12-12 Thread Thomas Shaddack
The problem that makes me feel uneasy about SSL is the vulnerability of the certification authorities; when they get compromised, everything they signed gets compromised too. However, the system could be for some applications potentially get hardened to certain degree, using the web-of-trust appro