>I'd also like to go on the record that I think a visual indicator to
>the user that shows a cert is valid only under local policy is a
>fantastic idea and I support it wholeheartedly.  Of course UI is hard,
>especially with this opaque a topic to an average user, but I still
>think giving it a shot is a good idea.

A similar usage of colors - with poor results:
http://www.usablesecurity.org/papers/jackson.pdf 

Is local policy more or less secure to the user?  I'd say more ...
_______________________________________________
therightkey mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/therightkey

Reply via email to