Idea: Using GPG signatures for SSL certificates

2003-12-12 Thread Thomas Shaddack
The problem that makes me feel uneasy about SSL is the vulnerability of the certification authorities; when they get compromised, everything they signed gets compromised too. However, the system could be for some applications potentially get hardened to certain degree, using the web-of-trust

Re: Idea: Using GPG signatures for SSL certificates

2003-12-12 Thread Anonymous
Thomas Shadduck writes: The problem that makes me feel uneasy about SSL is the vulnerability of the certification authorities when they get compromised, everything they signed gets compromised too. Technically this is true, but the only thing that the CA signs is other keys. So it merely

Re: Idea: Using GPG signatures for SSL certificates

2003-12-12 Thread Thomas Shaddack
Thomas Shadduck writes: - cute :) Though I am more often called Shaddup. The problem that makes me feel uneasy about SSL is the vulnerability of the certification authorities when they get compromised, everything they signed gets compromised too. Technically this is