Re: Fixing SSL quickly

2012-03-27 Thread ianG
On 28/03/12 12:29 PM, John Nagle wrote: On 3/23/2012 11:37 AM, Kevin Chadwick wrote: How can a free CA afford to validate its customers? That's like saying, how can open source hope to be bug-free :) By working with volunteers, like every other open organisation. iang

Re: Restricting which CAs can issue certs for which hostnames

2012-03-27 Thread John Nagle
On 9/2/2011 11:42 PM, Daniel Veditz wrote: On 8/31/11 3:52 PM, Hill, Brad wrote: Mozilla could add a certificate it controls to the trusted root store with which it cross-signs other CA certs, adding a nameConstraints in the process, yes? In theory. In practice Firefox uses the historical cert

Re: Fixing SSL quickly

2012-03-27 Thread John Nagle
On 3/23/2012 11:37 AM, Kevin Chadwick wrote: What are the plans to fix SSL. Would it be good to have a collaborated, IE, Firefox, Chrome single free CA (like startssl) where the rogue CA issue is prevented and security could be handled properly by eventually removing all other CAs from browsers.