[Ach] StartSSL for Business Sysadmins

ianG iang at iang.org
Sun Jan 12 19:17:56 CET 2014


On 12/01/14 19:35 PM, Aaron Zauner wrote:
> Hi,
>
> regarding recent discussion of Certificate Authorities and where/how to
> buy stuff: in my opinion that is not something we should discuss here,
> neither in the paper nor on the mailing list. This information is easily
> available on the internet. We also do not need a guide for that as ahmad
> suggested. I'm sorry, but that's not only out of scope but marketing for
> commercial vendors that make their money by providing a false sense of
> trust. And they are in fact doing it very poorly, often involving
> security risk for customers or sub-CAs.


I agree with everything except "easily available on the Internet" :)

PKI is a nightmare and it is designed to be so.  There is no way to make 
it Better, only more compliant with someone's guide or other.

iang




More information about the Ach mailing list