Security Basics mailing list archives

Re: Electronic Signature And Encryption


From: krymson () gmail com
Date: 15 May 2007 18:00:28 -0000

Hopefully you get more replies than just me, as I may have some things wrong. Hopefully not, but the list should 
correct me otherwise. :)

I like that you separate those two topics. Encryption is the easiest and done by SSL/TLS.

Digital signatures are the interesting one. You can still use TLS for that, but you do have the additional burden of 
making sure customers get their certificate so that your server can authenticate them. I think most orgs go with 
encrypting the forms (usually fairly trivial) and leave out the digital signatures part.

<- snip ->

In my friend's organisation they intend to implement two solutions;
Electronic Signature and Encryption of forms which are to be received
from customers over their website.

My friend has to write a report for his boss on the two issues. Can
somebody direct me on what tools to consider and where can I get more
info regarding Pros&Cons on certain approaches.


Current thread: