Educause Security Discussion mailing list archives

Re: Discontinuance of Thawte personal email certificates and Web of Trust


From: Charles Hedrick <hedrick () RUTGERS EDU>
Date: Wed, 30 Sep 2009 18:11:48 -0400

Thawte certs were used for email primarily, not web servers. For a web
server I really want a root that's in the browsers, because I don't
want our users ignoring warnings. However for email I think it's
reasonable to require people who want assurance to load a root CA. I'm
going to propose that Rutgers extend our existing internal cert system
to issue certs for email. I'd love to see EDUCAUSE or possibly
INCOMMON come up with a common root that we could use. But maybe
CACERT will do.

On Sep 30, 2009, at 3:49:00 PM, Valdis Kletnieks wrote:

On Wed, 30 Sep 2009 11:15:40 EDT, jeff murphy said:

I'm pretty sure CAcert doesn't have it's root in any of the browsers,
which is why I didn't bring it up.

Wouldn't an EDUCAUSE-sponsored project have the exact same issue,
though?
That's why I suggested CACert, as that gets bigger bang-for-buck if
EDUCAUSE
lobbies to get that root cert distributed, because non-EDUCAUSE
groups can
benefit as well then.


Attachment: smime.p7s
Description:


Current thread: