[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: AW: self-signed TSA [Was Re: Private Key Cloning]



Rish Salz wrote:

>> If I take your statements/conclusions below to their extreme, then anytime
>> PKIX comes up with a new service that uses digital signatures, that service
>> would have to issue its own self-signed certificates. I don't see the OCSP
>> folks requesting their own self-signed certificates.
> 
> Not HAVE TO issue, but COULD issue.  Most definitely.

So you want any user of a PKIX service to have to figure out a OOB mechanism
for each provider of the service to verify the self-signed certificate?

Regards,
Aram Perez