[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Legal entities who sign




lot of legal signature stuff touches on the non-repudiation subject ....
which has requirements pretty much orthogonal to anything that might be
stated in a certificate (this was discussed some time ago regarding what
does a "non-repudiation" flag actually mean ... aka you can place thousands
of bits and megabytes of prose in a certificate ... and it doesn't change
the situation).

past refs:
http://www.garlic.com/~lynn/aadsm10.htm#cfppki15 CFP: PKI research workshop
http://www.garlic.com/~lynn/aadsm10.htm#cfppki18 CFP: PKI research workshop
http://www.garlic.com/~lynn/aadsm10.htm#paiin PAIIN security glossary &
taxonomy
http://www.garlic.com/~lynn/aadsm11.htm#5 Meaning of Non-repudiation
http://www.garlic.com/~lynn/aadsm11.htm#6 Meaning of Non-repudiation
http://www.garlic.com/~lynn/aadsm11.htm#7 Meaning of Non-repudiation
http://www.garlic.com/~lynn/aadsm11.htm#8 Meaning of Non-repudiation
http://www.garlic.com/~lynn/aadsm11.htm#9 Meaning of Non-repudiation
http://www.garlic.com/~lynn/aadsm11.htm#11 Meaning of Non-repudiation
http://www.garlic.com/~lynn/aadsm11.htm#12 Meaning of Non-repudiation
http://www.garlic.com/~lynn/aadsm11.htm#13 Words, Books, and Key Usage
http://www.garlic.com/~lynn/aadsm11.htm#14 Meaning of Non-repudiation
http://www.garlic.com/~lynn/aadsm11.htm#15 Meaning of Non-repudiation
http://www.garlic.com/~lynn/aadsm12.htm#5 NEWS: 3D-Secure and Passport
http://www.garlic.com/~lynn/aadsm12.htm#12 TOC for world bank e-security
paper
http://www.garlic.com/~lynn/aadsm12.htm#30 Employee Certificates - Security
Issues
http://www.garlic.com/~lynn/aepay7.htm#nonrep0 non-repudiation, was Re:
crypto flaw in secure mail standards
http://www.garlic.com/~lynn/aepay7.htm#nonrep1 non-repudiation, was Re:
crypto flaw in secure mail standards
http://www.garlic.com/~lynn/aepay7.htm#nonrep2 non-repudiation, was Re:
crypto flaw in secure mail standards
http://www.garlic.com/~lynn/aepay7.htm#nonrep3 non-repudiation, was Re:
crypto flaw in secure mail standards
http://www.garlic.com/~lynn/aepay7.htm#nonrep4 non-repudiation, was Re:
crypto flaw in secure mail standards
http://www.garlic.com/~lynn/aepay7.htm#nonrep5 non-repudiation, was Re:
crypto flaw in secure mail standards
http://www.garlic.com/~lynn/aepay7.htm#nonrep6 non-repudiation, was Re:
crypto flaw in secure mail standards
http://www.garlic.com/~lynn/2001c.html#30 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#34 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#39 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#40 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#41 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#42 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#43 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#44 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#45 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#46 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#47 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#50 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#51 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#52 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#54 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#56 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#57 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#58 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#59 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#60 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#72 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001c.html#73 PKI and Non-repudiation
practicalities
http://www.garlic.com/~lynn/2001g.html#11 FREE X.509 Certificates
http://www.garlic.com/~lynn/2001g.html#38 distributed authentication
http://www.garlic.com/~lynn/2002f.html#35 Security and e-commerce
http://www.garlic.com/~lynn/2002g.html#37 Security Issues of using Internet
Banking
http://www.garlic.com/~lynn/2002g.html#69 Digital signature
http://www.garlic.com/~lynn/2002h.html#68 Are you really who you say you
are?
http://www.garlic.com/~lynn/2002i.html#67 Does Diffie-Hellman  schema
belong to Public Key schema family?
http://www.garlic.com/~lynn/2002i.html#77 Does Diffie-Hellman  schema
belong to Public Key schema family?
http://www.garlic.com/~lynn/2002j.html#40 Beginner question on Security
http://www.garlic.com/~lynn/2002l.html#24 Two questions on HMACs and
hashing
http://www.garlic.com/~lynn/2002m.html#38 Convenient and secure eCommerce
using POWF
http://www.garlic.com/~lynn/2002n.html#16 Help! Good protocol for national
ID card?
http://www.garlic.com/~lynn/2002n.html#19 Help! Good protocol for national
ID card?



                                                                                                                       
                     "Anders Rundgren"                                                                                 
                    <anders.rundgren@x     To:      <ietf-pkix@xxxxxxx>                                                
                             elia.com>     cc:                                                                         
                              Sent by:     Subject:      Legal entities who sign                                       
                    owner-ietf-pkix@xx                                                                                 
                            il.imc.org                                                                                 
                                                                                                                       
                                                                                                                       
                      10/31/2002 02:02                                                                                 
                                    AM                                                                                 
                                                                                                                       
                                                                                                                       





According to "e-lawyers", legal entities cannot sign as even
a delegated signer must be physical person.  This creates
huge practical problems and is also quite ridiculous, here
thinking of a CEO-certificate/key stored in a locked server-
room that not even the CEO may have a key to, and used by
business-systems, often completely out of the CEO's control.

Question: Would it be completely unthinkable that a
certificate policy stated that the owner of this certificate
(which only identifies a legal entity) has through its
management approved that the legal entity is to be held
legally responsible for all documents signed by this
certificate and associated key?'

This solution seems a bit related to Alexander the great
and the Gordian knot...

cheers,
Anders Rundgren