Re: Personal certs

Adrian Midgley <[email protected]> Tue, 26 Jan 2016 14:30:18 +0000
Newsgroups gmane.law.cryptography.uk
Message-ID <CAN2jWyggvp_YGhtmD11KfqPM7dAxAwtSXXq3rG=vLBzq-0kCgg@mail.gmail.com>
--001a114106d2e82a3f052a3d8658
Content-Type: text/plain; charset=UTF-8

Why did Thawte Web of Trust (a phrase I associate with Phil Zimmerman) die?

Did anything supplant it?

One of the things it occurred to me the GMC and Royal Colleges (eg of
surgeons) could do would be to assist their registrants or members to do
the difficult bit of the PGP WoTrust - knowing the person is the person.

Too new perhaps.

On Mon, 25 Jan 2016, 16:20 Melanie Dymond Harper <[email protected]> wrote:

> On Mon, Jan 25, 2016 at 09:45:02AM +0000,
> ukcrypto-request-QGMSyCZBOSwv4zxTlrOuLwNdhmdF6hFW@public.gmane.org wrote:
> >
> > > In article <D8889865-1033-46F4-82B6-50EDF78D7AFE-3A7p0BNfWfcdnm+yROfE0A@public.gmane.org>, Roger
> Hayter <[email protected]> writes
> > >
> > >> AMI, how are the keys for end-to-end users supplied?
> > >
> > > Is this relevant (I don't know for sure, but as someone formerly
> practising in Wales maybe you have some inside track):
> > >
> > > http://www.wales.nhs.uk/pearsrc/digitial_certificate_setup.pdf
> > > --
> > > Roland Perry
> >
> > I was never important enough to be advised to do such a thing. It does
> seem remarkably simple, but raises more questions.  Does it use the same
> SSL libraries as used for encrypted web sites?  If Thawte issue a
> certificate which you then use, does this potentially give them a way into
> your encrypted information or not?  And is this the same system the English
> NHS use for end-to-end encryption?  It would seem to render NHSnet
> irrelevant, unless its sole role is to prevent you sending encrypted email
> or secret documents outside NHSnet.
>
> That's very, _very_ out of date. Thawte haven't done personal
> certificates for a very long time, and the Thawte Web of Trust has been
> dead since November 2009.
>
> The certificate keys were generated within the browser in a similar way
> to the way in which most code-signing certificates are handled these
> days -- the CA doesn't typically see the private keys at all. I don't
> offhand remember the precise libraries in use, I'm afraid.
>
> Cheers
>
> Mel (formerly Thawte rep in the UK & Web of Trust notary)
>
>
>
>
>

--001a114106d2e82a3f052a3d8658
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<p dir=3D"ltr">Why did Thawte Web of Trust (a phrase I associate with Phil =
Zimmerman) die?</p>
<p dir=3D"ltr">Did anything supplant it?<br></p>
<p dir=3D"ltr">One of the things it occurred to me the GMC and Royal Colleg=
es (eg of surgeons) could do would be to assist their registrants or member=
s to do the difficult bit of the PGP WoTrust - knowing the person is the pe=
rson.</p>
<p dir=3D"ltr">Too new perhaps.</p>
<br><div class=3D"gmail_quote"><div dir=3D"ltr">On Mon, 25 Jan 2016, 16:20=
=C2=A0Melanie Dymond Harper &lt;<a href=3D"mailto:[email protected]">mel@her=
ald.co.uk</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=
=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On Mon, =
Jan 25, 2016 at 09:45:02AM +0000, <a href=3D"mailto:ukcrypto-request@chiark=
.greenend.org.uk" target=3D"_blank">ukcrypto-request-QGMSyCZBOSwv4zxTlrOuLwNdhmdF6hFW@public.gmane.org=
</a> wrote:<br>
&gt;<br>
&gt; &gt; In article &lt;<a href=3D"mailto:D8889865-1033-46F4-82B6-50EDF78D=
[email protected]" target=3D"_blank">D8889865-1033-46F4-82B6-50EDF78D7AFE@hay=
ter.org</a>&gt;, Roger Hayter &lt;<a href=3D"mailto:[email protected]" targe=
t=3D"_blank">[email protected]</a>&gt; writes<br>
&gt; &gt;<br>
&gt; &gt;&gt; AMI, how are the keys for end-to-end users supplied?<br>
&gt; &gt;<br>
&gt; &gt; Is this relevant (I don&#39;t know for sure, but as someone forme=
rly practising in Wales maybe you have some inside track):<br>
&gt; &gt;<br>
&gt; &gt; <a href=3D"http://www.wales.nhs.uk/pearsrc/digitial_certificate_s=
etup.pdf" rel=3D"noreferrer" target=3D"_blank">http://www.wales.nhs.uk/pear=
src/digitial_certificate_setup.pdf</a><br>
&gt; &gt; --<br>
&gt; &gt; Roland Perry<br>
&gt;<br>
&gt; I was never important enough to be advised to do such a thing. It does=
 seem remarkably simple, but raises more questions.=C2=A0 Does it use the s=
ame SSL libraries as used for encrypted web sites?=C2=A0 If Thawte issue a =
certificate which you then use, does this potentially give them a way into =
your encrypted information or not?=C2=A0 And is this the same system the En=
glish NHS use for end-to-end encryption?=C2=A0 It would seem to render NHSn=
et irrelevant, unless its sole role is to prevent you sending encrypted ema=
il or secret documents outside NHSnet.<br>
<br>
That&#39;s very, _very_ out of date. Thawte haven&#39;t done personal<br>
certificates for a very long time, and the Thawte Web of Trust has been<br>
dead since November 2009.<br>
<br>
The certificate keys were generated within the browser in a similar way<br>
to the way in which most code-signing certificates are handled these<br>
days -- the CA doesn&#39;t typically see the private keys at all. I don&#39=
;t<br>
offhand remember the precise libraries in use, I&#39;m afraid.<br>
<br>
Cheers<br>
<br>
Mel (formerly Thawte rep in the UK &amp; Web of Trust notary)<br>
<br>
<br>
<br>
<br>
</blockquote></div>

--001a114106d2e82a3f052a3d8658--