ISSUE-103

How should unknown CAs and self-signed certificates be treated?

State:
CLOSED
Product:
wsc-xit
Raised by:
Thomas Roessler
Opened on:
2007-08-12
Description:
Self-signed certificates are mostly treated as pure containers.

Certificates from unknown CAs can be treated as pure containers, or some of the information in such certificates can be used to cause distrust.

E.g., one could:

- Perform path validation and cause errors as one would for a known and
trusted CA, but don't display identity indicator? (This would effectively
make the "weak" and "strong" TLS notions orthogonal to whether we trust a CA.)

- Ignore path validation and treat as pure containers for cryptographic material?
Related Actions Items:
Related emails:
  1. ACTION-317: Different notions of KCM in different parts of the document (from tlr@w3.org on 2008-01-17)
  2. ACTION-348: cert related terminology (from stephen.farrell@cs.tcd.ie on 2007-12-05)
  3. Meeting record: WSC WG f2f 2007-11-06 (from tlr@w3.org on 2007-11-21)
  4. Draft minutes: WSC WG 2007-11-06 (from tlr@w3.org on 2007-11-17)
  5. Meeting record: WSC WG f2f 2007-10-03 (from tlr@w3.org on 2007-10-25)
  6. Draft Minutes: WSC WG face-to-face 2007-10-03 (from tlr@w3.org on 2007-10-10)
  7. Re: Draft Minutes: WSC WG face-to-face 2007-10-03 (from ifette@google.com on 2007-10-09)
  8. Re: ISSUE-103: Should unknown CAs and self-signed certificates be treated the same way? [Techniques] (from tlr@w3.org on 2007-08-29)
  9. Proposal: error handling / minimizing trust decisions (from tlr@w3.org on 2007-08-12)
  10. ISSUE-103: Should unknown CAs and self-signed certificates be treated the same way? [Techniques] (from sysbot+tracker@w3.org on 2007-08-12)

Related notes:

No additional notes.

Display change log ATOM feed


Mary Ellen Zurko <mzurko@us.ibm.com>, Chair, Thomas Roessler <tlr@w3.org>, Staff Contact
Tracker (configuration for this group), originally developed by Dean Jackson, is developed and maintained by the Systems Team <w3t-sys@w3.org>.
$Id: 103.html,v 1.1 2010/10/11 09:35:03 dom Exp $