CAcert.org

CAcert.org

CAcert.org is a community-driven certificate authority that issues free public key certificates to the public [ [https://www.cacert.org/index.php?id=12 About CAcert] ] (unlike other certificate authorities which are commercial and sell certificates). CAcert has over 110,000 verified users and has issued over 350,000 certificates as of|2008|July|alt=as of July 2008 [ [http://www.cacert.org/stats.php CAcert usage statistics] ] .

These certificates can be used to sign and encrypt email, authenticate and authorize users connecting to websites and secure data transmission over the Internet. Any application that supports the Secure Socket Layer (SSL) can make use of certificates signed by CAcert, as can any application that uses X.509 certificates, e.g. for encryption or code signing and document signatures.

Robot CA

CAcert automatically signs certificates for email addresses controlled by the requester and for domains for which certain addresses (such as "hostmaster@example.com") are controlled by the requester. Thus it operates as a robot certificate authority. These certificates are considered weak because CAcert does not emit any information in the certificates other than the domain name or email address (the "CommonName" field in X.509 certificates).

Web of trust

To create higher-trust certificates, users can participate in a web of trust system whereby users physically meet and verify each other's identities. CAcert maintains the number of assurance points for each account. Assurance points can be gained through various means, primarily by having one's identity physically verified by users classified as "Assurers" or by "Trusted Third Parties" such as public notaries.

Having more assurance points allows users more privileges such as writing a name in the certificate, longer expiration times on certificates. A user with at least 100 assurance points is designated an Assurer, and may verify other users; higher assurance points allows the assurer to assign more assurance points to others.

CAcert sponsors key signing parties, especially at big events such as CeBIT.

Inclusion status

As of|2005, certificates issued by CAcert are not as useful in web browsers as certificates issued by commercial CAs such as VeriSign, because most installed web browsers do not distribute CAcert's root certificate. Thus, for most web users, a certificate signed by CAcert behaves like a self-signed certificate. There was discussion for inclusion of CAcert's root certificate in Mozilla and derivatives (such as Mozilla Firefox) but it was closed without including it, at the end of April 2007. [ [https://bugzilla.mozilla.org/show_bug.cgi?id=215243 Discussion by Mozilla on including CAcert root certificate] ] This was after an audit was suspended in December 2006 because CAcert needed to improve their management system. There has been progress toward this and a new request for inclusion may be expected in the future. [ [https://bugzilla.mozilla.org/show_bug.cgi?id=215243#c158 CAcert audit comment on Mozilla] ] Getting the CAcert root cert included into Mozilla is probably CAcert's largest challenge right now, but one they are actively engaged in. [http://wiki.cacert.org/wiki/InclusionStatus CAcert inclusion status page] ] CAcert is engaged to give more transparency in its [http://wiki.cacert.org/wiki/Board management system] .

The following operating systems or distributions include the CAcert root certificate:
* ArkLinux
* CentOS
* Debian
* FreeWRT
* Gentoo
* Internet Tablet OS (installed on Nokia Internet Tablets)
* Knoppix
* Mandriva
* MirBSD
* OpenBSD

ee also

* Thawte - Also provides free personal certificates under a web of trust [https://www.thawte.com/en/secure-email/web-of-trust-wot/index.html Web of Trust - Thawte] ]

References

External links

* [http://www.cacert.org CAcert International]
* [http://wiki.cacert.org Unofficial FAQ]
* [http://wiki.cacert.org/wiki/FAQ/AssuranceDetails Assurance Details]
* IRC channel #cacert on irc.cacert.org ( [irc://irc.cacert.org/cacert] )
* Contact Form on [http://www.cacert.org/index.php?id=11&lang=en_AU www.cacert.org]
* [http://www.cacert.at CAcert Austria] (in German)
* [http://www.cacert.org.hu CAcert Hungary] (in Hungarian)
* [http://www.cacert-germany.de german CAcert-Support Forum] (in German)
* [https://www.gswot.org GSWoT] - CAcert assurers organized to provide and promote PGP key signing
* [http://wiki.cacert.org/wiki/Audit audit] , [http://wiki.cacert.org/wiki/AuditToDo todo for audits]


Wikimedia Foundation. 2010.

Игры ⚽ Поможем написать курсовую

Look at other dictionaries:

  • CAcert.org — Saltar a navegación, búsqueda CAcert.org es una Autoridad de certificación administrada por la comunidad que otorga gratuitamente certificados de clave pública.[1] (La mayor parte de las CAs son comerciales y venden certificados por cientos de… …   Wikipedia Español

  • CAcert — ist eine gemeinschaftsbetriebene, nicht kommerzielle Zertifizierungsstelle (Certification Authority, Root CA oder kurz CA), die kostenfrei X.509 Zertifikate für verschiedene Einsatzgebiete ausstellt. Damit soll eine Alternative zu den… …   Deutsch Wikipedia

  • HTTPS — (Hypertext Transfer Protocol Secure) Familie: Internetprotokollfamilie Einsatzgebiet: Verschlüsselte Datenübertragung Port: 443/TCP HTTPS im TCP/IP‑Protokollstapel: Anwendung HTTP …   Deutsch Wikipedia

  • Https — (Hypertext Transfer Protocol Secure) Familie: Internetprotokollfamilie Einsatzgebiet: Verschlüsselte Datenübertragung Port: 443/TCP HTTPS im TCP/IP‑Protokollstapel: Anwendung HTTP …   Deutsch Wikipedia

  • Net of trust — Schematische Darstellung eines Web of Trust Netz des Vertrauens bzw. Web of Trust (WOT) ist in der Kryptologie die Idee, die Echtheit von digitalen Schlüsseln durch ein Netz von gegenseitigen Bestätigungen (Signaturen) zu sichern. Es stellt eine… …   Deutsch Wikipedia

  • Netz des Vertrauens — Schematische Darstellung eines Web of Trust Netz des Vertrauens bzw. Web of Trust (WOT) ist in der Kryptologie die Idee, die Echtheit von digitalen Schlüsseln durch ein Netz von gegenseitigen Bestätigungen (Signaturen) zu sichern. Es stellt eine… …   Deutsch Wikipedia

  • Vertrauenskette — Schematische Darstellung eines Web of Trust Netz des Vertrauens bzw. Web of Trust (WOT) ist in der Kryptologie die Idee, die Echtheit von digitalen Schlüsseln durch ein Netz von gegenseitigen Bestätigungen (Signaturen) zu sichern. Es stellt eine… …   Deutsch Wikipedia

  • Vertrauensnetzwerk — Schematische Darstellung eines Web of Trust Netz des Vertrauens bzw. Web of Trust (WOT) ist in der Kryptologie die Idee, die Echtheit von digitalen Schlüsseln durch ein Netz von gegenseitigen Bestätigungen (Signaturen) zu sichern. Es stellt eine… …   Deutsch Wikipedia

  • Web of trust — Schematische Darstellung eines Web of Trust Netz des Vertrauens bzw. Web of Trust (WOT) ist in der Kryptologie die Idee, die Echtheit von digitalen Schlüsseln durch ein Netz von gegenseitigen Bestätigungen (Signaturen) zu sichern. Es stellt eine… …   Deutsch Wikipedia

  • Wot — Schematische Darstellung eines Web of Trust Netz des Vertrauens bzw. Web of Trust (WOT) ist in der Kryptologie die Idee, die Echtheit von digitalen Schlüsseln durch ein Netz von gegenseitigen Bestätigungen (Signaturen) zu sichern. Es stellt eine… …   Deutsch Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”