3 ms·
StartSSL [1] and COMODO [2] still offer them (of course, there's still the CA compromise issue you mentioned). Keep in mind, however, that a hierarchical, centr
by elgaton 10y ago
StartSSL [1] and COMODO [2] still offer them (of course, there's still the CA compromise issue you mentioned). Keep in mind, however, that a hierarchical, centralized trust model can still be useful (e.g. in medium-to-large organizations, where having an internal CA and delegating identity verification to a few knowledgeable employees is more practical than having everyone build a web of trust).
[1] https://www.startssl.com/ https://www.startssl.com/
[2] https://www.comodo.com/home/email-security/free-email-certificate.php https://www.comodo.com/home/email-security/free-email-certif...
- lmm 10y ago> Keep in mind, however, that a hierarchical, centralized trust model can still be useful (e.g. in medium-to-large organizations, where having an internal CA and delegating identity verification to a few knowledgeable employees is more practical than having everyone build a web of trust). Sure, but it's easy to build that kind of model on top of OpenPGP (just have an organizational signing key and tell everyone to trust that), whereas it's almost impossible to build a CA-independent model on top of SSL.