6 ms·
That’s not how public key cryptography works. You don’t go and buy an SSL certificate from a CA. You pay for them to /sign/ your public key, presumably after v
by jacquesgt 13y ago
That’s not how public key cryptography works.
You don’t go and buy an SSL certificate from a CA. You pay for them to /sign/ your public key, presumably after verifying your identity. You generate the public/private key pair, and then you keep the private key private.
The CA could in theory sign Eve's private key along with metadata saying that private key belongs to you, but that just gives someone the ability to impersonate you. It doesn’t give Eve the ability to read emails that Bob sent to you with a key wrapped with your public key.
- jbraithwaite 13y agoAt least with Comodo's s/mime service, they provide you with the private key [1]. IIRC, Symantec/Verisign did the same thing. - [1] https://secure.comodo.com/products/frontpage?area=SecureEmailCertificate https://secure.comodo.com/products/frontpage?area=SecureEmai...
- nickf 13y agoNo, they don't. The keys are generated using in-browser controls (XEnroll/CertEnroll and HTML 'keygen' tag).
- m_eiman 13y agoI think the free personal certs are server-generated, the business ones are generated client-side.
- acabal 13y agoThat's the one I used, and if I recall correctly they sent me an email with a link for me to download the cert. This suggests to me that it was generated server-side and that therefore they could have kept a copy for themselves. But I might be totally wrong on how it works.