3 ms·
What are the alternatives?
by eliasmacpherson 13y ago
What are the alternatives?
- wtbob 13y agoSPKI (http://en.wikipedia.org/wiki/Simple_public-key_infrastructure http://en.wikipedia.org/wiki/Simple_public-key_infrastructur...) is a great one. The guys behind it really thought hard about what a PKI should do, and what it can do, and what a relying party can actually rely on. Contrary to the Wikipedia page, there's a potential role for CAs. As an example, a CA could still sell a certificate authorising a key to, say, serve HTTPS data for the site foo.com; that key could then delegate authority for bar.foo.com, for www.foo.com and whatever else, without needing to go back cap-in-hand to the original CA. Among the cool things is that a CA trusted to vouch for people serving data in .com wouldn't necessarily be trusted to serve data for .co.uk. One might have CAs vouching for one's ownership of IP addresses. All of this was simple and straightforward, with a clean model (unlike the XPKI mess which conflates identity and authorisation), so of course it failed utterly.