Author: Peter PearsonPeter Pearson Date: Jul 21, 2008 09:28
On Mon, 21 Jul 2008 07:54:57 -0700 (PDT), JHAF gmail.com> wrote:
[snip]
> Another vulnerability could arise if unsigned CSRs weakens non-
> repudiation. Let's suppose that Alice is requesting a certificate and
> does know that the CSR will go unsigned to the RA/CA. After the
> certificate is issued, she repudiates a purchase statement signed with
> the private key saying that "she didn“t have access to the private
> key" or "she didn't control it". Will an impartial observer (say, a
> judge) consider reasonable this declaration?
How will signing the CSR affect the plausibility of Alice's claim?
In particular, if Alice is claiming that some bad guy signed the
purchase statement, can't she also claim that some bad guy signed
the CSR?
--
To email me, substitute nowhere->spamcop, invalid->net.
|