Mutual auth concept - Works?

2008-12-14 Thread Anders Rundgren
Mutual authentication in web-browsers in most cases depend on that the user recognizes the site visually or even examines their SSL cert. As we know this process suffers from serious limitations. It seems that for client-cert-authentication it should be possible to include a list of trusted host

Re: SECOM Trust EV root inclusion request

2008-12-14 Thread Ian G
On 13/12/08 18:25, Frank Hecker wrote: Ian G wrote: A possible solution is an open end-user offer. I have before mentioned that each CA should have a relying party agreement or similar; something on offer to the mozo end-user. It should be the minimum, or default, or entry-level document for th