[4065] in cryptography@c2.net mail archive
Re: lifetime of certs now in circulation
daemon@ATHENA.MIT.EDU (John R Levine)
Mon Jan 25 17:56:04 1999
Date: Mon, 25 Jan 1999 16:09:55 -0500 (EST)
From: John R Levine <johnl@iecc.com>
To: Dan Geer <geer@world.std.com>
Cc: cryptography@c2.net
In-Reply-To: <199901251953.AA09739@world.std.com>
> The ones that are in the 2020 foresight group,
> VeriSign, Microsoft, TC TrustCenter, and Thawte
> really ought to have their heads examined or I'm
> too dense to get the joke.
I suspect that the message here is that they're more worried about user
browers popping up "this certificate has expired" messages as happened to
Thawte customers with users running slightly old versions of Netscape, than
are worried about their certs being cracked.
Besides, aren't those certs about equally strong as the ones they certify?
If in 2018 someone can fake a cert signed by Microsoft, they can equally well
fake the signing cert.
Regards,
John Levine, johnl@iecc.com, Primary Perpetrator of "The Internet for Dummies",
Information Superhighwayman wanna-be, http://iecc.com/johnl, Sewer Commissioner
Finger for PGP key, f'print = 3A 5B D0 3F D9 A0 6A A4 2D AC 1E 9E A6 36 A3 47