<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Proving membership online</title>
	<atom:link href="http://ursecta.com/wp/2005/06/proving-membership-online/feed/" rel="self" type="application/rss+xml" />
	<link>http://ursecta.com/wp/2005/06/proving-membership-online/</link>
	<description>J. Martin Wehlou on Security, Software Development, and Medicine</description>
	<pubDate>Tue, 06 Jan 2009 22:21:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Martin Wehlou</title>
		<link>http://ursecta.com/wp/2005/06/proving-membership-online/#comment-8</link>
		<dc:creator>Martin Wehlou</dc:creator>
		<pubDate>Tue, 28 Jun 2005 19:44:47 +0000</pubDate>
		<guid isPermaLink="false">http://ursecta.com/wp/?p=6#comment-8</guid>
		<description>Thanks, Javed. Well, the task of the CA is to be a trusted third party to both negotiating partners in a transaction of some kind. In this case, the transaction is between the user and OtherSites, with Site Zero as common trusted third party. So it would be entirely natural to have Site Zero as ultimate CA for this particular scenario. One more CA "above" Site Zero won't contribute anything to the security. But, I admit, it may often be a political necessity.
</description>
		<content:encoded><![CDATA[<p>Thanks, Javed. Well, the task of the CA is to be a trusted third party to both negotiating partners in a transaction of some kind. In this case, the transaction is between the user and OtherSites, with Site Zero as common trusted third party. So it would be entirely natural to have Site Zero as ultimate CA for this particular scenario. One more CA &#8220;above&#8221; Site Zero won&#8217;t contribute anything to the security. But, I admit, it may often be a political necessity.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Javed Ikbal</title>
		<link>http://ursecta.com/wp/2005/06/proving-membership-online/#comment-7</link>
		<dc:creator>Javed Ikbal</dc:creator>
		<pubDate>Tue, 28 Jun 2005 18:28:35 +0000</pubDate>
		<guid isPermaLink="false">http://ursecta.com/wp/?p=6#comment-7</guid>
		<description>Nice writeup. I believe this is also the federated identity problem... I personally think the CN field in a digital certificte could be an easy method to solve this problem. I get a cert (self-generated?) and have site zero sign it. Then I can present that digital ID to anyone who is interested. There are holes in this scenario, but none too big.

Also see http://www.cacert.org/ 

I am trying to fit cacert into the model above.</description>
		<content:encoded><![CDATA[<p>Nice writeup. I believe this is also the federated identity problem&#8230; I personally think the CN field in a digital certificte could be an easy method to solve this problem. I get a cert (self-generated?) and have site zero sign it. Then I can present that digital ID to anyone who is interested. There are holes in this scenario, but none too big.</p>
<p>Also see <a href="http://www.cacert.org/" rel="nofollow">http://www.cacert.org/</a> </p>
<p>I am trying to fit cacert into the model above.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
