[83250] in Cypherpunks

home help back first fref pref prev next nref lref last post

Re: Verisign gets export approval

daemon@ATHENA.MIT.EDU (Lucky Green)
Thu Jul 17 13:56:47 1997

Date: Thu, 17 Jul 1997 10:00:56 -0700
To: Bill Frantz <frantz@netcom.com>, Adam Shostack <adam@homeport.org>
From: Lucky Green <shamrock@netcom.com>
Cc: stewarts@ix.netcom.com, cypherpunks@toad.com
In-Reply-To: <v0300781aaff3f52c25a1@[207.94.249.49]>
Reply-To: Lucky Green <shamrock@netcom.com>

At 09:16 AM 7/17/97 -0700, Bill Frantz wrote:
>It seems to me that someone who has a one year export approved Verisign
>cert should use it to authenticate a new top-level CA cert which they pass
>to their customers.  Cut Verisign and their nosy/noisy partner out of the
>loop.

Only a valid VeriSign Global ID cert (an X.509 v3 cert with a special
extension) will activate the strong encryption in exportable browsers. This
is hardcoded into Navigator and Internet Explorer.


--Lucky Green <shamrock@netcom.com>
  PGP encrypted mail preferred.
  DES is dead! Please join in breaking RC5-56.
  http://rc5.distributed.net/


home help back first fref pref prev next nref lref last post