[83250] in Cypherpunks
Re: Verisign gets export approval
daemon@ATHENA.MIT.EDU (Lucky Green)
Thu Jul 17 13:56:47 1997
Date: Thu, 17 Jul 1997 10:00:56 -0700
To: Bill Frantz <frantz@netcom.com>, Adam Shostack <adam@homeport.org>
From: Lucky Green <shamrock@netcom.com>
Cc: stewarts@ix.netcom.com, cypherpunks@toad.com
In-Reply-To: <v0300781aaff3f52c25a1@[207.94.249.49]>
Reply-To: Lucky Green <shamrock@netcom.com>
At 09:16 AM 7/17/97 -0700, Bill Frantz wrote:
>It seems to me that someone who has a one year export approved Verisign
>cert should use it to authenticate a new top-level CA cert which they pass
>to their customers. Cut Verisign and their nosy/noisy partner out of the
>loop.
Only a valid VeriSign Global ID cert (an X.509 v3 cert with a special
extension) will activate the strong encryption in exportable browsers. This
is hardcoded into Navigator and Internet Explorer.
--Lucky Green <shamrock@netcom.com>
PGP encrypted mail preferred.
DES is dead! Please join in breaking RC5-56.
http://rc5.distributed.net/