[83273] in Cypherpunks
Re: Verisign gets export approval
daemon@ATHENA.MIT.EDU (Steve Schear)
Thu Jul 17 18:55:43 1997
In-Reply-To: <3.0.2.32.19970717100056.00733db4@netcom10.netcom.com>
Date: Thu, 17 Jul 1997 13:43:57 -0700
To: Lucky Green <shamrock@netcom.com>, Bill Frantz <frantz@netcom.com>,
Adam Shostack <adam@homeport.org>
From: Steve Schear <azur@netcom.com>
Cc: stewarts@ix.netcom.com, cypherpunks@toad.com
Reply-To: Steve Schear <azur@netcom.com>
At 10:00 AM -0700 7/17/97, Lucky Green wrote:
>At 09:16 AM 7/17/97 -0700, Bill Frantz wrote:
>>It seems to me that someone who has a one year export approved Verisign
>>cert should use it to authenticate a new top-level CA cert which they pass
>>to their customers. Cut Verisign and their nosy/noisy partner out of the
>>loop.
>
>Only a valid VeriSign Global ID cert (an X.509 v3 cert with a special
>extension) will activate the strong encryption in exportable browsers. This
>is hardcoded into Navigator and Internet Explorer.
That's what patch installers are for ;-)
--Steve