Slashdot poses an interesting question and the ensuing discussion should get security folks’ minds churning.

So I’ll pose the question here as well and add how something like this should/could be implemented?

2 thoughts on “Is It Time for an Open Source Certificate Authority?”

  1. Peter says:

    I assume the desire for an open source certification authority is because people don’t want to pay the Verisign tax to receive an SSL certificate for $200-$500 a year.

    Other organizations offer SSL certificates for cheaper, for example GoDaddy offers them for about $20 a year. For many, this is a completely acceptable option, and the cost is significantly lower.

    The main issue is that the act of certification requires a good identification and authenticaiton (I&A) process. Having a good I&A requires time, and time generally requires money. The more trust you want to have in a certificate, the more it will cost to get that certificate.

    I don’t think there will ever be a viable open source certification authority in terms of getting around the cost of SSL and other certificates. There are plenty of open source CA software solutions out there, but the software is only a small piece of the puzzle.

  2. Laura says:

    cacert.org does a good job of trying the I&A process in a “web” manner. You earn more points for each time you find someone with the requisite number of points (an assurer) to verify your identity. They also offer a third party trust model where you have to submit to identity checking by your country’s equivalent of a notary system (justice of the peace, lawyer, accountant, etc).

Comments are closed.