home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!seismo!darwin.sura.net!gatech!usenet.ins.cwru.edu!agate!ucbvax!silverton.berkeley.edu!djb
- From: djb@silverton.berkeley.edu (D. J. Bernstein)
- Newsgroups: sci.crypt
- Subject: Re: Is there a single person here who agrees with David Sternlight?
- Message-ID: <12102.Jan2520.47.2693@silverton.berkeley.edu>
- Date: 25 Jan 93 20:47:26 GMT
- References: <C0rw0x.Grt@dcs.ed.ac.uk> <palmer.726947259@news.larc.nasa.gov> <TYTSO.93Jan13212750@SOS.mit.edu>
- Organization: IR
- Lines: 10
- X-Mail-Warning: Do not reply by mail---silverton not configured yet.
-
- In article <TYTSO.93Jan13212750@SOS.mit.edu> tytso@athena.mit.edu (Theodore Y. Ts'o) writes:
- > The only problem about RIPEM is that it doesn't use certificates. As
- > far as I'm concerned, if it doesn't use certificates, it's not useful.
- > Relying on a certificate server is tantamount to "authentication by IP
- > address", which is only one step above "authentication by assertion".
-
- Relying on the structure defined in the PEM ``standard'' is tantamount
- to ``authentication by Bidzos assertion,'' which is one step below.
-
- ---Dan
-