<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.12-alpha" --><?xml-stylesheet type="text/xsl" href="http://my.rsscache.com/rsc/rss2.xsl"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rsscache="http://ns.rsscache.com/1.0"><channel><title>CAcert NEWS Blog</title><link>http://blog.CAcert.org</link><description>CAcert NEWS and up coming events.</description><pubDate>Fri, 05 Sep 2008 15:31:09 +0000</pubDate><generator>http://wordpress.org/?v=2.0.12-alpha</generator><language>en</language><item><title>AR.20080902.A1 CPS issues: 2 bugs</title><link>http://blog.CAcert.org/2008/09/328.html</link><comments>http://blog.CAcert.org/2008/09/328.html#comments</comments><pubDate>Fri, 05 Sep 2008 15:31:09 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">iang</dc:creator><category>Information</category><guid isPermaLink="false">http://blog.CAcert.org/2008/09/328.html</guid><description>One side issue relating to the earlier post: in order to release funds for the critical systems work, we will need to sort out the CPS quickly.  There are two blocking questions that need to be fixed, so I&amp;#8217;ll list them here for all to think about:
CPS Bug #1: Assurance is now on a good [...]&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=51363375 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</description><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/">&lt;p&gt;One side issue relating to the &lt;a title="Audit Report, July-August 2008" href="http://blog.cacert.org/2008/09/327.html"&gt;earlier post&lt;/a&gt;: in order to release funds for the critical systems work, we will need to sort out the &lt;a title="Certification Practice Statement" href="http://svn.cacert.org/CAcert/policy.htm"&gt;CPS&lt;/a&gt; quickly.  There are two blocking questions that need to be fixed, so I&amp;#8217;ll list them here for all to think about:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CPS Bug #1:&lt;/strong&gt; Assurance is now on a good footing with the &lt;a title="now in DRAFT, which means it is binding on you the Assurer!" href="http://svn.cacert.org/CAcert/Policies/AssurancePolicy.html"&gt;DRAFT Assurance Policy&lt;/a&gt;, and we can state with some confidence that CAcert does a good job at identifying people within the community.&lt;/p&gt;
&lt;p&gt;But, there is a bug:  the certificates with names do not always use Assured Names.  Specifically, in the Organisations, there is no compelling reason to use Assurance information or anything else to name people.  So, Members are faced with a &amp;#8220;name&amp;#8221; that is either strongly Assured, or worthless, or somewhere arbitrarily in-between.&lt;/p&gt;
&lt;p&gt;How are you to tell the difference?  Perhaps by further looking in the certificate, but forcing people to investigate every certificate to figure out detailed issues makes a mockery of the process, and of the Assurers.&lt;/p&gt;
&lt;p&gt;Let&amp;#8217;s put it to you:  Should the Name in the certificate (specifically, the CommonName or CN field as shown by software) be&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;always Assured?&lt;/li&gt;
&lt;li&gt;always strong through some other mechanism, either Assurance or elsewise?&lt;/li&gt;
&lt;li&gt;sometimes be Assured, sometimes unknown, like now?&lt;/li&gt;
&lt;li&gt;be entirely variable at the discretion of the person?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;All of these choices have merits.  For example, the last one looks odd, but is maybe OK, if we recall that all certificates will identify the Member through the serial number.&lt;/p&gt;
&lt;p&gt;What do you think?  Over on the &lt;a title="Your Policy Group Needs You!" href="https://lists.cacert.org/cgi-bin/mailman/listinfo/cacert-policy"&gt;policy group&lt;/a&gt;, a choice will have to be made somehow, so dive on over there and help.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CPS Bug #2:&lt;/strong&gt;  The domains and email addresses placed in certificates are only ping-tested once, when added.  Over time, various changes and problems can occur, such as transfer, expiry, loss, etc, so this is not good.  Something has to be improved.  The question is, what?  There are these possibilities that I have seen so far:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;frequent or regular ping checks on email addresses,&lt;/li&gt;
&lt;li&gt;automatic revocations on domain expiry or transfer,&lt;/li&gt;
&lt;li&gt;a change made to a website through HTML text or headers, etc, to show control,&lt;/li&gt;
&lt;li&gt;a change made to DNS records to show control,&lt;/li&gt;
&lt;li&gt;a change made to Registry records to show ownership or delegation of control,&lt;/li&gt;
&lt;li&gt;a statement of ownership or control made to CAcert in the online system,&lt;/li&gt;
&lt;li&gt;or?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Probably, we need some combination of 2 or more of the above, because some of them will be hard for people to do.  As before, check in on the policy group to express your opinion.
&lt;/p&gt;
&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=51363375 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</content:encoded><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blog.CAcert.org/2008/09/328.html/feed/</wfw:commentRss></item><item><title>Audit Report 20090902</title><link>http://blog.CAcert.org/2008/09/327.html</link><comments>http://blog.CAcert.org/2008/09/327.html#comments</comments><pubDate>Thu, 04 Sep 2008 15:41:49 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">iang</dc:creator><category>News</category><category>Information</category><guid isPermaLink="false">http://blog.CAcert.org/2008/09/327.html</guid><description>The latest of the audit reports, for July-August, is now on the wiki.  As this report and CAcert&amp;#8217;s current situation are almost totally dominated by critical systems issues I shall only list those here.  First, the big direct issues:

The new plan for critical systems is now in place and approved by Board of CAcert.
The Vienna [...]&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=51292552 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</description><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/">&lt;p&gt;The latest of the &lt;a title="all Audit Presentations" href="http://wiki.cacert.org/wiki/AuditPresentations"&gt;audit reports&lt;/a&gt;, for &lt;a title="Audit Report, July-August 2008" href="http://wiki.cacert.org/wiki/Audit/CommunityReport20080902"&gt;July-August&lt;/a&gt;, is now on the wiki.  As this report and CAcert&amp;#8217;s current situation are almost totally dominated by critical systems issues I shall only list those here.  First, the big direct issues:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The new plan for critical systems is now in place and approved by Board of CAcert.&lt;/li&gt;
&lt;li&gt;The Vienna systems will be shutdown on 30th September.  This is a slightly variable date, it could change, but not substantially.  The intention is that they will not be restated, see below.&lt;/li&gt;
&lt;li&gt;The data will be incorporated into the Netherlands machines over the days following that date.&lt;/li&gt;
&lt;li&gt;So, &lt;strong&gt;service to CAcert will be interrupted from 30th September.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Until the job is done.  There are estimates as to how many days this will take, but I won&amp;#8217;t repeat them here.  It will take as long as it takes.&lt;/li&gt;
&lt;li&gt;Which means, if the migration does not succeed, then CAcert may be left without an operating CA.&lt;/li&gt;
&lt;li&gt;I&amp;#8217;ll be there.  If you are in the Netherlands in the first week of October, and would like to help, let us know.  We might need it!&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The above plan is the Number One Thing on everyone&amp;#8217;s desktop.  Other issues that bear mentioning are these, because they effect the plan:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The Vienna systems are &lt;strong&gt;Audit Fail&lt;/strong&gt;.  They were always a temporary arrangement, almost emergency status, and represent no base for the future nor a base for a responsible, professional CA.  Somewhere, the line has to be drawn, and the board has agreed it is time to draw that line.  30th September.  Hence, above, there is no intention to fall-back to the Vienna systems.&lt;/li&gt;
&lt;li&gt;The old Roots are &lt;strong&gt;Audit Fail&lt;/strong&gt;.  This is because there is no clear history, no documentation, and sanity checks don&amp;#8217;t change that view.  So, a task for the Dutch team is to create new roots, but only when they&amp;#8217;ve got everything else sorted out, and only after the process is properly documented.  (As an aside, the roots situation was reported and agreed with the board &lt;a title="Systems issues" href="http://wiki.cacert.org/wiki/TopMinutes-20070917"&gt;September 2007&lt;/a&gt;.)&lt;/li&gt;
&lt;li&gt;There was &lt;a title="Kriss Andsten's blog" href="http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html"&gt;a security bug reported last month&lt;/a&gt; by a member.  The handling of that bug was good, as it was more or less dealt with, within around 12 hours, and &lt;a title="Vulnerability Note, 14th of August 2008" href="http://blog.cacert.org/2008/08/321.html"&gt;notified to the community&lt;/a&gt;.  That&amp;#8217;s the good news.&lt;/li&gt;
&lt;li&gt;The bad news is that the bug was rather bad, and likely indicative of others of the same class.  (If you are into PHP, just think &lt;em&gt;register_globals&lt;/em&gt; &amp;#8230;) The software development team has a lot of work to do.&lt;/li&gt;
&lt;li&gt;Clearly, software development also suffers from the same lack of people as with the systems administration team.  After the critical systems is put onto a sound footing, management will have to look at the development side as well.  Meanwhile, you can help if you have PHP skills.  Ask to get access to the test system, and ask for a small task to look at.  There are many!&lt;/li&gt;
&lt;li&gt;Meanwhile, there is little benefit in shooting the messenger.  It&amp;#8217;s impolite and a waste of a good bullet.  Security is a process: it is about fixing and improving.  It decidedly isn&amp;#8217;t about pretending there are no bugs, nor that our code is perfect or even high quality.  Our thanks to Kriss for debunking that myth.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Some have said that this report looks overly dark.  If anything, it is too polite, not dark enough:  CAcert has had 2 years to prepare the critical systems, and has not.  It has had over a year in the current situation, and not done the migration.  The issues are very clear, and have been repeated maybe a hundred times, so I won&amp;#8217;t list them again.&lt;/p&gt;
&lt;p&gt;The time has come for CAcert to decide whether you want an audit or not.&lt;/p&gt;
&lt;p&gt;That&amp;#8217;s it from audit.  Next report will be (not before) November.  Either it will be lighter, or darker.  Over to you!
&lt;/p&gt;
&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=51292552 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</content:encoded><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blog.CAcert.org/2008/09/327.html/feed/</wfw:commentRss></item><item><title>CAcert event at Drupalcon Szeged 2008</title><link>http://blog.CAcert.org/2008/08/326.html</link><comments>http://blog.CAcert.org/2008/08/326.html#comments</comments><pubDate>Mon, 25 Aug 2008 17:51:40 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">sanduhrs</dc:creator><category>Events</category><category>News</category><category>Information</category><guid isPermaLink="false">http://blog.CAcert.org/2008/08/326.html</guid><description>
Drupalcon is the twice-yearly gathering of Drupalers to learn about, discuss and advance Drupal, and to network with other community members. Experience this thriving community in person yourself in Szeged, Hungary!
See the Drupalcon website for more information.
At Drupalcon we&amp;#8217;ll have a CAcert event organized by the people from erdfisch. If you need some assuring you&amp;#8217;ll [...]&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50620161 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</description><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/">&lt;p&gt;&lt;img align="left" alt="Logo Drupalcon.org" src="http://szeged2008.drupalcon.org/sites/all/themes/szeged2008/logo.png" /&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;a href="http://szeged2008.drupalcon.org/"&gt;Drupalcon&lt;/a&gt; is the twice-yearly gathering of Drupalers to learn about, discuss and advance &lt;a href="http://drupal.org"&gt;Drupal&lt;/a&gt;, and to network with other community members. Experience this thriving community in person yourself in Szeged, Hungary!&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;See &lt;a href="http://szeged2008.drupalcon.org/"&gt;the Drupalcon website&lt;/a&gt; for more information.&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;At Drupalcon we&amp;#8217;ll have a &lt;a href="http://cacert.org"&gt;CAcert&lt;/a&gt; event organized by the people from &lt;a href="http://erdfisch.de"&gt;erdfisch&lt;/a&gt;. If you need some assuring you&amp;#8217;ll find them every day of the conference from 12:45 to 13:15 on the ground floor in the sitting corner near the registration desk.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;See the full announcement &lt;a href="http://szeged2008.drupalcon.org/blog/cacert-event-drupalcon"&gt;CAcert event at Drupalcon&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50620161 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</content:encoded><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blog.CAcert.org/2008/08/326.html/feed/</wfw:commentRss></item><item><title>Wuppertal 24 Live mit CAcert Assurances</title><link>http://blog.CAcert.org/2008/08/325.html</link><comments>http://blog.CAcert.org/2008/08/325.html#comments</comments><pubDate>Sun, 24 Aug 2008 19:10:00 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">dastrath</dc:creator><category>Events</category><guid isPermaLink="false">http://blog.CAcert.org/2008/08/325.html</guid><description>Im Rahmen von Wuppertal 24 Live (14.09.07 bis 15.09.07, 18:00 - 02:00 Uhr) veranstaltet die Wuppertaler Linux User Group einen (nicht nur Einsteiger-) Themenabend mit Linux-Installationsmöglichkeiten.
Selbstverständlich wird es sowohl die Möglichkeit geben, sich über CAcert zu informieren, als auch CAcert-Assurances durchzuführen.

&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50565424 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</description><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/">&lt;p&gt;Im Rahmen von &lt;a title="Wuppertal 24 Live" href="http://www.w24live.de"&gt;Wuppertal 24 Live&lt;/a&gt; (14.09.07 bis 15.09.07, 18:00 - 02:00 Uhr) veranstaltet die &lt;a title="Wuppertaler Linux User Group" href="http://www.wuplug.org/"&gt;Wuppertaler Linux User Group&lt;/a&gt; einen (nicht nur Einsteiger-) Themenabend mit Linux-Installationsmöglichkeiten.&lt;/p&gt;
&lt;p&gt;Selbstverständlich wird es sowohl die Möglichkeit geben, sich über CAcert zu informieren, als auch CAcert-Assurances durchzuführen.
&lt;/p&gt;
&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50565424 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</content:encoded><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blog.CAcert.org/2008/08/325.html/feed/</wfw:commentRss></item><item><title>CAcert auf den mrmcd111b</title><link>http://blog.CAcert.org/2008/08/323.html</link><comments>http://blog.CAcert.org/2008/08/323.html#comments</comments><pubDate>Thu, 21 Aug 2008 17:02:32 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">jtb</dc:creator><category>Events</category><guid isPermaLink="false">http://blog.CAcert.org/2008/08/323.html</guid><description>Auf den meta rhein main chaos days 111b: &amp;#8220;connecting the dots&amp;#8221;   vom 05. September bis 07. September 2008 wird es wieder einen Vortrag mit abschließendem GPG-Keysigning und CAcert-Assurance geben.
Mehr Infos im Fahrplan: Key Signing und CAcert

&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50393905 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</description><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/">&lt;p&gt;Auf den &lt;a href="http://mrmcd.metarheinmain.de/"&gt;meta rhein main chaos days 111b: &amp;#8220;connecting the dots&amp;#8221;&lt;/a&gt;   vom 05. September bis 07. September 2008 wird es wieder einen Vortrag mit abschließendem GPG-Keysigning und CAcert-Assurance geben.&lt;/p&gt;
&lt;p&gt;Mehr Infos im Fahrplan: &lt;a href="https://mrmcd.net/schedule/mrmcd111b/event/2731.en.html"&gt;Key Signing und CAcert&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50393905 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</content:encoded><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blog.CAcert.org/2008/08/323.html/feed/</wfw:commentRss></item><item><title>CAcert auf der FrOSCon 2008</title><link>http://blog.CAcert.org/2008/08/322.html</link><comments>http://blog.CAcert.org/2008/08/322.html#comments</comments><pubDate>Mon, 18 Aug 2008 15:04:48 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">wonderer</dc:creator><category>Information</category><guid isPermaLink="false">http://blog.CAcert.org/2008/08/322.html</guid><description>
Auch dieses Jahr ist CAcert mit einem Informationsstand auf der FrOSCon vertreten (Sankt Augustin 23.- 24.08.2008). Interressierte, Assurer und welche, die es werden möchten sind herzlichst dazu eingeladen den Stand zu besuchen und sich ggf. vorher unter http://wiki.cacert.org/wiki/FrOSCon2008 einzutragen um den Platz entsprechend bereit zu halten.
Die FrOSCon bietet auch dieses Jahr wieder eine große Auswahl [...]&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50234802 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</description><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/">&lt;p&gt;&lt;img src="http://www.froscon.de/uploads/pics/froscon-logo-web_01.gif" /&gt;&lt;br /&gt;
Auch dieses Jahr ist CAcert mit einem Informationsstand auf der FrOSCon vertreten (Sankt Augustin 23.- 24.08.2008). Interressierte, Assurer und welche, die es werden möchten sind herzlichst dazu eingeladen den Stand zu besuchen und sich ggf. vorher unter &lt;strong&gt;&lt;a target="_blank" href="http://wiki.cacert.org/wiki/FrOSCon2008"&gt;http://wiki.cacert.org/wiki/FrOSCon2008&lt;/a&gt;&lt;/strong&gt; einzutragen um den Platz entsprechend bereit zu halten.&lt;br /&gt;
Die FrOSCon bietet auch dieses Jahr wieder eine große Auswahl an Themen aus dem Bereich Freier Software und Open Source. Das Programm ist online unter &lt;a target="_blank" href="http://programm.froscon.de"&gt;http://programm.froscon.de&lt;/a&gt; abrufbar.
&lt;/p&gt;
&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50234802 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</content:encoded><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blog.CAcert.org/2008/08/322.html/feed/</wfw:commentRss></item><item><title>[Ad] Oprah's Superfood of the Year!</title><link>http://www.rsscache.com/Section/Advertise/click.aspx?a=18886926</link><description>Detoxify and Lose Weight with AcaiPure - Click Here for Free Trial</description></item><item><title>Vulnerability Note, 14th of August 2008</title><link>http://blog.CAcert.org/2008/08/321.html</link><comments>http://blog.CAcert.org/2008/08/321.html#comments</comments><pubDate>Thu, 14 Aug 2008 13:20:40 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">teus</dc:creator><category>Information</category><guid isPermaLink="false">http://blog.CAcert.org/2008/08/321.html</guid><description>CAcert certificate issuance with unverified arbitratry email addresses
Overview
The CAcert issuance of certificates had a vulnerability that permitted an attacker to add arbitrary email addresses without verification.

I Description
Issuance of certificates is by means of login to a webpage by Members.  After authenticating the Member, she is offered a choice of certificates, with a choice of [...]&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50067065 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</description><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/">&lt;p&gt;&lt;em&gt;CAcert certificate issuance with unverified arbitratry email addresses&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Overview&lt;/strong&gt;&lt;br /&gt;
The CAcert issuance of certificates had a vulnerability that permitted an attacker to add arbitrary email addresses without verification.&lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;
I Description&lt;/strong&gt;&lt;br /&gt;
Issuance of certificates is by means of login to a webpage by Members.  After authenticating the Member, she is offered a choice of certificates, with a choice of pre-verified email addresses.&lt;br /&gt;
In the POST response to that choice, there is insufficient checking on the paramaters supplied, and it is possible to add multiple additional email addresses that are not pre-verified.&lt;/p&gt;
&lt;p&gt;The specific failure is use of register_globals and insufficient paramater testing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;II. Impact&lt;/strong&gt;&lt;br /&gt;
A Member may add email addresses from a limited range of TLDs (Japan only has been verified).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;III. Solution&lt;/strong&gt;&lt;br /&gt;
The paramater checking has been fixed.  Register_globals is now turned off in the test system to explore side effects. Operational software will follow&lt;br /&gt;
soon.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Systems Affected&lt;/strong&gt;&lt;br /&gt;
Only Japan TLD addresses may have been affected. There is no indication that any prior issued certificates with Japan TLD email addresses are other than valid.&lt;/p&gt;
&lt;p&gt;This is a Member-reliance issue only.  Any disputes will be filed in CAcert&amp;#8217;s internal Arbitration forum.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;Vendor  Status  Date Updated&lt;/em&gt;&lt;/strong&gt;&lt;br /&gt;
CAcert  Fixed   14th of August 2008&lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;
References&lt;/strong&gt;&lt;br /&gt;
&lt;a href="http://bugs.cacert.org/view.php?id=595"&gt;bug report&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html"&gt;Kriss his blog&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Credit&lt;/strong&gt;&lt;br /&gt;
CAcert credits Kriss Andsten for reporting this issue.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;CAcert, Teus Hagen&lt;br /&gt;
&lt;/em&gt;
&lt;/p&gt;
&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50067065 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</content:encoded><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blog.CAcert.org/2008/08/321.html/feed/</wfw:commentRss></item><item><title>Assuring Party @ DebConf8, Argentina.</title><link>http://blog.CAcert.org/2008/08/320.html</link><comments>http://blog.CAcert.org/2008/08/320.html#comments</comments><pubDate>Wed, 13 Aug 2008 12:21:08 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dererk</dc:creator><category>Information</category><guid isPermaLink="false">http://blog.CAcert.org/2008/08/320.html</guid><description>A new CAcert Assuring Party will take place at DebConf8 in Mar del Plata,  Argentina, right next to the Keysigning Party[1], during this Thursday.
To obtain assurance at the event, login to the CAcert site and click the "CAcert Web of Trust" menu, and then click on one of the WoT forms.
Print that form out, [...]&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50019176 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</description><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/">&lt;pre&gt;A new CAcert Assuring Party will take place at DebConf8 in Mar del Plata,  Argentina, right next to the Keysigning Party[1], during this Thursday.
To obtain assurance at the event, login to the CAcert site and click the "CAcert Web of Trust" menu, and then click on one of the WoT forms.&lt;/pre&gt;
&lt;pre&gt;Print that form out, verify that it has complete and accurate information, bring it and 2 forms of government issued photo identification (one will be accepted, but two are preferred in case of document validity doubts). Please also read over the following pages:
&lt;a href="http://wiki.cacert.org/wiki/FAQ/AssuranceIntroduction"&gt;http://wiki.cacert.org/wiki/FAQ/AssuranceIntroduction&lt;/a&gt; and &lt;a href="http://wiki.cacert.org/wiki/FAQ/AssuranceByCAP"&gt;http://wiki.cacert.org/wiki/FAQ/AssuranceByCAP&lt;/a&gt;.&lt;/pre&gt;
&lt;pre&gt;There are some printers you can use to print forms at DebConf FrontDesk on the ground floor of the "Hotel Dora".

See you in there!&lt;/pre&gt;
&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=50019176 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</content:encoded><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blog.CAcert.org/2008/08/320.html/feed/</wfw:commentRss></item><item><title>Barcamp Stuttgart mit CAcert Assurances</title><link>http://blog.CAcert.org/2008/07/319.html</link><comments>http://blog.CAcert.org/2008/07/319.html#comments</comments><pubDate>Tue, 29 Jul 2008 08:24:02 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">wonderer</dc:creator><category>Information</category><guid isPermaLink="false">http://blog.CAcert.org/2008/07/319.html</guid><description>Das erste BarCamp in Stuttgart wird am 27. und 28. September 2008 im Literaturhaus Stuttgart und den Räumen der MFG stattfinden. Hier wird es auch die Möglichkeit der CAcert Assurance geben.
Weitere Infos auch unter http://wiki.cacert.org/wiki/BarCampStuttgart2008

&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=49280050 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</description><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/">&lt;p&gt;Das erste BarCamp in Stuttgart wird am &lt;strong&gt;27. und 28. September 2008&lt;/strong&gt; im Literaturhaus Stuttgart und den Räumen der MFG stattfinden. Hier wird es auch die Möglichkeit der CAcert Assurance geben.&lt;br /&gt;
Weitere Infos auch unter &lt;a target="_blank" href="http://wiki.cacert.org/wiki/BarCampStuttgart2008"&gt;http://wiki.cacert.org/wiki/BarCampStuttgart2008&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=49280050 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</content:encoded><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blog.CAcert.org/2008/07/319.html/feed/</wfw:commentRss></item><item><title>Assurance Policy now in DRAFT</title><link>http://blog.CAcert.org/2008/07/318.html</link><comments>http://blog.CAcert.org/2008/07/318.html#comments</comments><pubDate>Fri, 25 Jul 2008 01:09:07 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">iang</dc:creator><category>Information</category><guid isPermaLink="false">http://blog.CAcert.org/2008/07/318.html</guid><description>A week or so ago, the policy group pushed the Assurance Policy into DRAFT, which means according to PoP that it is now binding on the community.  To all the Assurers out there, this is your policy!
You should take a moment to have a look at it.  As it is in DRAFT, there is room [...]&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=49090535 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</description><content:encoded xmlns:content="http://purl.org/rss/1.0/modules/content/">&lt;p&gt;A week or so ago, the policy group pushed the &lt;a title="Assurance Policy in its DRAFT Form" href="http://svn.cacert.org/CAcert/Policies/AssurancePolicy.html"&gt;Assurance Policy&lt;/a&gt; into &lt;a title="p20080712.1" href="http://wiki.cacert.org/wiki/PolicyDecisions"&gt;DRAFT&lt;/a&gt;, which means according to &lt;a title="Policy on Policy says a document goes through work-in-progress, then DRAFT, then POLICY" href="http://www.cacert.org/policy/PolicyOnPolicy.php"&gt;PoP&lt;/a&gt; that it is now binding on the community.  To all the Assurers out there, this is your policy!&lt;/p&gt;
&lt;p&gt;You should take a moment to have a &lt;a title="the Assurance Policy in DRAFT" href="http://svn.cacert.org/CAcert/Policies/AssurancePolicy.html"&gt;look at it&lt;/a&gt;.  As it is in DRAFT, there is room for change, although each change will need to be voted through in the policy group.   You will see its evolution in the &lt;strike&gt;striking&lt;/strike&gt; and &lt;strong&gt;bolding&lt;/strong&gt; of parts.  Also be aware of the &lt;a title="The Assurance Handbook" href="http://wiki.cacert.org/wiki/AssuranceHandbook2"&gt;Assurance Handbook&lt;/a&gt;, which is where most of the daily practice will end up.  Now that there is a policy, the Handbook should also evolve more clearly and more rapidly.&lt;/p&gt;
&lt;p&gt;The Assurance Policy establishes many things that in the past have been unclear or subject to variation.  Here&amp;#8217;s a brief list of some changes:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The general standard of a Name is that it is as written on a government-issued photo ID.  It should be recorded as fully as possible.&lt;/li&gt;
&lt;li&gt;However, because there are many variations in real life, multiple names will be possible.  That is, the online system will have a new feature added to it to add extra names, each requiring full Assurance independently.  When that is done, this will address the difficulties that people have with different documents, transliterations, married names, middle names and initials, etc.&lt;/li&gt;
&lt;li&gt;We&amp;#8217;ve always encouraged Assurers to assure each other mutually, and this policy goes one step further:  it encourages non-Assurers to also assure you, under your supervision.  That is, when assuring a Member, you take the Member through the process of Assurance as if she were an Assurer.  You advise her on the steps, and encourage her to allocate 0,1,2 Assurance Points to you according to her judgement.  Be strict, it is better for her to allocate zero points to you to get used to the idea of assessing Name and other issues. You keep the forms, and when we get the system changed, you will enter in her points. Mutual Assurance will help us in the future:  It has the benefit of equalising the relationship, explaining the whole process, preparing the junior Member for the role and responsibilities of Assurer, and also identifying who you are to her.  As you the Assurer will be responsible for the entire result, and it takes extra time, you can choose to do it or not.&lt;/li&gt;
&lt;li&gt;As we now live in a world of Identity Theft, it is important for you the Assurer to protect the Members from harm.  In particular; &lt;a title="and they won't be as easy to catch as this one..." href="http://wiki.cacert.org/wiki/Arbitrations/a20070921.2"&gt;false Assurances do happen&lt;/a&gt;, and could be used to acquire valuable information.  To this end, the Assurance Policy states:&lt;br /&gt;
&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;&amp;#8220;A Member may check the status of another Member, especially for an assurance process&amp;#8230;&amp;#8221;&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;In the future, we will need some way for you the Assurer to show you really are an Assurer.  How that is done is left up to the systems and management people; a future thought puzzle.&lt;/li&gt;
&lt;li&gt;The final big change is that Experience is no longer to be reflected in the Assurance Points.  In the future, there will be a separate set of points, called Experience Points.  Each Assurance you conduct will earn you 2 Experience Points, as before.  Separating out the points to match their meanings gets rid of a lot of mental gymnastics.  Again, we have to wait until the software is done.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;As you can see, there is more work to do!  The policy needs to be reviewed, improved and taken the final step to POLICY.  Until it goes to POLICY, you still have a chance of fixing or improving it, even though it is already binding on you, the Assurer.  And, the Handbook needs updating with the new Policy work.&lt;br /&gt;
Also, the account system needs to be updated to add these features:  multiple names, a new set of points for Experience, mutual Assurance, and perhaps some support for showing your status as Assurer.  This will take time, but help will make it go faster:  are there any PHP programmers who can help make those coding changes?
&lt;/p&gt;
&lt;p&gt;&lt;div style="font-size: 8pt;"&gt;&lt;img align=left src=http://www.rsscache.com/Section/Stats/logo.aspx?n=49090535 border=0&gt; Bandwidth saved by &lt;a href=http://www.rsscache.com&gt;RSScache.com&lt;/a&gt;&lt;/div&gt;</content:encoded><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blog.CAcert.org/2008/07/318.html/feed/</wfw:commentRss></item><rsscache:id>924</rsscache:id></channel></rss>