In the software I used (as recently as last Thursday) the keys are _absolutely_, _positively_ generated locally. Subsequently the public key can be mailed automagically to RSADSI to be incorporated into a certificate which is returned to you. The latest version of RIPEM Mac uses the same procedure for the same functionality.
[...] users will get certified keys from RSA [...]
Yes! _After_ sending RSADSI an uncertified key.
[the user] can generate a key for use on their network
This is the uncertified key.
Apple believes you'll want publically certified keys
Thus, they provide a mechanism to get RSADSI to certify your (self generated) key. Scott Collins | "Few people realize what tremendous power there | is in one of these things." -- Willy Wonka ......................|................................................ BUSINESS. voice:408.862.0540 fax:974.6094 collins@newton.apple.com Apple Computer, Inc. 1 Infinite Loop, MS 301-2C Cupertino, CA 95014 ....................................................................... PERSONAL. voice/fax:408.257.1746 1024:669687 catalyst@netcom.com
Scott Colins writes:
In the software I used (as recently as last Thursday) the keys are _absolutely_, _positively_ generated locally. Subsequently the public key can be mailed automagically to RSADSI to be incorporated into a certificate ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ which is returned to you. The latest version of RIPEM Mac uses the same procedure for the same functionality.
Well, what keeps people from makeing keys with somebody else's name/user id on them and sending them in to be certified? Where is the authentication from the key certifier's point of view? Just wondering. Happy Hunting, -Chris. ______________________________________________________________________________ Christian Douglas Odhner | "The NSA can have my secret key when they pry cdodhner@indirect.com | it from my cold, dead, hands... But they shall pgp 2.3 public key by finger | NEVER have the password it's encrypted with!" "If guns are outlawed, only the government will have guns." -E. Abbey My opinions are shareware. For a registered copy, send me 15$ in DigiCash. Key fingerprint = 58 62 A2 84 FD 4F 56 38 82 69 6F 08 E4 F1 79 11 ------------------------------------------------------------------------------
participants (2)
-
Christian D. Odhner
-
collins@newton.apple.com