Forum Moderators: phranque

Message Too Old, No Replies

Certificate Authority

         

Lisa

1:33 am on Jul 25, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



How and where did Verisign sign-up to be a certificate authority? There are a few other companies out there that are CAs but where do people go to become official. Do they go directly to Microsoft and Netscape? How do Opera and the other browsers fit in… questions questions… I can’t find answers.

richlowe

2:06 am on Jul 25, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Here's the way that I understand it: anyone can be a certificate authority. In fact, you can install Microsoft certificate server on your IIS server (I'm sure there is an apache equivalent) and viola, you are an authorithy. You can then use Verisign or you can use your own server as the authority. Of course, the problem with using your own server is no one else recognizes it. The browser manufacturers include a number of authority certificates when they ship the browser, which is how verisign gets recognized as one of the big authorities.

You can see how this works by installing the appropriate certificate software on your server, then creating a cerificate and not use any authority but your own. Now visit the site with a browser, and it will pop up and tell you it does not know the authority, then it will ask you if you trust it. YOu can answer yes or no.

so verisign and others were only granted authority because the browser manufacturers distribute their certificate with the browsers, so the browsers will, by default, accept any certificate signed using verisign.

I believe, in overview, that's the way it works.

Richard LOwe

Lisa

2:23 am on Jul 25, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



So how much does Microsoft take on kick backs to trust Verisign?

Or really, How much would it cost me to have Microsoft distribute and trust me?

richlowe

2:25 am on Jul 25, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Oh a few billion, I'd bet.

I really have no idea, though.

Richard Lowe