home.social

#cacert — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cacert, aggregated by home.social.

fetched live
  1. TIL

    pip install pip_system_certs

    Helps solving issues with requests and other Python libraries when you are installing custom CA certificates on the operating system and these are not recognized.

  2. @marcel the last #CAcert assurance I did was in 2013. I stopped using it myself I don't know how many years back. I think there would still be use for it, but it would require the root certs to be part of the major browser and OS trust chains.
    @cacert

  3. @deepjoy
    Yes, I participated in two projects funded by #NLnet
    First, #CAcert (I was on the board from 2012 to 2016, most recently as Vice President). Then, from 2016 until its unfortunate discontinuation in 2022, I worked on the #WPIA project, again as Vice President and also as Managing Director.

    I have to say that the email server actually requires the least work of all.
    I use the #MailCow Suite @doncow , and a lot of it is already automated, and the individual components work together seamlessly.
    My mail server "serves" almost the entire family network, as well as 4 small businesses and a handful of clubs. So, about 10 or 12 "main domains", and around 20 or 25 alias domains.

    IP reputation hasn't worried me much either; I've only had one blacklisting issue in the last five years, but the hosting provider resolved it within a few hours. And of course, you have to ensure that #DKIM, #DMARC, #SPF etc. work together correctly. Then it becomes quite easy.
    So I'd say things have gotten easier since I started #selfhosting e-Mail years ago. (#mDaemon was my first hosting suite for e-Mail).

    Edit: I should also mention that I run an email setup with a primary mail server and a backup mail server.

    @yunohost @nlnet

  4. @fluepke Nutze die schon seit Jahren. Hatte nicht mitbekommen, dass das Angebot eingestellt wird. Scheinbar geringe Verbreitung und Akzeptanz.

    Es bleibt, als komplett kostenlose Community-CA nach dem Web-of-Trust-Prinzip, aktuell wohl nur cacert.org/

    #cacert

  5. @jwildeboer @mynacol
    Great. What do the entries look like that accept #letsencrypt and #CAcert.org for S/MIME certificates and disallow all others?

  6. This topic has been occupying my brain cycles for quite some time now. It's already so deep down that I spontaneously sing "I am CA" to the Village People's YMCA song :) So it's time to share with you all and get more input. (CA is Certification Authority in x.509 lingo, I'll explain it all in my blog series :) (Why didn't #cacert think about this many years ago? Damn ;)

    #nerdcert

  7. @vlpatton The classic method is a key signing party. Get a bunch of people in the same room with legal photo identification and their fingerprints, and go around the room checking everyone else’s ID. Then, go home and sign everyone’s keys. Send the signed key to the key owner. Import signed keys and collect signatures!

    Key servers sharing signatures haven’t been a thing since the attacks years ago. Any modern keyserver will strip the signatures, so you’ll have to distribute your key with signatures some other way (WKD, DNS, a file on your web site, etc.).

    CAcert will do PGP key endorsements if you get enough assurances on their platform. Everyone with a signed key has had two forms of ID checked by two people. However, their infrastructure can only work on old-school RSA keys right now (they’re working on modernizing).

    #PGP #GnuPG #CAcert #KeySigningParty #cryptoparty #WebOfTrust

  8. @leyrer
    Ich sagte nicht, dass er tatsächlich "vertrauenswürdig" ist. Aber Faktum ist, dass es diesen und zwei weitere "Vertrauensdiensteanbieter" in Österreich gibt. Und es bieten alle Drei auch S/MIME kompatible Zertifikate an.

    Aber Du hast im Grunde schon recht, da geniesst bei mir #CAcert höheres Vertrauen als die drei zusammen.

  9. Für CAs ist es mit der Entfernung des <keygen> Element aus dem HTML Standard in der Tat nicht mehr so einfach die Private Keys komfortabel im Browser des Kunden erstellen zu lassen, diese in dessen Zertifikatsverwaltung zu schieben, ... aber #CAcert hat eine technische Lösung gefunden (siehe blog.cacert.org/2024/02/finall - auch wenn CAcert als allgemeine CA mangels Integration in den Browsern ausscheidet).

    6/x

    @Lioh @gnulinux

  10. Just got a mail notification that #CAcert relocated its association from Australia to #Switzerland, namely to #Geneva.

    Wasn't aware that they're still alive and active after all the degradation due to expired and cryptographically outdated root certificates, etc.

  11. Ich habe soeben zwei Wesen bei CaCert (re-)assured. Und dabei festgestellt das mein Engagement mit #CaCert schon 19 Jahre läuft. Hut ab, das es die Organisation schon so lange gibt!

  12. 20 Jahre #CAcert und immer noch ist der Nutzen sehr begrenzt.

  13. @resmo
    Do you know the Web of Trust from #CAcert.org?
    At the moment, we have very few applications that are based on this. There could easily be more ;-)
    If you have an idea: welcome!

    (We also have a few more ideas, but our resources are rather scarce and we can't work on more than one at a time. We want to present something new at Froscon this summer).

    #weboftrust #cacert #wot #security

  14. @wez @voltagex I purchased a code signing certificate from SignMyCode.com and it’s worked great. Though I bought it before the HSM requirements went into place, I don’t automate anything with it — though it’s a tempting idea.

    There’s always #CAcert, but they’ll probably never be globally trusted.

  15. Sicherheit im Internet, signierte E-Mails, spannende Gespräche. #CAcert auf der #FrOSCon - am 5. und 6. August in Sankt Augustin nahe Köln/Bonn. blog.cacert.org/

  16. 2/2
    Die für IT-Laien bedienbaren Tools bzw. die Integration in die Anwendungen kommen dann quasi von allein. Mehr zum Thema bei mir oder beim Verein wiki.cacert.org/CAcert #CACert

  17. So, die #CACert Identity Verification Forms hab ich jetzt lange genug aufbewahrt. Ab in den Schredder damit. Auf das Verbrennen verzichte ich.

    Hat denke ich seit #letsencrypt sowieso keine praktische Relevanz mehr.

  18. @fsf #PGP #GPG #GnuPG is so niche these days. There are more people signing commits with it than emails.

    Besides, good luck arguing about the validity and trustworthiness of plain PGP sigs in most courts (not all though -- does #Germany recognize #CACert as valid?)

    The best advice about using email: stop using email, switch to safer things.

  19. @blub @erAck #CAcert gibt's noch? Dachte, die wäre mit Let's Encrypt entgültig ausgestorben. Haben's ja nie durch die CAB-Akkreditierung geschafft.
  20. @silberhaeckse
    Na toll.. danke.
    Wenn das nur noch mit OpenSSL geht (falls..) wird #CAcert noch unbedeutender.

  21. Hat letztens mal jemand probiert, bei #CACert ein S/MIME Email-Zertifikat zu erstellen? Kommt nur
    "Wir haben keine gültige Zertifikatsanfrage bekommen. Bitte versuchen Sie es mit einem anderen Browser."
    Firefox 78 und 89 und Chromium 90.

    Verlängern kurz vorher ging, ich hätte danach keine alte Email-Adresse löschen sollen, was das existierende Zertifikat widerruft..

    Eine Websuche bringt nur zwei alte nicht weiterhelfende Support-Anfragen.

    Muss wohl der openssl Weg werden.

  22. @sungo I got myself verified in-person by several #CAcert members over a decade ago at a computer event in #Utrecht (#HCCDagen), but due to lacking browser support I have rarely used it since.
    Nowadays I just use #LetsEncrypt instead.

    I guess not forcefully redirecting to #httpS on their own site is a conscious choice, as their #CertificateAuthority still does not seem widely adopted by browser vendors

    mastodon.social/media/DcoGRJec

  23. #CAcert (cacert.org) is not going well—they might close down at the end of the year.

    They are looking for donations or other contributions (improve their wiki, become a sysadmin, board member, and many other small tasks).