Information

General news/information to the CAcert community or about security in general

PAUSE gets a CAcert certificate

Posted by Johan Vromans
On April 19th, 2008 at 20:04

Permalink | Trackback | Links In |

No Comments |
Posted in Information

The Perl Authors Upload Server (PAUSE) has had a self signed cert for it’s SSL stuff. As of April 19, 2008 it will use a cert signed by CAcert.

For more information: http://www.cpan.org/modules/04pause.html#ssl

CAcert group on LinkedIn

Posted by Evaldo Gardenali
On April 19th, 2008 at 00:04

Permalink | Trackback | Links In |

No Comments |
Posted in Information

CAcert group is now approved on LinkedIn, and open to the CAcert community. The group is reachable at http://www.linkedin.com/e/gis/89248/182D4E19701F

CAcert Assurances on the Penguicon Convention, USA, Michigan, Detroit(Troy)

Posted by H. Heigl
On April 16th, 2008 at 03:04

Permalink | Trackback | Links In |

No Comments |
Posted in Information
At the Penguin Convention in Michigan there will be a keysigning party for Michigan and the
surrounding cities (Flint, Lansing etc.). Penguicon is open to the public, but registration is now at the door only for this year.  Penguicon will take place next weekend, April 18-20. in Michigan, US and the details can be found on the official website.  The keysigning portion will take place on Saturday.
More information on the Penguicon Website (http://www.penguicon.org/).

CAcert under GPL Licence

Posted by H. Heigl
On April 8th, 2008 at 06:04

Permalink | Trackback | Links In |

No Comments |
Posted in Information

CAcert is now official under the GPL Licence Version 2. More information and the Source Code could be found under http://www.cacert.org/src-lic.php

CAcert Association Special General Meeting 4th April 2008 (reminder)

Posted by Teus Hagen
On April 1st, 2008 at 22:04

Permalink | Trackback | Links In |

No Comments |
Posted in Events, Information

CAcert Inc. as association, will have a Special General Meeting on two by-laws issues to be voted upon:

  1. Rules defining non-profit (a prerequisite for tax reasons);
  2. Enable to vote via email by CAcert association members (needed to get an easier influence from membership).

The SGM is on 4th of April 2008 11 pm MET, via CAcert irc channel. The details are in the SGM agenda.

CAcert association members are called to attend this meeting. The minimum quorum for a formal meeting is five attendees. Even if these voting topics are not much of a discussion the SGM is important and minimizes the costs of operation.

CATS Assurer Prüfung nun auch auf deutsch

Posted by H. Heigl
On March 27th, 2008 at 17:03

Permalink | Trackback | Links In |

No Comments |
Posted in Information

die Assurer Challenge, die demnächst für alle CAcert Assurer Pflicht sein wird, kann jetzt auch mit deutschen Fragen abgelegt werden. Und auch die Anleitung gibt’s inzwischen auf deutsch: http://wiki.cacert.org/wiki/AssurerPr%C3%BCfung

Audit Report 20080321

Posted by iang
On March 22nd, 2008 at 05:03

Permalink | Trackback | Links In |

No Comments |
Posted in Information

As promised, there is now a current report posted on the wiki from Audit. Highlights:

  • CAcert is in the process of rolling out its new CAcert Community Agreement. The website now refers to it.
  • Soon, expect to see checkboxes to tick with statements like “I agree to the CAcert Community Agreement”.
  • The Assurance Policy is the next policy that the Audit needs tied down. Currently, it is at an advanced stage. Debate is going on as to whether to drop the requirement for Dates of Birth, as these are considered useful for fraud in some places. Unfortunately, the system does use this as an internal discriminator, so there are pros and cons.
  • Pat Wilson is now working on the Security Manual. Thanks, and welcome Pat!
  • The critical systems are the critical path for audit! Evaldo has been tasked to build the sysadm team, move the systems and implement dual control. See other blog entries!
  • Have you met the Assurer Challenge yet? CATS is in place, and some time soon, assurances will be blocked for those who have not as yet met the challenge.
  • If you are interested in the Audit work, there is a ToDo list on the wiki, and I have put the audit criteria online with the working commentary and (wip) conformance. See the main report for that location and the secret password!

That’s it from the Audit side. Now over to you!

Audit Report 20080111

Posted by iang
On March 21st, 2008 at 01:03

Permalink | Trackback | Links In |

No Comments |
Posted in Information

One of the things that happened last year was to negotiate an audit funding deal with NLnet. (This has now agreed and first tranche of funds has been delivered to CAcert.) One of the requirements imposed on CAcert was to deliver reports to the Community and to NLnet at each event like milestones, and at approximately 2 month intervals.

With that in mind, I wrote a 2008 New Year’s report as a sort of checkpoint. For some reason it wasn’t published then, but is now on the wiki. Highlights are these:

  1. Many policies are now in POLICY or DRAFT. Some important work-in-progress projects are started, especially the Assurance Policy. This project needs help!
  2. The work on Risks/Liabilities/Obligations finally settled on a CAcert Community Agreement.
  3. NLnet funds CAcert for audit, described here.
  4. Non-critical systems were moved last year to Netherlands BIT center, but critical systems are still in their halfway house. CAcert needs more sysadms.
  5. Audit Criteria are going on-line.
  6. Best is last: CATS went on line: Have you done the Assurer Challenge yet?

The full report is found on the wiki area. Bear in mind that this report is late, and another is already due. I’ll start on that now!

Recruiting System Administrators

Posted by Evaldo Gardenali
On February 29th, 2008 at 05:02

Permalink | Trackback | Links In |

No Comments |
Posted in Information

Calling all system administrators in the CAcert Community!  We have need of help in running services like web, svn, wiki.  Please contact evaldo@cacert.org if you can help.

CAcert Community Agreement is defined now!

Posted by Teus Hagen
On February 26th, 2008 at 01:02

Permalink | Trackback | Links In |

No Comments |
Posted in News, Information

As you may know, CAcert started a big effort in 2007 to address who we are as members of a CA service provision, the Community and the increase of the recognition of CAcert as a professional CA.
CAcert belongs now to the top ten CA’s in the world! This all was inspired and demanded by the need to have CAcert Root Key included in the browsers. For this CAcert started the Audit process, which focused on the questions of Risks, Liabilities, and Obligations amongst us all.

CAcert has now conquered that monumental task. Core of that task was defining who we are as a community, and writing a CAcert Community Agreement that we can all agree to, which brings us together as that community, and which protects you, using the CAcert issued certificates, legally, financially and freely.

Here you can read the details of the CAcert Community Agreement .

Introductory notes on the agreement are on the wiki. This introduction attempts to explain some of the parts, which need maybe some more explanation, eg on free certificates, privacy concernings, certificate care and usage risks, and the CAcert Community.

The Agreement is now approved: by the Board, by the Policy Group, and by the Association, and it is now ready for you!

CAcert software developers will modify the website and the Assurance team will modify the Assurance processes to ask people to agree to it.This will take some time.
In the end we will need agreement from everyone inside the CAcert Community, because it protects each and every one of you, and all of us together, as a community.

CAcert Management Sub-Committee