<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>CAcert NEWS Blog</title>
	<atom:link href="http://blog.cacert.org/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.cacert.org</link>
	<description>CAcert NEWS and up coming events.</description>
	<pubDate>Tue, 24 Aug 2010 16:02:46 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>CAcert Assurer Training Event am 04. Oktober 2010 in Aachen</title>
		<link>http://blog.cacert.org/2010/08/482.html</link>
		<comments>http://blog.cacert.org/2010/08/482.html#comments</comments>
		<pubDate>Tue, 24 Aug 2010 15:45:23 +0000</pubDate>
		<dc:creator>walter</dc:creator>
		
		<category><![CDATA[Training]]></category>

		<category><![CDATA[ATE Assurer Training Aachen 2010]]></category>

		<guid isPermaLink="false">https://blog.cacert.org/?p=482</guid>
		<description><![CDATA[
Es hat sich viel getan im letzten Jahr. Eine ganze Reihe von bisher eher &#8220;muendlich ueberlieferten&#8221; Regeln wurden in Policies gegossen. Neue Prozeduren (z.B. die Assurer Challenge) und Verpflichtungen (z.B. in dem CAcert Community Agreement) wurden beschlossen. Die Assurer Training Events wollen versuchen, die ganzen Informationen &#8220;unter&#8217;s Volk&#8221; zu bringen:
- Wovor schuetzt die CCA jedes [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://upload.wikimedia.org/wikipedia/commons/thumb/3/39/Aachen_Ford-Entwicklungszentrum.jpg/800px-Aachen_Ford-Entwicklungszentrum.jpg" alt="" /></p>
<p>Es hat sich viel getan im letzten Jahr. Eine ganze Reihe von bisher eher &#8220;muendlich ueberlieferten&#8221; Regeln wurden in Policies gegossen. Neue Prozeduren (z.B. die Assurer Challenge) und Verpflichtungen (z.B. in dem CAcert Community Agreement) wurden beschlossen. Die Assurer Training Events wollen versuchen, die ganzen Informationen &#8220;unter&#8217;s Volk&#8221; zu bringen:</p>
<p>- Wovor schuetzt die CCA jedes CAcert-Community-Mitglied und somit auch dich?<br />
- Kannst du die 5 Statements der &#8220;Purpose of Assurance&#8221; aufzaehlen?<br />
- Kannst du auf Anhieb 10 Sicherheitsmerkmale des deutschen<br />
  Personalausweises aufzaehlen?</p>
<p>Antworten auf diese und weitere Fragen erhaelst du bei den Assurer Training Events (ATEs).</p>
<p>Die kommenden Veranstaltungen finden statt am:<strong> Montag den 04. Oktber 2010</strong> in den Seminarräumen (Madrid + Lissabon) der Jugendherberge Aachen statt.</p>
<p><img src="http://upload.wikimedia.org/wikipedia/commons/thumb/f/fd/AachenMainStationHDR.jpg/800px-AachenMainStationHDR.jpg" alt="" /></p>
<p><strong>Anreise</strong></p>
<p>PKW<br />
Aus Deutschland kommend:<br />
Aus Richtung Köln A4 / E40 bzw. aus Richtung Mönchengladbach A44 bis Kreuz Aachen.<br />
Weiter auf der A 44 Richtung Lüttich (Liège).<br />
Abfahrt Aachen Lichtenbusch (Letzte Abfahrt vor der Grenze nach Belgien)<br />
Rechts Richtung Zentrum, dann nach Ortseingang an der ersten großen Ampel-Kreuzung links in die Siegelallee abbiegen (Hier steht ein Schild mit der Aufschrift: „Euregionales Jugendgästehaus Aachen“)<br />
Nach der Eisenbahnbrücke rechts in die Maria-Theresia-Allee</p>
<p>Aus Belgien kommend:<br />
Aus Richtung Lüttich (Liège) A3 / E40 Bis Abfahrt Eynatten<br />
Rechts Richtung Aachen Süd<br />
An der erste Großen Ampelkreuzung nach der Grenze zu Deutschland: links in den Luxemburger Ring abbiegen<br />
Nach der Eisenbahnbrücke rechts in die Maria-Theresia-Allee</p>
<p>Ausgewiesene öffentliche PKW-Parkflächen stehen auf der Maria Theresia Allee kostenfrei zur Verfügung.</p>
<p>Bahn und Bus<br />
Start Hauptbahnhof [Haltestelle 2 gegenüber dem Haupteingang des HBF] Linie 3B Richtung „Uniklinik“<br />
alternativ kann die Linie 1 und 46 an der gleichen Haltestelle benutzt werden<br />
Haltestelle Misereor dort Straßenseite wechseln<br />
Haltestelle Misereor [Karmeliterstraße] Linie 2 Richtung „Aachen, Preuswald“<br />
Haltestelle Reumontstraße<br />
Haltestelle Schillerstraße<br />
Haltestelle Goethestraße<br />
Haltestelle Kaiser-Friedrich-Park<br />
Haltestelle Yorckstraße<br />
Haltestelle Brüsseler Ring<br />
Ziel Ronheide (Jugendherberge) Ausstieg</p>
<p>Abfahrtzeiten:<br />
     Hauptbahnhof: xx:04, xx:21, xx:34, xx:51<br />
     Misereor: xx:14, xx:29, xx:44, xx:59<br />
Fahrzeit:<br />
     14 bis 16 Minuten<br />
Fahrpreis:<br />
     € 2,35 einfache Fahrt (günstiger bei 4er-Karte)</p>
<p><strong>Anmeldung</strong></p>
<p><a href="mailto:events@cacert.org?subject=ATE-attend-ATE-AC&amp;body=I%20will%20attend">Ich möchte am Event in Aachen teilnehmen!</a></p>
<p>siehe auch <a href="http://wiki.cacert.org/Events/2010_10_04-ATE-Aachen">WiKi</a></p>
<p>Nebenbei, am 02 und 03. Oktober findet der diesjährige Oktober ac-treff in den gleichen Räumlichkeiten statt,  vielleicht hat der eine oder andere von euch Lust auch dort dabei zu sein. Mehr dazu findet ihr <a href="https://vewa-net.de/wiki/doku.php?id=treffen:kommende:2010-10-02_aachen">hier</a>.</p>
<p>Wir sehen uns in Aachen ?!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cacert.org/2010/08/482.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>CAcert auf der FrOSCon 2010 (Sa 21. + So 22. Aug)</title>
		<link>http://blog.cacert.org/2010/08/481.html</link>
		<comments>http://blog.cacert.org/2010/08/481.html#comments</comments>
		<pubDate>Fri, 20 Aug 2010 01:43:05 +0000</pubDate>
		<dc:creator>U. Schroeter</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<category><![CDATA[Information]]></category>

		<category><![CDATA[Assurance]]></category>

		<category><![CDATA[Event]]></category>

		<category><![CDATA[FrOSCon]]></category>

		<category><![CDATA[Keysigning]]></category>

		<guid isPermaLink="false">https://blog.cacert.org/?p=481</guid>
		<description><![CDATA[Wie jedes Jahr nimmt CAcert auch auf der diesjährigen FrOSCon in St.Augustin (bei Bonn) als Aussteller teil. Interessenten können sich Assuren lassen. Ebenfalls findet auch wieder eine Keysigning Party statt.


Wer gerade als Assurer die Tätigkeit aufgenommen hat, kann gerne mithelfen. Genügend erfahrene Assurer sind anwesend und können so bei den ersten Schritten behilflich sein.
Ehemalige Thawte [...]]]></description>
			<content:encoded><![CDATA[<p>Wie jedes Jahr nimmt CAcert auch auf der diesjährigen FrOSCon in St.Augustin (bei Bonn) als Aussteller teil. Interessenten können sich Assuren lassen. Ebenfalls findet auch wieder eine Keysigning Party statt.<br />
<span id="more-481"></span><br />
<img align="right" width="192" src="http://www.froscon.de/fileadmin/img/froscon_logo.jpg" alt="FrOSCon Logo" /><br />
Wer gerade als Assurer die Tätigkeit aufgenommen hat, kann gerne mithelfen. Genügend erfahrene Assurer sind anwesend und können so bei den ersten Schritten behilflich sein.</p>
<p>Ehemalige Thawte Notarys sollten die Gelegenheit nutzen, sich noch einmal Assuren zu lassen, bzw. selbst Assurances durchzuführen, da sonst zur Deadline am 16. November Punkte verfallen können. (siehe auch Blog Post vom 3.8. <a href="https://blog.cacert.org/wp-admin/post.php?action=edit&amp;post=466">Thawte Points Transfer and Removal of Points at Nov 16th 2010</a>)</p>
<p>Ebenso sucht CAcert Helfer im Projekt. Zur Zeit suchen wir dringend Personen die im Support mithelfen und Systemadministratoren für die Nicht-Kritischen Systeme (Wiki, Blog, Email, IRC, usw.).</p>
<p>Für Assurer Training Events (ATE&#8217;s) suchen wir Personen, die die Vorbereitung und Planung in ihrer Stadt übernehmen können. Da die ATE&#8217;s die Basis für die co-Audited Assurances bilden und das wiederum die Basis für das Audit über die Registration Authority (RA) ist, kommt diesem Thema derzeit die höchste Priorität zu (siehe auch Board Motion vom 1.8.2010 <a href="https://community.cacert.org/board/motions.php?motion=m20100801.3">m20100801.3</a>).</p>
<p>Sprecht uns am Samstag oder Sonntag zu den Themen &#8220;Thawte Points Removal&#8221;, &#8220;Helfer Gesucht&#8221; bzw. &#8220;ATE&#8217;s&#8221; auf dem Stand an.</p>
<p><strong>Wann? - Wo? - Preise?</strong></p>
<ul>
<li>Wann?<br />
  21.08.2010 - 22.08.2010</li>
<li>Wo?<br />
     Hochschule Bonn-Rhein-Sieg<br />
     Grantham-Allee 20<br />
     53757 Sankt Augustin<br />
<a href="http://osm.org/go/0GIHypxFq--">OpenStreet Map</a><br />
<a href="http://maps.google.de/maps?f=q&amp;source=s_q&amp;hl=de&amp;geocode=&amp;q=Grantham-Allee,+Sankt+Augustin&amp;sll=51.151786,10.415039&amp;sspn=11.446222,27.905273&amp;ie=UTF8&amp;hq=&amp;hnear=Grantham-Allee,+53757+Sankt+Augustin&amp;ll=50.78133,7.183213&amp;spn=0.011261,0.027251&amp;z=15&amp;iwloc=A">Google Maps</a></li>
<li>Was kosten Tickets?<br />
Tickets kosten für beide Tage insgesamt 5 Euro. </li>
</ul>
<p><strong>Links:</strong></p>
<ul>
<li><a href="http://www.froscon.de">Free and Open Source Software Conference 2010</a></li>
<li><a href="http://www.froscon.de/aussteller/projekte.html">CAcert in der Ausstellerliste</a></li>
<li><a href="https://wiki.cacert.org/events/FrOSCon2010">FrOSCon 2010 im CAcert Wiki</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.cacert.org/2010/08/481.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Community Update July 2010</title>
		<link>http://blog.cacert.org/2010/08/480.html</link>
		<comments>http://blog.cacert.org/2010/08/480.html#comments</comments>
		<pubDate>Fri, 06 Aug 2010 02:13:03 +0000</pubDate>
		<dc:creator>U. Schroeter</dc:creator>
		
		<category><![CDATA[Information]]></category>

		<category><![CDATA[News]]></category>

		<category><![CDATA[Progress]]></category>

		<category><![CDATA[Assurance]]></category>

		<category><![CDATA[Board]]></category>

		<category><![CDATA[Community]]></category>

		<category><![CDATA[Policy]]></category>

		<category><![CDATA[PracticeOnNames]]></category>

		<category><![CDATA[RDL]]></category>

		<category><![CDATA[Software-Assessment]]></category>

		<category><![CDATA[Support]]></category>

		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">https://blog.cacert.org/?p=480</guid>
		<description><![CDATA[July 2010 was full of activities. Two Board members resigned. New procedures for Assurers were updated. And the Software-Assessment Project reaches one milestone.


2010-07-20 Daniel resigns from Board, Infrastructure Team Lead, Systems Admin (various)
2010-07-17 PracticeOnNames updated with the NL country variation Arbitration ruling of a20090618.12. The ruling was written February this year, but had not been [...]]]></description>
			<content:encoded><![CDATA[<p>July 2010 was full of activities. Two Board members resigned. New procedures for Assurers were updated. And the Software-Assessment Project reaches one milestone.<br />
<span id="more-480"></span></p>
<ul>
<li><b>2010-07-20</b> Daniel <a href="https://lists.cacert.org/wws/arc/cacert-board/2010-07/msg00049.html">resigns</a> from Board, Infrastructure Team Lead, Systems Admin (various)</li>
<li><b>2010-07-17</b> PracticeOnNames updated with the NL country variation Arbitration ruling of <a href="https://wiki.cacert.org/Arbitrations/a20090618.12">a20090618.12</a>. The ruling was written February this year, but had not been pushed out yet to the community. This presents a more relaxed rule: &quot;Abbreviations on givennames are allowed under some circumstances&quot; regarding Dutch givennames.</li>
<li><b>2010-07-16</b> Faster Support Actions on requests by Assurers and Users on Name Change cases, DoB changes after events
<ul>
<li>In February this year, there was an interesting Arbitration case that relates to all assurers and members with name change and DoB problem requests. This Arbitration case <a href="https://wiki.cacert.org/Arbitrations/a20100210.2">a20100210.2</a> takes precedence if requested within 24 hours an error was made, or upto 7 days after a big event. As thus should allow to decrease the disputes queue, we need all the help from the community, that such errors are reported within the given timeframe. This is to simplify Support cases and to decrease the delay in Arbitration cases by reducing the cases in the queue. For details please read the Arbitration case <a href="https://wiki.cacert.org/Arbitrations/a20100210.2">a20100210.2</a> ruling.</li>
</ul>
</li>
<li><b>2010-07-14</b> One Milestone in Software-Assessment-Project reached<br />
  Within the last week we’ve reached one milestone in our new Software-Assessment-Project. The team is working since November 2009 on a new Software Repository and a new Testserver. The Testserver needed a Testserver Mgmt System to set the environment for testing new Software and Patches for the Webdb system.<br />
  The long blocking factor was the Testserver Mgmt System. That is now installed and functional with basic functions:</p>
<ul>
<li>Increase Assurance Points (to start testing as Assurer)</li>
<li>Setting special Flags (to start testing as i.e. Support-Engineer for SE patches)</li>
</ul>
<p>  The Testserver Mgmt System is buildt with the Zend Framework and is an addtl. instance on the Testserver.</p>
<p>  The next step in deploying the new Software-Assessment Environment is to find the first Testers, who helps deploying the procedure on Documentation of current patches (see <a href="https://wiki.cacert.org/Software/CurrentTest">Software-Assessment: Current Tests</a>)</p>
<p>  The Software-Assessment-Project is an essential brick in the wall for the Audit as this blocks several Audit steps (Audit over Systems, CCA-Rollout, and others). An overview of the steps to an Audit-restart can be found on the <a href="https://wiki.cacert.org/OverviewProjectsBoard">Overview Projects Board</a> Wiki page.</p>
<p>  For further infos about the Software-Assessment-Project read <a href="https://wiki.cacert.org/Software/Assessment">Software-Assessment-Project</a> Page</li>
<li><b>2010-07-10</b> Voting on Policy Group for <a href="https://wiki.cacert.org/PolicyDecisions#p20100710_License_root_under_Root_Distribution License">p20100710 License root under Root Distribution License</a> opened</li>
<li><b>2010-07-04</b> Ernestine <a href="https://lists.cacert.org/wws/arc/cacert-board/2010-07/msg00018.html">resigns</a> from Board and Treasurer</li>
<li><b>2010-07-03</b> Dominik George was appointed by board motion <a href="https://community.cacert.org/board/motions.php?motion=m20100625.1">m20100625.1</a> to become Support-Engineer</li>
</ul>
<p>Please keep yourself informed by continuously reading the <a href="https://wiki.cacert.org/Community/Update">Community Updates</a> in the Wiki.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cacert.org/2010/08/480.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>root certificates under free license, RDL</title>
		<link>http://blog.cacert.org/2010/07/478.html</link>
		<comments>http://blog.cacert.org/2010/07/478.html#comments</comments>
		<pubDate>Fri, 30 Jul 2010 15:35:21 +0000</pubDate>
		<dc:creator>sspreitzer</dc:creator>
		
		<category><![CDATA[Information]]></category>

		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">https://blog.cacert.org/?p=478</guid>
		<description><![CDATA[The CACert policy group proudly announces the new Root Distribution License (RDL)[1], which grants the distribution of CACerts root certificates by non related parties. RDL is a free/libre compatible license to allow unrelated vendors and/or distributors to distribute CACert&#8217;s root certificates to their users.
CACert confesses itself to interoperability with free and open projects. The CACert [...]]]></description>
			<content:encoded><![CDATA[<p>The CACert policy group proudly announces the new Root Distribution License (RDL)[1], which grants the distribution of CACerts root certificates by non related parties. RDL is a free/libre compatible license to allow unrelated vendors and/or distributors to distribute CACert&#8217;s root certificates to their users.</p>
<p>CACert confesses itself to interoperability with free and open projects. The CACert website is soon to be updated to reflect the new RDL.<br />
A distributable source package can be found here [2]</p>
<p>[1] <a href="http://www.cacert.org/policy/RootDistributionLicense.php">http://www.cacert.org/policy/RootDistributionLicense.php</a><br />
[2] <a href="http://sspreitzer.fedorapeople.org/ca-cacert/">http://sspreitzer.fedorapeople.org/ca-cacert/</a></p>
<p>~<a href="http://spreitzer.name/">sspreitzer</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cacert.org/2010/07/478.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>PING e.V. Sommerfest, 7.8.2010, Dortmund</title>
		<link>http://blog.cacert.org/2010/07/477.html</link>
		<comments>http://blog.cacert.org/2010/07/477.html#comments</comments>
		<pubDate>Mon, 19 Jul 2010 21:59:34 +0000</pubDate>
		<dc:creator>5e94d9c011b5e318e600b8415cac65cf5a56361d</dc:creator>
		
		<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">https://blog.cacert.org/?p=477</guid>
		<description><![CDATA[Die Profis des größten gemeinnützigen Internetvereins helfen und beraten bei Fragen zu den Themen Internet und Sicherheit.
Der PING e.V. lädt am 07. August 2010 ab 14:00 Uhr zum &#8220;Sommerfest&#8221; ein.
Besucher haben an diesem Tag die Möglichkeit, hinter die Kulissen unseres Vereins zu schauen und die Aktiven Mitglieder kennenzulernen.
Abgerundet wird das ganze mit mehreren Kurzvorträgen. Die [...]]]></description>
			<content:encoded><![CDATA[<p>Die Profis des größten gemeinnützigen Internetvereins helfen und beraten bei Fragen zu den Themen Internet und Sicherheit.</p>
<p>Der PING e.V. lädt am 07. August 2010 ab 14:00 Uhr zum &#8220;Sommerfest&#8221; ein.<br />
Besucher haben an diesem Tag die Möglichkeit, hinter die Kulissen unseres Vereins zu schauen und die Aktiven Mitglieder kennenzulernen.</p>
<p>Abgerundet wird das ganze mit mehreren Kurzvorträgen. Die Vorträge dauern jeweils ca. 15 - 20 Minuten und sind sowohl für Einsteiger als auch versierte Interessierte geeignet.<br />
Im Anschluss an einen Vortrag besteht die Möglichkeit in einer lockeren Diskussionsrunde Fragen zu klären oder die eigene Erfahrung einzubringen. Weiter geht es nach einer kleinen Pause mit dem nächsten Vortrag. Selbstverständlich stehen dann die Referenten und die ehrenamtlichen Helfer des Vereins für Fragen und Diskussionen gerne zur Verfügung. </p>
<p>Des Weiteren werden ein PGP Keysigning und CAcert Assurance angeboten.</p>
<p>Geplante Themen der Vorträge:</p>
<ul>
<li>OpenStreetMap</li>
<li>Wireless-Lan Sicherheit</li>
<li>Bildbearbeitung mit freier Software</li>
<li>Menschliche und digitale Spuren im Internet</li>
<li>Voice-over-IP</li>
<li>Einblick in Ubuntu Linux</li>
</ul>
<p>Weitere Informationen, Anfahrtdetails und last minute updates gibt es auf der <a href="http://www.ping.de/sommerfest">Event-Seite</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cacert.org/2010/07/477.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>One Milestone in Software-Assessment-Project reached</title>
		<link>http://blog.cacert.org/2010/07/476.html</link>
		<comments>http://blog.cacert.org/2010/07/476.html#comments</comments>
		<pubDate>Wed, 14 Jul 2010 02:18:11 +0000</pubDate>
		<dc:creator>U. Schroeter</dc:creator>
		
		<category><![CDATA[Information]]></category>

		<category><![CDATA[News]]></category>

		<category><![CDATA[Progress]]></category>

		<category><![CDATA[audit]]></category>

		<category><![CDATA[CCA Rollout]]></category>

		<category><![CDATA[Patches]]></category>

		<category><![CDATA[Software]]></category>

		<category><![CDATA[Software-Assessment]]></category>

		<category><![CDATA[Testserver]]></category>

		<guid isPermaLink="false">https://blog.cacert.org/?p=476</guid>
		<description><![CDATA[Within the last week we&#8217;ve reached one milestone in our new Software-Assessment-Project.
The team is working since November 2009 on a new Software Repository and a new Testserver.
The Testserver needed a Testserver Mgmt System to set the environment for testing new Software and Patches for the Webdb system.

The long blocking factor was the Testserver Mgmt System. [...]]]></description>
			<content:encoded><![CDATA[<p>Within the last week we&#8217;ve reached one milestone in our new Software-Assessment-Project.<br />
The team is working since November 2009 on a new Software Repository and a new Testserver.<br />
The Testserver needed a Testserver Mgmt System to set the environment for testing new Software and Patches for the Webdb system.<br />
<span id="more-476"></span><br />
The long blocking factor was the Testserver Mgmt System. That is now installed and functional with basic functions:<br />
 * Increase Assurance Points (to start testing as Assurer)<br />
 * Setting special Flags (to start testing as i.e. Support-Engineer for SE patches)<br />
The Testserver Mgmt System is buildt with the Zend Framework and is an addtl. instance on the Testserver.</p>
<p>The next step in deploying the new Software-Assessment Environment is to find the first Testers, who helps deploying the procedure on Documentation of current patches (see <a href="https://wiki.cacert.org/Software/CurrentTest">Software-Assessment: Current Tests</a>)</p>
<p>The Software-Assessment-Project is an essential brick in the wall for the Audit as this blocks several Audit steps (Audit over Systems, CCA-Rollout, and others). An overview of the steps to an Audit-restart can be found on the <a href="https://wiki.cacert.org/OverviewProjectsBoard">Overview Projects Board</a> Wiki page.</p>
<p>For further infos about the Software-Assessment-Project read <a href="https://wiki.cacert.org/Software/Assessment">Software-Assessment-Project Page</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cacert.org/2010/07/476.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>New Password Recovery w/ Assurance Procedure</title>
		<link>http://blog.cacert.org/2010/06/475.html</link>
		<comments>http://blog.cacert.org/2010/06/475.html#comments</comments>
		<pubDate>Mon, 14 Jun 2010 00:05:36 +0000</pubDate>
		<dc:creator>U. Schroeter</dc:creator>
		
		<category><![CDATA[Information]]></category>

		<category><![CDATA[News]]></category>

		<category><![CDATA[Assurance]]></category>

		<category><![CDATA[Password Recovery]]></category>

		<category><![CDATA[Support]]></category>

		<guid isPermaLink="false">https://blog.cacert.org/?p=475</guid>
		<description><![CDATA[To All Assurers,
A new Password Recovery w/ Assurance procedure has been established thru Arbitration case a20100407.1.
The procedure is outlined under https://wiki.cacert.org/Support/PasswordRecoverywithAssurance

All you need to do is (for the user who has lost his Password):

Find an Assurer to do an Assurance
Create an A-Word (part of a passphrase)
The Assurer has to trigger the Password Recovery Procedure by [...]]]></description>
			<content:encoded><![CDATA[<p>To All Assurers,</p>
<p>A new Password Recovery w/ Assurance procedure has been established thru <a href="https://wiki.cacert.org/Arbitrations/a20100407.1">Arbitration case a20100407.1</a>.<br />
The procedure is outlined under <a href="https://wiki.cacert.org/Support/PasswordRecoverywithAssurance">https://wiki.cacert.org/Support/PasswordRecoverywithAssurance</a><br />
<span id="more-475"></span><br />
All you need to do is (for the user who has lost his Password):</p>
<ol>
<li>Find an Assurer to do an Assurance</li>
<li>Create an A-Word (part of a passphrase)</li>
<li>The Assurer has to trigger the Password Recovery Procedure by sending a signed Email to Support with the A-Word and the info about the Assuree (Name, Primary Email).</li>
</ol>
<p>That&#8217;s it.</p>
<p>Support than will contact the parties to get further informations.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cacert.org/2010/06/475.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>SP to DRAFT &#8212; marks the milestone in Policy!</title>
		<link>http://blog.cacert.org/2010/06/474.html</link>
		<comments>http://blog.cacert.org/2010/06/474.html#comments</comments>
		<pubDate>Sat, 05 Jun 2010 12:07:20 +0000</pubDate>
		<dc:creator>iang</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[Progress]]></category>

		<category><![CDATA[audit]]></category>

		<category><![CDATA[milestone]]></category>

		<category><![CDATA[Policy]]></category>

		<category><![CDATA[policy group]]></category>

		<category><![CDATA[security policy]]></category>

		<guid isPermaLink="false">https://blog.cacert.org/?p=474</guid>
		<description><![CDATA[This weekend, the Security Policy goes into DRAFT.  We&#8217;ve battled and we&#8217;ve won: consensus has erupted in policy group.  Not only do we get our Security Policy, but SP going to DRAFT marks a major milestone for CAcert:
We now have a complete set of policies for audit !
We&#8217;ve been close before, but never [...]]]></description>
			<content:encoded><![CDATA[<p>This weekend, the Security Policy <a href="//wiki.cacert.org/PolicyDecisions#p20100510">goes into DRAFT</a>.  We&#8217;ve battled and we&#8217;ve won: consensus has erupted in policy group.  Not only do we get <a href="//svn.cacert.org/CAcert/Policies/SecurityPolicy.html">our Security Policy</a>, but SP going to DRAFT marks a major milestone for CAcert:</p>
<blockquote><p><b>We now have a complete set of policies for audit <big><i>!</i></big></b></p></blockquote>
<p>We&#8217;ve been close before, but never the cigar.  In early 2009, some audit work was done, but with gaps:  the CPS and the &#8220;index&#8221; were missing.  <a href="//www.cacert.org/policy/CertificationPracticeStatement.php">The CPS</a> came <a href="//wiki.cacert.org/PolicyDecisions#p20090706">into DRAFT in June 2009</a>, it was close enough at the time.  The &#8220;index&#8221; is called the <a href="//svn.cacert.org/CAcert/Policies/ConfigurationControlSpecification.html">Configuration-Control Specification (CCS)</a>, which is a rather clumsy name for such a simple thing.  CCS is a list to all the assets that have to be audited, so it&#8217;s worth a little attention.  The structure more or less looks like this:</p>
<blockquote><p>Audit => Criteria (we call them DRC) => CCS (the index)</p></blockquote>
<p>Then, with CCS in hand, the Auditor can find the parts needed:</p>
<blockquote><pre>
                     --> Policies
                   /
       CCS ==----> critical systems
                   \
                     --> roles in control, etc
</pre>
</blockquote>
<p>CCS was the missing link.  Luckily the index CCS is relatively easy to write, <i>if all the other policies and systems are clear</i>, and this also means it was doomed to always be last, once the other policies were clear.  A month back <a href="//wiki.cacert.org/PolicyDecisions#p20100426">policy group pushed it through</a>, we brought the CCS finally into its place as a (DRAFT) binding policy.</p>
<p>Which should have been the completion of our policy set for audit, but as CCS was finishing, the Board of CAcert Inc decided to veto the Security Policy, as they can under the rules (<a href="//www.cacert.org/policy/PolicyOnPolicy.php">PoP</a> 4.6).  Now, much has been written about this drama in the maillists, and the debate did raise some serious questions at the time, but they can be left for another day.  This week, then we in policy group are taking Security Policy back to DRAFT.  Has anything changed?  Here are the major points of change:</p>
<ol type="a">
<li> The part about the Board Members having a background check has been removed.  This was reasonable, as, on the whole, the ABC process is too clumsy for the Board, and the Board now has its own requirements to deal with conflicts of interest, courtesy of the new Associations Act 2009.</li>
<li> Application Engineer is removed, and that capability is returned to the Systems Adminstration team leader.  T/L can bring in a Software Assessor any time he needs one, and take on that risk, etc.</li>
<li> One non-difference is that SP was still binding on the critical roles, because they accept the SP as their binding document when they are appointed.  This is part of the process, as documented in Security Manual.   The reason for this is that, under the principles of data protection, anyone who can access the data needs a special agreement, and in CAcert, the SP is that agreement.</li>
<li>Meanwhile, SP goes back to being binding on the Community.  Why would the Community need to be bound to Security Policy, when they can&#8217;t do anything wrong anyway?  Well, because there are always errors, holes, bugs, omissions and short cuts.  In any process!  So, while we should fix these omissions, it helps to have the big stick of policy to wield as well.  Just because you find a software bug doesn&#8217;t mean you can exploit it, and just because you have a title like &#8220;auditor&#8221; doesn&#8217;t mean you can stare at the private root key.  We all have wider obligations, and SP is one of them.</li>
</ol>
<p>Other than tighter wording, etc, that&#8217;s it.  Welcome to our complete Policy set!</p>
<p>Which final comment brings us to the success of CAcert&#8217;s Policy project.  It was 5 calendar years in the making, starting off with Christian&#8217;s original CPS, and it cost many Member-Years of effort.  Some examples:  The SP was probably a Member-Year of effort.  The CPS is likely equal, the agreements and foundations (CCA, DRP, PoP, etc) another huge lump.  I said CCS was an easy one to write, but &#8220;easy&#8221; still runs to around a Member-Month of effort.  PoJAM, similar.</p>
<p>If we think how much a commercial company pays for a Member-Year of effort (100k, plus or minus), that&#8217;s a serious investment.</p>
<blockquote><p><b>Thank your policy group, and help out with reading and voting!</b></p></blockquote>
<p>35 decisions, <a href="//svn.cacert.org/CAcert/Policies/ControlledDocumentList.html">13 policies to DRAFT and beyond</a>, 55 contributors.  Here&#8217;s the top ten, a Hall of Fame, collected a wiki-scraping script I wrote last night:</p>
<table>
<tr>
<th>Name</th>
<th>#</th>
<th>Decisions</th>
</tr>
<tr>
<td><a href="https://wiki.cacert.org/Community/HomePagesMembers/TomasTrnka">Tomáš</a></td>
<td>10</td>
<td><small>p20100510,p20100426,p20100401,p20100119,p20100113,p20091108,p20091106,p20090706,p20090327,p20081016</small></td>
</tr>
<tr>
<td><a href="https://wiki.cacert.org/Community/HomePagesMembers/JavierFernandez">Faramir</a></td>
<td>10</td>
<td><small>p20100510,p20100426,p20100401,p20100326,p20100120,p20100119,p20100113,p20091106,p20090706,p20090327</small></td>
</tr>
<tr>
<td><a href="https://wiki.cacert.org/LambertHofstra">Lambert</a></td>
<td>10</td>
<td><small>p20100426,p20100401,p20100326,p20100113,p20091108,p20091106,p20090706,p20090327,p20090105.1,p20081016</small></td>
</tr>
<tr>
<td><a href="https://wiki.cacert.org/PhilippDunkel">Philipp D</a></td>
<td>9</td>
<td><small>p20100510,p20100426,p20100401,p20100113,p20091106,p20090706,p20090327,p20090105.1,p20081016</small></td>
</tr>
<tr>
<td><a href="https://wiki.cacert.org/PieterVanEmmerik">Pieter</a></td>
<td>8</td>
<td><small>p20100510,p20100426,p20100401,p20100306,p20100120,p20100113,p20091106,p20090327</small></td>
</tr>
<tr>
<td><a href="https://wiki.cacert.org/Iang">Iang</a></td>
<td>8</td>
<td><small>p20100510,p20100426,p20100306,p20100120,p20100119,p20100113,p20091106,p20090706</small></td>
</tr>
<tr>
<td><a href="https://wiki.cacert.org/UlrichSchroeter">Ulrich</a></td>
<td>7</td>
<td><small>p20100510,p20100426,p20100401,p20100326,p20100306,p20100120,p20100119</small></td>
</tr>
<tr>
<td><a href="https://wiki.cacert.org/BernhardFr%C3%B6hlich">Ted</a></td>
<td>7</td>
<td><small>p20100510,p20100120,p20100119,p20100113,p20091106,p20090706,p20081016</small></td>
</tr>
<tr>
<td><a href="https://wiki.cacert.org/Community/HomePagesMembers/BrianMcCullough">Brian</a></td>
<td>7</td>
<td><small>p20100510,p20100426,p20100401,p20100119,p20091108,p20091106,p20090706</small></td>
</tr>
<tr>
<td>Morten</td>
<td>6</td>
<td><small>p20100510,p20100426,p20100306,p20100120,p20100119,p20100113</small></td>
</tr>
</table>
<p>(That&#8217;s not a formal result, and it only counts voters from the last 2 years, many others did other things that are harder to measure.)</p>
<p>We now have a set of policies that not only deals with the criteria of the Audit (DRC), not only removes that critical path blockage of documentation for audit, but also presents the only honest, fair, presentable and sustainable policy set in the entire business.  In my humble opinion.</p>
<p>This is a set of documents everyone can be proud of.  On this foundation we can build.  We can, for our Members, create business of real value, not just issue certificates that defy valuation to people who don&#8217;t understand their need.</p>
<p>Now, on to implementation and audit.  Questions about the audit <i>are</i> questions about implementation, so don&#8217;t forget:</p>
<blockquote><p><b>Do not ask when your audit is done, rather, ask how you, yourself, are doing your audit!</b></p></blockquote>
<p>And now, you&#8217;ve got the full policy set, so you know what the Auditor is going to be looking for <img src='http://blog.cacert.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cacert.org/2010/06/474.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>scheduled systems downtime - 15th June</title>
		<link>http://blog.cacert.org/2010/06/473.html</link>
		<comments>http://blog.cacert.org/2010/06/473.html#comments</comments>
		<pubDate>Wed, 02 Jun 2010 08:03:51 +0000</pubDate>
		<dc:creator>iang</dc:creator>
		
		<category><![CDATA[Information]]></category>

		<category><![CDATA[News]]></category>

		<category><![CDATA[critical systems]]></category>

		<category><![CDATA[downtime]]></category>

		<guid isPermaLink="false">https://blog.cacert.org/?p=473</guid>
		<description><![CDATA[Wytze reports on a planned outage for CAcert main systems, as the systems are moved from one rack to another:
&#8220;The move has been scheduled for Tuesday June 15, starting at 10:00 CEST, and hopefully ending before 18:00 CEST.
During a significant part of that period, all systems will be down. We will take care of providing [...]]]></description>
			<content:encoded><![CDATA[<p>Wytze reports on a planned outage for CAcert main systems, as the systems are moved from one rack to another:</p>
<p>&#8220;The move has been scheduled for <strong>Tuesday June 15</strong>, starting at <strong>10:00 CEST</strong>, and hopefully ending before <strong>18:00 CEST</strong>.</p>
<p>During a significant part of that period, all systems will be down. We will take care of providing a backup during the outage for ocsp.cacert.org (to avoid inconveniencing browser users which have OCSP enabled for CAcert, as they should!), and a placeholder for www.cacert.org which report the downtime and the reason for it.&#8221;</p>
<p><img src="http://www.deboca.net/cacert/slide_IMG_1546.JPG" border="0" /></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cacert.org/2010/06/473.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Community 2010 March Update</title>
		<link>http://blog.cacert.org/2010/03/471.html</link>
		<comments>http://blog.cacert.org/2010/03/471.html#comments</comments>
		<pubDate>Wed, 31 Mar 2010 23:33:58 +0000</pubDate>
		<dc:creator>U. Schroeter</dc:creator>
		
		<category><![CDATA[Information]]></category>

		<category><![CDATA[News]]></category>

		<category><![CDATA[Progress]]></category>

		<category><![CDATA[Board Motions]]></category>

		<category><![CDATA[Community]]></category>

		<category><![CDATA[Events]]></category>

		<category><![CDATA[Officers]]></category>

		<category><![CDATA[Policys]]></category>

		<category><![CDATA[Software-Assessment]]></category>

		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">https://blog.cacert.org/?p=471</guid>
		<description><![CDATA[
2010-03-30 New Roots task force offers SHA2 based roots/end user certificates for testing
2010-03-30 Software-Assessment Project telco 2010-03-30

GIT as the future Software Assessment repository passed test successful
Testserver needs Testserver Management System, action plans triggered to start a deployment


2010-03-27 Walter Güldenberg appointed as Events Team Leader
2010-03-26 Sysadmin team works out way forward for SNI, client certificate authentication [...]]]></description>
			<content:encoded><![CDATA[<ul>
<li>2010-03-30 New Roots task force offers <a href="https://lists.cacert.org/wws/arc/cacert/2010-03/msg00029.html">SHA2 based roots/end user certificates for testing</a></li>
<li>2010-03-30 <a href="http://wiki.cacert.org/Software/Assessment/20100330-S-A-MiniTOP-telco">Software-Assessment Project telco 2010-03-30</a>
<ul>
<li>GIT as the future Software Assessment repository passed test successful</li>
<li>Testserver needs Testserver Management System, action plans triggered to start a deployment</li>
</ul>
</li>
<li>2010-03-27 <a href="http://wiki.cacert.org/WalterGueldenberg">Walter Güldenberg</a> appointed as <a href="https://community.cacert.org/board/motions.php?motion=m20100327.1">Events Team Leader</a></li>
<li>2010-03-26 Sysadmin team works out <a href="https://lists.cacert.org/wws/arc/cacert-sysadm/2010-03/msg00014.html">way forward</a> for SNI, client certificate authentication and SSL renegotiation changes in browsers</li>
<li>2010-03-26 Security Policy - Board <a href="https://community.cacert.org/board/motions.php?motion=m20100327.2">vetos</a> Security Policy Draft regarding point 9.1.4.2. Coverage - Board sighting conflicts with CAcert incorporated rules</li>
<li>2010-03-25 Ongoing update of CAcert <a href="http://wiki.cacert.org/Officers">Officers list</a></li>
<li>2010-03-24 First ATE in 2010 season: <a href="http://wiki.cacert.org/events/20100324Sydney">ATE-Sydney</a> with 6 co-Audited Assurances and addtl. 14 interested Attendees
<ul>
<li>Discussions through email and irc about how to seed CAcert deserts. Plans for contacting Usergroups (existing IT related social networks)</li>
<li>mostly, area has many old SuperAssurers that will have faded away</li>
</ul>
</li>
<li>2010-03-21 <a href="http://wiki.cacert.org/Brain/CAcertInc/Committee/MeetingAgendasAndMinutes/20100321">Board Meeting 2010-03-21</a> &#8220;Determine Root escrow and recovery mechanism&#8221; review ends with no consensus</li>
<li>2010-03-18 Rasika Dayarathna, our Privacy Officer, resigned due to lack of time. Looking forward to rejoining us later.</li>
<li>2010-03-14 <a href="http://wiki.cacert.org/OverviewProjectsBoard">Boards Projects Overview Page</a> started deployment
<ul>
<li>with this page, Board and also Community can get a better overview over the running and upcoming projects regarding Audit</li>
<li>currently active areas/projects:
<ul>
<li>1.1 <a href="http://wiki.cacert.org/Software/Assessment">Software Assessment</a></li>
<li>2.1 <a href="http://wiki.cacert.org/Roots/EscrowAndRecovery">New Root</a></li>
<li>7.1 <a href="https://lists.cacert.org/wws/arc/cacert-policy/2010-03/">Policy Group</a></li>
<li>8.1 Assurance (co-Audit)</li>
<li>9.2 <a href="http://wiki.cacert.org/comma/RegularCampaigns/AssurerEvents/AssurerTrainingEvents">ATE&#8217;s</a> (planning)</li>
</ul>
</li>
</ul>
</li>
<li>2010-03-13 Board Members allowed to <a href="https://community.cacert.org/board/motions.php?motion=m20100309.2">serve on arbitration team</a> again</li>
<li>2010-03-06 <a href="http://wiki.cacert.org/DanielBlack">Daniel Black</a> gets <a href="https://community.cacert.org/board/motions.php?motion=m20100309.3">appointed</a> as Infrastructure Team Leader</li>
<li>2010-03-06 Efficiency gain - <a href="http://wiki.cacert.org/PolicyDecisions#p20100306">Policy Officer empowered</a> to perform minor adjustments to policy</li>
<li>2010-03-06 <a href="http://wiki.cacert.org/events/Cebit2010">CeBIT 2010</a> Big Assurance Event successful passed after 5 days with a team of about 8 to 12 and more Assurers. CAcert was one of the 15 projects on the booth at the Open Source Project Lounge sponsored by Linux New Media.</li>
<li>2010-03-03 Co-Audited Assurances Program finalized and starts at <a href="http://wiki.cacert.org/events/Cebit2010">CeBIT 2010</a></li>
</ul>
<p>Contributions to this Community Update by: Ian, Daniel, Uli</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.cacert.org/2010/03/471.html/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
