PKI 的证书颁发机构

发布于 2024-10-21 13:59:40 字数 1459 浏览 8 评论 0原文

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(2

最单纯的乌龟 2024-10-28 13:59:40

首先,我建议这个问题更适合 http://security.stackexchange.com

这一切都取决于您信任的人。有些组织会信任政府,而有些组织肯定不会。有些人会信任银行扮演这个角色,但竞争对手会信任他们吗?我见过许多银行建立自己的 PKI 或使用 PKI 供应商 - 并且根 CA 生成和存储的物理安全要求非常詹姆斯·邦德!

针对您的具体情况,请考虑您的需求、信任要求和风险。哪个 PKI 提供商最有可能满足您的需求?他们的灾难恢复和业务连续性计划是如何构建的 - 这符合您的要求吗?他们如何防止根 CA 受到损害?

First off, I would suggest this question is much more suited to http://security.stackexchange.com

It all comes down to who you trust. Some organisations will trust government, while some definitely won't. Some will trust a bank in this role, but would a competitor trust them? I have seen many banks set up their own PKIs or use a PKI vendor - and the physical security requirements around root CA generation and storage are very James Bond!

For your specific situation, look at your needs, trust requirements and risk. What PKI provider is most likely to match your needs? How is their disaster recovery and business coninuity plan structured - does this match your requirements? How do they prevent compromise of the root CA?

挽心 2024-10-28 13:59:40

证书颁发机构的主要问题是它应该强制所有用户的信任。

考虑到根证书是信任的基础,如果这里有政府,其对该国家/地区居民的固有权力会影响证书的信任,因为居民将无法辩称他不信任其国家/地区。外交担当对外信任的接力棒。

银行和公司没有这种“自动”信任。顺便说一句,他们在证书交付和管理方面可能执行的策略可能是关于使用中立性的关键问题。

我希望它能澄清你的问题。

The major problem with the Certificate Authority is that it should enforce the Trust of ALL the users.

Considering that the root certificate is the base of the trust, if you have a government here, its inherent authority over the resident of that country influence the trust of the certificate as a resident would not be able to argue he does not trust its country. The diplomacy take the relay for the trust outside the country.

Banks and corporation does not have this "automatic" trust. And by the way, the policies they may enforce on Certificate delivery and management may be a critical problem regarding the neutrality of the usages.

I hope it clarifies a bit your question.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文