next up previous contents
Next: Certificates Signed by Untrusted Up: Visible Changes Previous: Visible Changes

New Certificate Authority process

The decision on whether or not to accept a new certificate authority is very important as it may affect the perceived security of many sites. When we first receive the new authority's certificate, lynx-cert must present a screen, similar to the options screen, to configure the trust parameters of the CA. Whatever trust parameter the user chooses will then stored, along with the certificate.

The following text will be used.

                                        Lynx Certificate Retrieval

        You have reached the Lynx Certificate Retrieval page

You have just downloaded a certificate for an unknown Certificate
Authority (CA). A Certificate Authority issues signed certificates
which are used to authenticate both sites and users. When you accept a
Certificate Authority, you are trusting it to correctly verify the
identity of the name listed in the certificates it signs. If you agree
to trust this authority, you will by default connect to sites which
present certificates signed by it silently. If you do not, you will be
prompted for confirmation when you access a site with a certificate
signed by this CA.

                                                [continue]

                                        Lynx Certificate Retrieval

This is the certificate you have just downloaded ....

    MIT Certification Authority
          Subject: C=US, SP=Massachusetts, O=Massachusetts Institute
                of Technology, OU=MIT Certification Authority
          Issuer: C=US, SP=Massachusetts, O=Massachusetts Institute
                of Technology, OU=MIT Certification Authority
          Serial Number: 00
          This Certificate is valid after Mon Jul 15, 1996
                               but before Thu Jul 13, 2006
          Fingerprint: BB:43:9C:06:0A:2C:A2:EC:BB:65:83:E5:E0:84:B8:C6

Do you wish to accept this certifying authority?
     [no] [yes]

Note: regardless of whether or not you choose to trust the CA, lynx
will store the certificate and your preference for future
reference.



Team Athena