[Previous] [Next] [Index] [Thread]

RE: SSL and certificates

On Wed, 28 Aug 1996, Michael Brennen wrote:

>For a commercial application you will need to use ViaCrypt PGP.  There are
>versions for Windows, Mac and many different flavors of Unix.  They don't
>give out source; all distributions are binary. 
>One major reason for using PGP is the simplicity of key management.  In
>DES or IDEA you need a secure channel to exchange keys.  With PGP, key
>management becomes much simpler. 

I believe that this is the major reason for not using PGP for this type 
of application.  The trust model is not solid enough.  Trusted CAs are required!

