česky | deutsch | english | français
More Points, More Privileges
Information
What can CAcert provide to you, to increase your privacy and security for free?
Level |
Description |
Points |
CATS passed |
Client certificates (un-assured) |
Benefits: You can send digitally signed/encrypted emails; others can send encrypted emails to you. |
AP: 0-49 |
./. |
Limitations: Certificates expire in 6 months. Only the email address itself can be entered into the certificate (not your full name). |
|||
Verification needed: You must confirm it is your email address by responding to a 'ping' email sent to it. |
|||
Client certificates (assured) |
Benefits: Same as above plus you can include your full name in the certificates. |
AP: 50-100 |
./. |
Limitations: Certificates expire in 24 months. (**) |
|||
Verification needed: Same as above, plus you must get a minimum of 50 assurance points by meeting with at least two or more assurers from the CAcert Web of Trust, who verify your identity using your government issued photo identity documents. |
|||
Code signing certificates |
Benefits: Digitally sign code, web applets, installers, etc. including your name and location in the certificates. |
AP: 100 |
Yes |
Limitations: Certificates expire in 12 months. Certificates must include your full name. |
|||
Verification needed: 100 assurance points + 0 or more experience points by meeting with multiple assurers from the CAcert Web of Trust, who verify your identity using your government issued photo identity documents, become an assurer, CATS passed |
|||
Server certificates (un-assured) |
Benefits: Enable encrypted data transfer for users accessing your web, email, or other SSL enabled service on your server; wildcard certificates are allowed. |
AP: 0-49 |
./. |
Limitations: Certificates expire in 6 months; only the domain name itself can be entered into the certificates (not your full name, company name, location, etc.). |
|||
Verification needed: You must confirm that you are the owner (or authorized administrator) of the domain by responding to a 'ping' email sent to either the email address listed in the whois record, or one of the RFC-mandatory addresses (hostmaster/postmaster/etc). |
|||
Server certificates (assured) |
Benefits: Same as above. |
AP: 50-100 |
./. |
Limitations: Same as above, except certificates expire in 24 months. (**) |
|||
Verification needed: Same as above, plus get at least 50 assurance points by meeting with assurer(s) from the CAcert Web of Trust, who verify your identity using your government issued photo identity documents. |
|||
Become an assurer in CAcert Web of Trust |
Benefits: The ability to assure other new CAcert users; contribute to the strengthening and broadening of the CAcert Web of Trust. |
AP: 100 |
Yes |
Limitations: The number of experience point you have will limit the maximum assurance points you can issue for people you assure. |
|||
Verification needed: You will need to be issued 100 assurance points by meeting with existing assurers from the CAcert Web of Trust, who verify your identity using your government issued photo identity documents. Passing CATS |
|||
Become an |
Benefits: The ability to issue the maximum of assurance points -> 35 AP |
AP: 100 |
Yes |
Limitations: maximum assurance points you can issue limited by AP. |
|||
Verification needed: You will need to be issued 50 experience points, passed CATS |
|||
Become a |
Benefits: The ability to train new CAcert assurers; contribute to the TTP and Co-Audit programs for strenghening and broadening the CAcert Web of Trust. |
AP: 100 |
Yes |
Limitations: maximum assurance points you can issue limited by AP. |
|||
Verification needed: You will need to be issued 50 experience points, has been co-audited, attended an ATE, knows about CARS, passed CATS |
|||
Become a member of the CAcert Association |
Benefits: You get a vote in how CAcert (a non-profit association incorporated in Australia) is run; be eligible for positions on the CAcert board. |
./. |
./. |
Limitations: None, the sky is the limit for CAcert. |
|||
Verification needed: None; $10 USD per year membership fee. |
- (*) Please note a general limitation is that, unlike long-time players like Verisign, CAcert's root certificate is not included by default in mainstream browsers, email clients, etc. This means people to whom you send encrypted email, or users who visit your SSL-enabled web server, will first have to import CAcert's root certificate, or they will have to agree to pop-up security warnings (which may look a little scary to non-techy users).
- (**) Certificates issued under the Organisation Assurance program are valid for 12 months
