<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for jwiltshire.org.uk</title>
	<atom:link href="http://www.jwiltshire.org.uk/content/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jwiltshire.org.uk/content</link>
	<description>The public face of jwiltshire</description>
	<lastBuildDate>Fri, 24 Jun 2011 20:44:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on StartSSL: finally, a trustworthy certifier* by Brad</title>
		<link>http://www.jwiltshire.org.uk/content/2011/06/13/startssl-finally-a-trustworthy-certifier/comment-page-1/#comment-3322</link>
		<dc:creator>Brad</dc:creator>
		<pubDate>Fri, 24 Jun 2011 20:44:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.jwiltshire.org.uk/content/?p=312#comment-3322</guid>
		<description>They&#039;re back up, no false certs issued or private keys stolen.  more info here.

http://www.theregister.co.uk/2011/06/21/startssl_security_breach/

amazing to me how little the company bothered to communication their situation.  I have a class2 cert with them and would certainly want their assurance that docs I provided them were not compromised / stolen etc.</description>
		<content:encoded><![CDATA[<p>They&#8217;re back up, no false certs issued or private keys stolen.  more info here.</p>
<p><a href="http://www.theregister.co.uk/2011/06/21/startssl_security_breach/" rel="nofollow">http://www.theregister.co.uk/2011/06/21/startssl_security_breach/</a></p>
<p>amazing to me how little the company bothered to communication their situation.  I have a class2 cert with them and would certainly want their assurance that docs I provided them were not compromised / stolen etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on StartSSL: finally, a trustworthy certifier* by Corsac</title>
		<link>http://www.jwiltshire.org.uk/content/2011/06/13/startssl-finally-a-trustworthy-certifier/comment-page-1/#comment-3317</link>
		<dc:creator>Corsac</dc:creator>
		<pubDate>Tue, 21 Jun 2011 06:35:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.jwiltshire.org.uk/content/?p=312#comment-3317</guid>
		<description>Hmhm, advertising StartSSL might not have been a good idea, they&#039;ve just been compromised:

Due to a security breach that occurred at the 15th of June, issuance of digital certificates and related services has been suspended. Our services will remain offline until further notice.

Subscribers and holders of valid certificates are not affected in any form.

Visitors to web sites and other parties relying on valid certificates are not affected.

We apologize for the temporary inconvenience and thank you for your understanding.</description>
		<content:encoded><![CDATA[<p>Hmhm, advertising StartSSL might not have been a good idea, they&#8217;ve just been compromised:</p>
<p>Due to a security breach that occurred at the 15th of June, issuance of digital certificates and related services has been suspended. Our services will remain offline until further notice.</p>
<p>Subscribers and holders of valid certificates are not affected in any form.</p>
<p>Visitors to web sites and other parties relying on valid certificates are not affected.</p>
<p>We apologize for the temporary inconvenience and thank you for your understanding.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on StartSSL: finally, a trustworthy certifier* by Kint</title>
		<link>http://www.jwiltshire.org.uk/content/2011/06/13/startssl-finally-a-trustworthy-certifier/comment-page-1/#comment-3316</link>
		<dc:creator>Kint</dc:creator>
		<pubDate>Mon, 20 Jun 2011 22:43:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.jwiltshire.org.uk/content/?p=312#comment-3316</guid>
		<description>http://www.h-online.com/security/news/item/Attack-on-Israeli-Certificate-Authority-1264008.html</description>
		<content:encoded><![CDATA[<p><a href="http://www.h-online.com/security/news/item/Attack-on-Israeli-Certificate-Authority-1264008.html" rel="nofollow">http://www.h-online.com/security/news/item/Attack-on-Israeli-Certificate-Authority-1264008.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on StartSSL: finally, a trustworthy certifier* by Ben</title>
		<link>http://www.jwiltshire.org.uk/content/2011/06/13/startssl-finally-a-trustworthy-certifier/comment-page-1/#comment-3312</link>
		<dc:creator>Ben</dc:creator>
		<pubDate>Tue, 14 Jun 2011 20:59:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.jwiltshire.org.uk/content/?p=312#comment-3312</guid>
		<description>To clarify a bit what Jon said, you only need to verify a domain in order to get a certificate for that domain, and you may wait up to 30 days after verifying a domain before requesting a certificate. After 30 days you will need to re-verify your domain if you haven&#039;t gotten a certificate for it yet, but you don&#039;t need to if you already got one.

From what I could tell, you can only get one certificate per (verified) domain, e-mail address...but I may have missed something.</description>
		<content:encoded><![CDATA[<p>To clarify a bit what Jon said, you only need to verify a domain in order to get a certificate for that domain, and you may wait up to 30 days after verifying a domain before requesting a certificate. After 30 days you will need to re-verify your domain if you haven&#8217;t gotten a certificate for it yet, but you don&#8217;t need to if you already got one.</p>
<p>From what I could tell, you can only get one certificate per (verified) domain, e-mail address&#8230;but I may have missed something.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on StartSSL: finally, a trustworthy certifier* by Jon</title>
		<link>http://www.jwiltshire.org.uk/content/2011/06/13/startssl-finally-a-trustworthy-certifier/comment-page-1/#comment-3311</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Tue, 14 Jun 2011 13:08:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.jwiltshire.org.uk/content/?p=312#comment-3311</guid>
		<description>Asheesh, sure. The process is:
 - undergo Class 2 identify verification and pay the fee
 - for each domain, verify it by getting a code by email
 - within thirty days issue one or more certificates for that domain (you can mix domains on the same certificate)

Repeat steps 2 and 3 for a year.</description>
		<content:encoded><![CDATA[<p>Asheesh, sure. The process is:<br />
 &#8211; undergo Class 2 identify verification and pay the fee<br />
 &#8211; for each domain, verify it by getting a code by email<br />
 &#8211; within thirty days issue one or more certificates for that domain (you can mix domains on the same certificate)</p>
<p>Repeat steps 2 and 3 for a year.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on StartSSL: finally, a trustworthy certifier* by Philipp Kern</title>
		<link>http://www.jwiltshire.org.uk/content/2011/06/13/startssl-finally-a-trustworthy-certifier/comment-page-1/#comment-3308</link>
		<dc:creator>Philipp Kern</dc:creator>
		<pubDate>Tue, 14 Jun 2011 08:09:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.jwiltshire.org.uk/content/?p=312#comment-3308</guid>
		<description>But I&#039;d really need to pay 60 USD every year?  Mhhh… ):

(Yes, I know that&#039;s much less than other CAs want, given enough certificates issues.  Except for CAcert…)</description>
		<content:encoded><![CDATA[<p>But I&#8217;d really need to pay 60 USD every year?  Mhhh… ):</p>
<p>(Yes, I know that&#8217;s much less than other CAs want, given enough certificates issues.  Except for CAcert…)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on StartSSL: finally, a trustworthy certifier* by Asheesh Laroia</title>
		<link>http://www.jwiltshire.org.uk/content/2011/06/13/startssl-finally-a-trustworthy-certifier/comment-page-1/#comment-3307</link>
		<dc:creator>Asheesh Laroia</dc:creator>
		<pubDate>Tue, 14 Jun 2011 01:30:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.jwiltshire.org.uk/content/?p=312#comment-3307</guid>
		<description>&quot;Being verified once and then issuing as many certificates as I need&quot; seems really useful to me. Can you explain more about the process for doing that?

I tried to find it on the StartCom website, but actually had some trouble.</description>
		<content:encoded><![CDATA[<p>&#8220;Being verified once and then issuing as many certificates as I need&#8221; seems really useful to me. Can you explain more about the process for doing that?</p>
<p>I tried to find it on the StartCom website, but actually had some trouble.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Privacy specialists should hire security specialists by Chris</title>
		<link>http://www.jwiltshire.org.uk/content/2011/03/02/privacy-specialists-should-hire-security-specialists/comment-page-1/#comment-3226</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Mon, 11 Apr 2011 23:29:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.jwiltshire.org.uk/content/?p=289#comment-3226</guid>
		<description>AFCAIT you&#039;ve covered all the bases with this answer!</description>
		<content:encoded><![CDATA[<p>AFCAIT you&#8217;ve covered all the bases with this answer!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A little civil disobedience by Jon</title>
		<link>http://www.jwiltshire.org.uk/content/2011/03/27/a-little-civil-disobedience/comment-page-1/#comment-3192</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Sun, 27 Mar 2011 22:50:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.jwiltshire.org.uk/content/?p=308#comment-3192</guid>
		<description>Excellent! I defy any census staff to first penetrate the door of my shared building, and then find me at home...</description>
		<content:encoded><![CDATA[<p>Excellent! I defy any census staff to first penetrate the door of my shared building, and then find me at home&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A little civil disobedience by Ker</title>
		<link>http://www.jwiltshire.org.uk/content/2011/03/27/a-little-civil-disobedience/comment-page-1/#comment-3191</link>
		<dc:creator>Ker</dc:creator>
		<pubDate>Sun, 27 Mar 2011 22:42:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.jwiltshire.org.uk/content/?p=308#comment-3191</guid>
		<description>It will get classed as an incomplete or blank form and you wil receive a home visit from census staff. Can you really be bothered with that? I&#039;d rather get mine complete, sent, and never be bothered with it again... for ten years anyway.</description>
		<content:encoded><![CDATA[<p>It will get classed as an incomplete or blank form and you wil receive a home visit from census staff. Can you really be bothered with that? I&#8217;d rather get mine complete, sent, and never be bothered with it again&#8230; for ten years anyway.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

