On Thu, Mar 10, 2011 at 12:11:01AM +0100, Melvin Carvalho wrote:
> On 10 March 2011 00:02, Jonas Smedegaard <dr at jones.dk> wrote:
> > On Wed, Mar 09, 2011 at 10:29:06PM +0000, Clint Adams wrote:
> Traditionally we've always 'self signed' our WebID certificates.  So
> there's no CA that needs to be in the loop.  In fact, I dont know of
> any instance WebID has *ever* been used with a CA, but I suppose it is
> possible too. :)

Then how does the authentification part works? Is there a web of trust, or
a way to be sure a X.509 cert belongs to a certain ID?


