SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Entrust offers certificate technology to Mozilla

Entrust offers certificate technology to Mozilla

By:  Mari-Len De Guzman  On: 24 Jul 2007 For: ComputerWorld Canada Creator

The security vendor hopes to encourage open source users to incorporate CRL-DP capability to their PKI development plans. Just watch out for any "field use" clauses in the licensing

Also visit our blog pages to read and comment on: The landmine of P2P file sharing

Information security vendor Entrust Inc. has released code to its patented certificate revocation list distribution points (CRL-DP) technology to open source group Mozilla Foundation in a bid to further increase uptake of its PKI product, an Entrust executive said.

“What we wanted to do is promulgate (the CRL-DP capability) and get it out there as much as possible so we elected to make this technology available to the open source community so they can use it,” explained Kevin Simzer, senior vice-president at Addison, Tex.-based Entrust on Wednesday.

“Then when a customer wants to buy PKI, hopefully they will pick Entrust because we have that capability built into our product,” he added.

The Entrust executive also said the move will allow open source users to build “more scalable” PKI environments by having access to the CRL-DP code. A certificate revocation list tracks users’ security credentials and associated rights.

Entrust’s CRL-DP technology allows an enterprise IT administrator to efficiently manage the increasing number of revoked or invalid digital certificates from users, said Simzer.

Under a royalty-free Mozilla Public Licence, the GNU GPL and Lesser GPL, Entrust will contribute its CRL-DP code to Mozilla’s Network Security Services (NSS) libraries, allowing open source users to incorporate CRL-DP capability to their PKI developments.

NSS is a set of libraries designed to support cross-platform development of security-enabled client and server applications, which can support secure sockets layer (SSL) v2 and v3, transport layer security and other security standards.

Simzer said Entrust’s CRL-DP is currently the only certificate revocation list distribution feature within the NSS libraries. In a statement, Frank Hecker, executive director of the Mozilla Foundation said incorporating the CRL-DP capability into the existing NSS libraries will “significantly elevate the value of the PKI-enabled applications that use these libraries.”

“Secure technology like PKI is too important no to provide to the open-source community,” he said.

One open source enthusiast, however, was not quick to applaud the Entrust move.

“It’s hard to tell, just from the press release, some of the legal fine prints,” said Russell McOrmond, policy coordinator for Ottawa-based Canadian Association for Open Source.

He added that the open source community should look at the specific “field of use” clause associated with Entrust’s contribution.

“There have been attempts before to make software available to a specific open source community, but not the entire open source community, and it turns out that that legal fine print makes it not very workable,” said McOrmond.


Sign up for our Newsletters












Print |  Views: 1423   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Mari-Len De Guzman Mari-Len De Guzman is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Entrust adds layered security to Exchange Server
Entrust adds layered security to Exchange ServerSecurity vendor Entrust Inc. offers components of its security model to enhance Microsoft Exchange Server 2007
Open source insecurities: Get past the myth
Open source insecurities: Get past the mythSome users are still wary about deploying software that isn’t based on proprietary technologies. Experts explain why threat protection goes beyond code
Citrix-XenSource deal raises open source questions
Citrix-XenSource deal raises open source questionsThe virtualization market may get some stronger competition, but developers may resent the technology being co-opted by a larger conglomerate of proprietary company. Gartner, Novell and others react
Open Invention Network builds a future around open source
meet keith bergelt, ceo of the open invention network (oin), a collaborative enterprise that enables innovation in open source and seeks to build a vibrant ecosystem around linux. bergelt spoke to computerworld canada about open source’s future, the economic benefits of fostering open source development, and oin’s goals moving forward.(v
VIDEO: Google exec clarifies Chrome questions
highlights from google’s mobile engineering manager alex nicolaou’s keynote speech on chrome and the chromium.org open source project at ibm’s cascon 2008 conference in richmond hill, ontario. (video runs approx. 5 minutes)
Entrust claims its SSL is secure
entrust inc. has announced its secure sockets layer certificates are not affected by a security hole discovered last month at the chaos communication congress.on dec. 30, a team of european researchers demonstrated they were able to exploit a weakness in the md

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.