OASIS Open Mailing List Archives  ·  All Lists  ·  dss-x  ·  2008-03

dss-x — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Some more thoughts concerning the legal aspects


Hi Pim, in Germany there are no stipulations for the strength of the authentication. Hence even UID/password is fine (with respect to the law). As the legal construction in this case may be interpreted that the DSS-server signs on behalf of the client, who provides the DSS-server (explicitly or implicitely) with a power of attorney (cf. Section 2 of http://www.ecsec.de/pub/2004_PKI.pdf) and the creation of a power of attorney (in German law) does not need to have a specific form, there probably can not be stipulations in general. BR, Detlef > ----- Ursprüngliche Nachricht ----- > Von: Pim van der Eijk [mailto:[email protected]] > Gesendet: Donnerstag, 6. März 2008 09:16 > An: 'Ezer Farhi'; Huehnlein, Detlef > Cc: [email protected] > Betreff: [dss-x] RE: Some more thoughts concerning the legal aspects > > > Hello Ezer and Detlef, > > In countries that do support server-based signing with > qualified signatures, what are the (minimum) requirements for > user authentication? > > Pim > >

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]