Comment by layer8
5 hours ago
See eIDAS annexes I to III: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
Certificates must be issued by qualified trust service providers (see section 3 for their requirements) who verify the identity of the certificate holder and ensure that the holder has sole control over the certified key. Among other things, this generally means that the key must be held in a certified HSM or smart card/USB key.
The provider infrastructure is subject to supervision of the EU member states, who accredit bodies that perform the conformity assessments.
The main purpose of all this is to ensure that the four requirements listed in article 26 are met:
"An advanced electronic signature shall meet the following requirements:
(a) it is uniquely linked to the signatory;
(b) it is capable of identifying the signatory;
(c) it is created using electronic signature creation data [private key] that the signatory can, with a high level of confidence, use under his sole control; and
(d) it is linked to the data signed therewith in such a way that any subsequent change in the data is detectable."
Let's Seal could attempt to argue that they do ensure these requirements, but their "control of a domain" scheme is unlikely to clear that bar, and they probably also don't secure their signing infrastructure in a way that would be deemed sufficient.
No comments yet
Contribute on Hacker News ↗