# CAcert.org

> Mediated Wiki article. Canonical URL: https://mediated.wiki/source/CAcert.org
> Markdown URL: https://mediated.wiki/source/CAcert.org.md
> Source: https://en.wikipedia.org/wiki/CAcert.org
> Source revision: 1356426489
> License: Creative Commons Attribution-ShareAlike 4.0 International (https://creativecommons.org/licenses/by-sa/4.0/)

**CAcert.org** is a community-driven [certificate authority](/source/Certificate_authority) that issues free [X.509](/source/X.509) [public key certificates](/source/Public_key_certificate).[1] CAcert.org relies heavily on automation and therefore issues only [Domain-validated certificates](/source/Domain-validated_certificate) (and not [Extended validation](/source/Extended_Validation_Certificate) or [Organization Validation](/source/Organization_Validation_Certificate) certificates).

These certificates can be used to [digitally sign](/source/Digital_signature) and [encrypt](/source/Encrypt) [email](/source/Email_encryption); encrypt [code](/source/Code_signing) and documents; and to authenticate and authorize user connections to websites via [TLS/SSL](/source/Transport_Layer_Security).

## CAcert Inc. Association

On 24 July 2003, Duane Groth incorporated **CAcert Inc.** as a non-profit association registered[2] in [New South Wales](/source/New_South_Wales), [Australia](/source/Australia) and after, in September 2024, moved to Europe in Geneva, [Switzerland](/source/Switzerland). CAcert Inc runs **CAcert.org**—a community-driven certificate authority.

In 2004, the Dutch Internet pioneer [Teus Hagen](/source/Teus_Hagen) became involved. He served as board member and, in 2008, as a president.[3]

## Certificate Trust status

CAcert.org's [root certificates](/source/Root_certificate) are not included in the most widely deployed certificate stores[4] and has to be added by its customers.[5] As of 2021, most [browsers](/source/Web_browser), [email clients](/source/Email_client), and [operating systems](/source/Operating_system) do not automatically trust certificates issued by CAcert. Thus, users receive an "untrusted certificate" warning upon trying to view a website providing [X.509](/source/X.509) certificate issued by CAcert, or view emails authenticated with CAcert certificates in [Microsoft Outlook](/source/Microsoft_Outlook), [Mozilla Thunderbird](/source/Mozilla_Thunderbird), etc. CAcert uses its own certificate on its website.

### Web browsers

Discussion for inclusion of CAcert root certificate in [Mozilla Application Suite](/source/Mozilla_Application_Suite) and [Mozilla Firefox](/source/Mozilla_Firefox) started in 2004. [Mozilla](/source/Mozilla) had no [CA](/source/Certificate_authority) certificate policy at the time. Eventually, Mozilla developed a policy which required CAcert to improve their management system and conduct [audits](/source/Audit). In April 2007, CAcert formally withdrew its application for inclusion in the Mozilla root program.[6] At the same time, the [CA/Browser Forum](/source/CA/Browser_Forum) was established to facilitate communication among browser vendors and Certificate Authorities. Mozilla's advice was incorporated into "baseline requirements" used by most major browser vendors. Progress towards meeting these requirements can hardly be expected in the near future.[6]

### Operating systems

[FreeBSD](/source/FreeBSD) included CAcert's root certificate but removed it in 2008, following [Mozilla's](/source/Mozilla) policy.[7] In 2014, CAcert was removed from [Ubuntu](/source/Ubuntu),[8] [Debian](/source/Debian),[9] and [OpenBSD](/source/OpenBSD)[10] root stores. In 2018, CAcert was removed from [Arch Linux](/source/Arch_Linux).[11]

As of Feb 2022, the following operating systems or distributions include the CAcert root certificate by default:[12]

- [FreeWRT](/source/FreeWRT)
- [GRML](/source/Grml)
- [Knoppix](/source/Knoppix)
- [Mandriva Linux](/source/Mandriva_Linux)
- [MirOS BSD](/source/MirOS_BSD)
- [Openfire](/source/Openfire)
- Privatix
- [Replicant](/source/Replicant_(operating_system)) (Android)

As of 2021, the following operating systems or distributions have an optional package with the CAcert root certificate:[12]

- [Arch Linux](/source/Arch_Linux)
- [Debian](/source/Debian)[13]
- [Gentoo](/source/Gentoo_Linux) (app-misc/ca-certificates only when USE flag cacert is set, defaults OFF from version 20161102.3.27.2-r2 )
- [openSUSE](/source/OpenSUSE)

## Web of trust

Main article: [Web of trust](/source/Web_of_trust)

To create higher-trust certificates, users can participate in a web of trust system whereby users physically meet and verify each other's identities.[14][15] CAcert maintains the number of **assurance points** for each account. Assurance points can be gained through various means, primarily by having one's identity physically verified by users classified as "Assurers".

Having more assurance points allows users more privileges such as writing a name in the certificate and longer expiration times on certificates. A user with at least 100 assurance points is a Prospective Assurer, and may—after passing an Assurer Challenge[16]—verify other users; more assurance points allow the Assurer to assign more assurance points to others.

CAcert sponsors [key signing parties](/source/Key_signing_party), especially at big events such as [CeBIT](/source/CeBIT) and [FOSDEM](/source/FOSDEM).

As of 2021, CAcert's web of trust has over 380,000 verified users.[17]

## Root certificate descriptions

Since October 2005, CAcert offers Class 1 and Class 3 root certificates. Class 3 is a high-security subset of Class 1.[18]

## See also

- [Let's Encrypt](/source/Let's_Encrypt)
- [CAcert wiki](http://wiki.cacert.org/)

## Further reading

- Smith, Curtis (25 September 2006). *Pro Open Source Mail: building an enterprise mail solution*. Berkeley, Calif.: Apress. p. 132. ISBN 978-1-59059-598-5. [OCLC 255341703](https://www.worldcat.org/oclc/255341703)
- Herong, Yang (2020). ["PKI Tutorials - Herong's Tutorial Examples"](https://www.herongyang.com/PKI/)

## References

1. ["FAQ/AboutUs - CAcert Wiki"](http://wiki.cacert.org/FAQ/AboutUs). *wiki.cacert.org*. Retrieved September 24, 2019.

1. ["CAcertInc - CAcert Wiki"](http://wiki.cacert.org/CAcertInc?action=show&redirect=Brain%2FCAcertInc). *wiki.cacert.org*. Retrieved September 24, 2019.

1. ["NLnet; Teus Hagen"](https://nlnet.nl/people/TeusHagen/). *nlnet.nl*. Retrieved September 24, 2019.

1. Oppliger, Rolf (2014). *Secure Messaging on the Internet.*. Boston/London: Artech House. p. 171. ISBN 978-1-60807718-2. [OCLC 9227277768](https://www.worldcat.org/oclc/9227277768)

1. Turnbull, James; Matotek, Dennis; Lieverdink, Peter (2009). *Pro Linux System Administration*. Apress. p. 474. ISBN 978-1-43021913-2.

1. ["215243 - CAcert root cert inclusion into browser"](https://bugzilla.mozilla.org/show_bug.cgi?id=215243). *bugzilla.mozilla.org*. Retrieved September 24, 2019.

1. FreeBSD Security Officer (29 June 2008). ["ca-roots"](http://www.freshports.org/security/ca-roots/). *FreshPorts*. Retrieved 16 December 2013. The ca_root_ns port basically makes no guarantees other than that the certificates comes from the Mozilla project.

1. Luke Faraone (5 December 2013). ["CAcert should not be trusted by default"](https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/1258286). *Ubuntu Launchpad Bug report logs*. Retrieved 14 March 2014.

1. Jake Edge (March 18, 2014). ["Debian and CAcert"](https://lwn.net/Articles/590879/). [LWN.net](/source/LWN.net)

1. Henderson, Stuart (9 April 2014). ["CVS: cvs.openbsd.org: src"](https://marc.info/?l=openbsd-cvs&m=139705404731140). Retrieved 8 September 2019. – via [MARC](/source/MARC_(archive))

1. ["FS#59690 : \[ca-certificates\] Reconsider CAcert inclusion"](https://bugs.archlinux.org/task/59690). *bugs.archlinux.org*. Retrieved September 24, 2019.

1. ["CAcert inclusion status page"](https://web.archive.org/web/20210508183356/http://wiki.cacert.org/InclusionStatus). *cacert.org*. Archived from [the original](http://wiki.cacert.org/InclusionStatus) on 2021-05-08. Retrieved 2021-04-24.

1. ["Debian -- Details of package ca-cacert in sid"](https://packages.debian.org/sid/ca-cacert). Retrieved 1 January 2016.

1. Butcher, Matt (2007). *Mastering OpenLDAP: Configuring, Securing, and Integrating Directory Services.*. Birmingham, UK: Packt Publishing. ISBN 978-1-84719103-8. [OCLC 488331349](https://www.worldcat.org/oclc/488331349)

1. Burns, Bryan; Killion, Dave; Beauchesne, Nicolas (2007). *Security Power Tools*. O'Reilly Media. p. 512. ISBN 978-059655481-1.

1. [Assurance Policy](http://www.cacert.org/policy/AssurancePolicy.php), section 2.3.

1. ["Welcome to CAcert.org"](http://www.cacert.org/stats.php). *www.cacert.org*. [Archived](https://web.archive.org/web/20050204070956/http://www.cacert.org:80/stats.php) 2005-02-04 at the Wayback Machine. Retrieved April 24, 2021.

1. ["FAQ/TechnicalQuestions - CAcert Wiki"](http://wiki.cacert.org/FAQ/TechnicalQuestions#CAcert_Class_3_certificates). *wiki.cacert.org*. Retrieved September 24, 2019.

---
Adapted from the Wikipedia article [CAcert.org](https://en.wikipedia.org/wiki/CAcert.org) by Wikipedia contributors ([contributor history](https://en.wikipedia.org/wiki/CAcert.org?action=history)). Available under [Creative Commons Attribution-ShareAlike 4.0 International](https://creativecommons.org/licenses/by-sa/4.0/). Changes may have been made.
