Web of Trust
Key validity vs. owner trust
Assigning key validity and owner trust
Owner trust levels
Key validity levels
Key validity computation: complete
Key validity computation: marginal
Key validity computation: unknown
If the key is signed by no name with at least owner trust marginal
Trust signatures & trusted introducers
PGP Disadvantages
Hierarchical trust
Trust models in multiple hierarchies: Methods
Trusted list
Common root
Cross-certification
Root CA 1 issues certificate for CA 2 (can be bilateral) or for intermediate CAs
Bridge
X.509 certificate extension: Basic Constraints
Problems with CAs