CAcert.org


CAcert.org is a community-driven certificate authority that issues free public key certificates to the public. CAcert has over 334,000 verified users and has issued over 1,285,000 certificates. CAcert.org heavily relies on automation and therefore issues only Domain-validated certificates.
These certificates can be used to digitally sign and encrypt email, authenticate and authorize users connecting to websites and secure data transmission over the Internet. Any application that supports the Secure Socket Layer can make use of certificates signed by CAcert, as can any application that uses X.509 certificates, e.g. for encryption or code signing and document signatures.

CAcert Inc. Association

CAcert Inc. is an incorporated non-profit association registered in New South Wales since July 2003 which runs CAcert.org. It has members living in many different countries and a board of 7 members. It was founded by Duane Groth in 2003. In 2004, the Dutch internet pioneer Teus Hagen became involved with the community-driven certificate authority and served as board member and in 2008 as president.

Certificate Trust status

As per 29 August 2018 the certificates issued by CAcert do not have status of being trusted by most browsers hence users will be warned about untrusted certificate.
As for email use, MS Outlook will not accept using these certificates either.
CAcert use their own certificate on their HTTPS pages on their website.

Web of trust

To create higher-trust certificates, users can participate in a web of trust system whereby users physically meet and verify each other's identities. CAcert maintains the number of assurance points for each account. Assurance points can be gained through various means, primarily by having one's identity physically verified by users classified as "Assurers".
Having more assurance points allows users more privileges such as writing a name in the certificate and longer expiration times on certificates. A user with at least 100 assurance points is a Prospective Assurer, and may—after passing an Assurer Challenge—verify other users; more assurance points allow the Assurer to assign more assurance points to others.
CAcert sponsors key signing parties, especially at big events such as CeBIT and FOSDEM. CAcert's web of trust has 365,201 verified users as of 2019-02-14.

Root certificate descriptions

Since October 2005, CAcert offers Class 1 and Class 3 root certificates. Class 3 is a high-security subset of Class 1.

Inclusion status

The habit to include a list of CAs in the browser was established with Netscape Navigator v.3.0. It was 1996, the dawn of the first browser war, and little emphasis was put on the security implications of making such a list. The key concern was the users' ability to quickly access secured web pages, almost irrespectively of the signing CA. Browsers needed to not skip any important CA included by their competitors.
CAcert arrived much later. Discussion for inclusion of its root certificate in Mozilla and derivatives started in 2004. Mozilla had no CA certificate policy at the time. Eventually, they developed a policy which required that CAcert improved their management system and deepened their formal verifications, auditing in particular. CAcert withdrew its request for inclusion at the end of April 2007. Progress toward Mozilla requirements and a new request for inclusion can hardly be expected in the near future. At the same time, the CA/Browser Forum was established to allow peaceful discussion among browser producers. Mozilla's advice was adopted, and, in addition, Extended Validation Certificates began to be issued.
FreeBSD used to include CAcert root certificate but removed it in 2008 following Mozilla's policy. In 2014 it was removed from Ubuntu, Debian, and OpenBSD. In 2018 it was removed from Arch Linux.
The following operating systems or distributions include the CAcert root certificate, or have it available in an installable package: