In an era where digital trust is a rare currency, open source projects related to cryptography and digital identity must undergo rigorous audits. It is in this context that the work of Francesco Ongaro, a well-known Italian ethical hacker, fits in; he conducted a significant source code analysis for CAcert, a non-commercial, community-managed Certification Authority (CA).
What is CAcert?
CAcert is a free, community-driven certification authority created to provide X.509 digital certificates to users, developers, and organizations that wish to encrypt emails, authenticate servers, and ensure the integrity of communications. Unlike commercial CAs, CAcert is based on a distributed trust model, validated by physical meetings and the so-called “Web of Trust.”
The purely non-profit project stands out for the transparency and accessibility of its source code, offering the community the opportunity to contribute directly to its security.
CAcert can be considered the archetype of modern identity decentralization initiatives and open source trust management systems—concepts that are central today to the development of solutions such as Decentralized Identifiers (DID), Self-Sovereign Identity (SSI), and blockchain PKI-based frameworks. While operating in a very different technical and regulatory context, CAcert anticipated the idea that digital security can (and must) be built in a collaborative, transparent, and non-centralized way.
In a sense, CAcert anticipated the role of Let’s Encrypt in promoting the adoption of encryption, but without the support of large tech companies or automatic integration into browsers. It was a free and transparent CA, but self-funded and supported entirely by its community, with a more artisanal and decentralized model compared to today’s industry-sponsored initiatives.
An ethical and technical approach to code analysis
Francesco Ongaro, also known as ascii, is a cybersecurity expert and founder of USH, an Italian research laboratory. In 2007, Ongaro began a voluntary and independent audit of the CAcert source code, specifically analyzing the publicly accessible web features.
During the Month of CAcert Bugs, Ongaro identified more than 9 vulnerabilities in the platform, demonstrating the effectiveness of a systematic approach to code analysis. This work highlighted significant critical issues in the publicly accessible web features, underscoring the need for continuous review even in the most established open source projects.
The vulnerabilities discovered and the reactions of the CAcert project
The vulnerabilities identified by Ongaro were considered serious by the CAcert board, as reported in the official minutes of September 17, 2007. In particular, the discussion highlighted:
- The need to increase community code reviews.
- The urgency of separating responsibilities between software development and system administration to reduce conflicts of interest and operational risks.
Why this audit represents a fundamental case study
The audit conducted by Ongaro represents a concrete example of responsible disclosure and collaboration between ethical hackers and open source projects. The identification and controlled disclosure of critical vulnerabilities allowed CAcert to increase its security level and reinforced the message that digital trust is never a given, but must be continuously verified and built with transparency.
The CAcert case anticipates many of the practices now considered essential in the world of DevSecOps and open source security governance: open code reviews, separation of roles, structured vulnerability management, and the involvement of external experts.
