Re: NSS Environment Variable to Disable 1024-bit Support?

2010-05-18 Thread Kathleen Wilson
On 5/15/10 10:48 AM, Nelson B Bolyard wrote: On 2010-05-15 01:35 PDT, Wan-Teh Chang wrote: On Fri, May 14, 2010 at 11:18 PM, Nelson B Bolyardnel...@bolyard.me wrote: I looked through PSM for such a warning briefly. I found a warning for sites that use symmetric encryption of strength= 90

Re: NSS Environment Variable to Disable 1024-bit Support?

2010-05-18 Thread Wan-Teh Chang
On Tue, May 18, 2010 at 11:16 AM, Kathleen Wilson kathleen95...@yahoo.com wrote: So, is it the case that PSM is not actually checking for 512-bit certs? Yes, I confirm that's the case. Nelson and I didn't find the code or the bug report for checking for 512-bit certs. I just created a test

Re: NSS Environment Variable to Disable 1024-bit Support?

2010-05-15 Thread Nelson B Bolyard
On 2010-05-14 14:21 PDT, Kathleen Wilson wrote: Of course, the followup question for folks familiar with PSM... Is there a hidden preference (or other capability) in the PSM that can be set to make my Firefox browser display a warning when a 1024-bit cert is used? e.g. similar to what

Re: NSS Environment Variable to Disable 1024-bit Support?

2010-05-15 Thread Wan-Teh Chang
On Fri, May 14, 2010 at 11:18 PM, Nelson B Bolyard nel...@bolyard.me wrote: I looked through PSM for such a warning briefly.  I found a warning for sites that use symmetric encryption of strength = 90 bits, but I found nothing that specifically looks at public key strength.  If I know the

Re: NSS Environment Variable to Disable 1024-bit Support?

2010-05-15 Thread Nelson B Bolyard
On 2010-05-15 01:35 PDT, Wan-Teh Chang wrote: On Fri, May 14, 2010 at 11:18 PM, Nelson B Bolyard nel...@bolyard.me wrote: I looked through PSM for such a warning briefly. I found a warning for sites that use symmetric encryption of strength = 90 bits, but I found nothing that specifically

Re: NSS Environment Variable to Disable 1024-bit Support?

2010-05-14 Thread Kathleen Wilson
On 5/13/10 3:32 PM, Nelson B Bolyard wrote: On 2010-05-13 14:30 PST, Kathleen Wilson wrote: Is there an NSS environment variable that can be set such that a warning is provided when a 1024-bit cert is used in Firefox? No. Any NSS environment variable would disable a feature completely, not

NSS Environment Variable to Disable 1024-bit Support?

2010-05-13 Thread Kathleen Wilson
Is there an NSS environment variable that can be set such that a warning is provided when a 1024-bit cert is used in Firefox? My understanding is that if someone were to try to use a 512-bit cert in Firefox they would get a warning message to the effect that the connection is not secure, but

Re: NSS Environment Variable to Disable 1024-bit Support?

2010-05-13 Thread Nelson B Bolyard
On 2010-05-13 14:30 PST, Kathleen Wilson wrote: Is there an NSS environment variable that can be set such that a warning is provided when a 1024-bit cert is used in Firefox? No. Any NSS environment variable would disable a feature completely, not result in it causing a warning. Any variable