Re: certutil or PKI for NSS 3.11.9

2008-06-24 Thread Nelson B Bolyard
Arshad Noor wrote, On 2008-06-23 15:58: Nelson, I think you may want to qualify your message in this paragraph, so as to not mislead people who don't understand PKI very well. Arshad: I want people who don't understand PKI very well to get one message, loud and clear: Don't try to make and

Re: certutil or PKI for NSS 3.11.9

2008-06-24 Thread Arshad Noor
I will defer to your experience in the war-stories you've heard, Nelson. You've certainly seen a lot more people do stupid things in this area than I have, I'm sure. I tend to get involved only when people want to do PKI the right way :-). I am a strong believer that educating the general masses

Re: certutil or PKI for NSS 3.11.9

2008-06-23 Thread Arshad Noor
Nelson, I think you may want to qualify your message in this paragraph, so as to not mislead people who don't understand PKI very well. As I'm sure most people on this list know, every Root CA certificate is a self-signed certificate. There is nothing inherently insecure about such