Re: MITM in the wild

2008-11-12 Thread Ian G
Eddy Nigg wrote: Nope, just eliminating an assumption or two: identity required for court. Once these are eliminated, life becomes much easier. Real identity is required for court, No it's not. You just need the person, not their identity. The identity is useful for eliminating

Re: MITM in the wild

2008-11-12 Thread Eddy Nigg
On 11/12/2008 08:32 AM, Ian G: eBay users seems to survive without them? Because a different body governs them. Or lets make some comparison to transportation, where one in order to drive a car must undergo some training and carry a license. I could imagine something similar applied to the

SSL version 3 - How Firefox contructs key materials for 3DES

2008-11-12 Thread Rusdy13
I've been developing a web server (research) based on ssl version 3 doc (ssl-version3-02.txt), choosing cipher suite 0x000a (ssl-tripleDes-sha) and using firefox browser to test the program. It works successfully from client hello until server finished (handshake protocol). All key materials

Re: Help to use PKCS 11 functions in firefox extension

2008-11-12 Thread Robert Relyea
Akkshayaa Venkatram wrote: Hi I am developing a Firefox extension that calls PKCS 11 functions like C_Encrypt, C_Sign, C_Decrypt and others.. We don't expose the direct C_ calls in NSS. NSS typically has the token open during the entire time, so applications making calls and changing states

Re: SSL version 3 - How Firefox contructs key materials for 3DES

2008-11-12 Thread Nelson B Bolyard
Rusdy13 wrote, On 2008-11-12 02:25: I've been developing a web server (research) based on ssl version 3 doc (ssl-version3-02.txt), choosing cipher suite 0x000a (ssl-tripleDes-sha) and using firefox browser to test the program. It works successfully from client hello until server finished

Re: signtool.exe

2008-11-12 Thread Julien R Pierre - Sun Microsystems
Nelson, Nelson B Bolyard wrote: Two years ago this week, John Smith wrote to us: When I sign using keytool.exe version 3.10 it signs OK, When I sign using keytool.exe version 3.11 it throws this error: using certificate directory: C:\Documents and Settings\myusername\Application

Re: signtool.exe

2008-11-12 Thread Nelson B Bolyard
Julien R Pierre - Sun Microsystems wrote, On 2008-11-12 14:46: The user above was using Windows, not Solaris. On Windows we didn't have freebl shared libs in 3.10, and thus no freebl library loading was necessary. That's true for Windows. The simplest workaround for Windows users is to