NSS 3.13.4

2012-04-06 Thread Kai Engert
The NSS team has released NSS 3.13.4 CVS tag: NSS_3_13_4_RTM ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_13_4_RTM/ Please refer to https://bugzilla.mozilla.org/show_bug.cgi?id=741135 for the list of changes contained in this update. Kai -- dev-tech-crypto mailing list

Re: Alternative for SGN_DecodeDigestInfo

2012-04-06 Thread Brian Smith
Robert Relyea wrote: Why are they linking with Freebl anyway? It's intended to be a private interface for softoken. It's a very good way to find yourself backed into a corner. Right. This was a long time ago. You helped me add the J-PAKE implementation to Softoken after we discovered this

Re: Combining OCSP stapling with advance MITM preparation

2012-04-06 Thread Brian Smith
Kai Engert wrote: The domain owner could configure their server to include this OCSP response in all TLS handshakes, even though this OCSP response is unrelated to the server certificate actually being used. For complete protection, the real domain holder would have to staple all the OCSP