Re: [Ach] Proposal to Remove legacy TLS Ciphersuits Offered by Firefox

2014-01-08 Thread L. Aaron Kaplan
On Jan 5, 2014, at 4:27 PM, Kurt Roeckx k...@roeckx.be wrote: On Fri, Jan 03, 2014 at 12:19:10AM +0100, Aaron Zauner wrote: 3DES isn't broken. Triple DES provides about 112bit security (We've a section on the topic in the Paper in the Keylenghts section). All ciphers that we recomend are

Re: NSS OCSP stapling tests

2014-01-08 Thread Julien Pierre
Kai, On 1/3/2014 02:40, Kai Engert wrote: On Do, 2014-01-02 at 19:34 -0800, Julien Pierre wrote: The new OCSP stapling tests in NSS 3.15.3 are all failing on our Solaris machines. See error log below. We have a slightly smaller number of failures on Linux. Are these tests going out to a