Re: Announcing Mozilla::PKIX, a New Certificate Verification Library

2014-04-25 Thread Camilo Viecco
On 4/25/14, 9:18 AM, Zack Weinberg wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 04/25/2014 09:59 AM, Erwann Abalea wrote: Le vendredi 25 avril 2014 13:46:51 UTC+2, Martin Paljak a écrit : What is the rationale for this: 4. Mozilla::pkix performs chaining based on issuer name

Re: reduce default OCSP timeouts.

2013-10-11 Thread Camilo Viecco
On 10/11/13 1:39 PM, Bob Clary wrote: On 10/11/2013 12:57 PM, Camilo Viecco wrote: Hello List I am planning to land a patch to reduce the default (soft-fail) OCSP network timeout values. Currently OCSP connections timeout after 10 seconds and my plan is to changed that to 3 seconds (hard fail

Re: reduce default OCSP timeouts.

2013-10-11 Thread Camilo Viecco
On 10/11/13 1:58 PM, Eddy Nigg wrote: On 10/11/2013 11:50 PM, From Wan-Teh Chang: I would use a timeout of 5 seconds. 3 seconds seem a little short. I agree 10 seconds are too long. +1 Thanks Eddy/Wan Tech: 5 seconds seems too high for a fail open option, but let me ask you: what percent

Re: Proposal to Change the Default TLS Ciphersuites Offered by Browsers

2013-08-16 Thread Camilo Viecco
Hello Brian I think this proposal has 3 sections. 1. Unifing SSL behavior on browsers. 2. Altering the criteria for cipher suite selection in Firefox (actually NSS) 3. removing certain cipher suites from the default firefox ciphersuite. On 1: I dont see the point, but I am not against. On 2:

Re: Proposal to Change the Default TLS Ciphersuites Offered by Browsers

2013-08-16 Thread Camilo Viecco
On 8/16/13 11:13 AM, Camilo Viecco wrote: Hello Brian I think this proposal has 3 sections. 1. Unifing SSL behavior on browsers. 2. Altering the criteria for cipher suite selection in Firefox (actually NSS) 3. removing certain cipher suites from the default firefox ciphersuite. On 1: I dont