Re: Root certificate authorities

2011-03-07 Thread Ritmo2k
On Mar 5, 1:22 pm, Nelson B Bolyard nel...@bolyard.me wrote: Brian Smith wrote: Ritmo2k wrote: Anyone know if its possible to configure Firefox to implicitly trust all certificate authorities installed in the Windows Trusted Root Certification Authorities Store? Firefox does not

Re: J-PAKE in NSS

2011-03-07 Thread Jean-Marc Desperrier
Brian Smith wrote: Jean-Marc Desperrier wrote: [...] (I'd expect it instead to leave the AES256 key inside NSS and just get back the handle to it to encrypt what it needs later. [...]). The kind of improvement you described above will be made to resolve Bug 443386 and/or Bug 638966. I

Re: Known Issue? Looping CA Cross-Certificates not displayed as going to a Root CA

2011-03-07 Thread Brian Smith
Ridley wrote: Presence both of a pair of cross-certificates in the Authorities certificarte store results looping rather than traversing to a root certificate. See https://bugzilla.mozilla.org/show_bug.cgi?id=634074. - Brian -- dev-tech-crypto mailing list dev-tech-crypto@lists.mozilla.org

Re: J-PAKE in NSS

2011-03-07 Thread Brian Smith
Jean-Marc Desperrier wrote: Brian Smith wrote: The kind of improvement you described above will be made to resolve Bug 443386 and/or Bug 638966. I think Bug 638966 is slightly different, it's about permanently storing the secret keys in the NSS db (I don't know if that's really possible,

TLS-SRP (was Re: J-PAKE in NSS)

2011-03-07 Thread Brian Smith
Jean-Marc Desperrier wrote: But Curl, that supports secret keys from version 7.21.4, with GnuTLS only at the moment but is pushing hard to get in in Openssl also, apparently has simply given up about having TSP-SRP support when compiled with NSS. I see in an old doc that Johnathan was

Re: TLS-SRP (was Re: J-PAKE in NSS)

2011-03-07 Thread Daniel Stenberg
On Mon, 7 Mar 2011, Brian Smith wrote: But Curl, that supports secret keys from version 7.21.4, with GnuTLS only at the moment but is pushing hard to get in in Openssl also, apparently has simply given up about having TSP-SRP support when compiled with NSS. Can I just add that we (in the