As I'm not sure of the way the proposed implementation for EV indication works, I don't quite know who to address this question to. I'm hoping the right person is reading :-)
At the moment, if a web page has some http and some https elements, Firefox (rightly) complains. You only get a lock, and a lack of warnings, if all of the page elements were served over https. Will whatever NSS or PSM flag is set to say "this page has an EV certificate" only be set if _all_ page elements are served from a server with such a certificate? Apparently, at the moment, IE displays the green bar if the top-level page is EV, and the rest is "normal" SSL. Gerv _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security
