> I think you misunderstand the answer. You can use a 128bit key on your
> server, but the end users will probably be connecting using a 40bit
browser.
> So they won't be getting the maximum level of encryption available.
We have tested it out here at Lucent (I haven't myself so I can only say
what happend, not why). Installing a 128bits certificate on the web server,
and using 40bits french Netscape (v 4.5 or 4.6) on NT4 to access it :
computer crash !
As I've said, I only share my experience, so maybe Florin will be better
fitted out with a 40bits certificate after all....
Marc van Leeuwen
Lucent Technologies
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]