Priit Randla wrote:
>
>  Also, what should i do to avoid Mozilla ( and Netscape )  asking pins
> for private keys which are associated
>  with certificates unsuitable for TLS ( nonRepudiation, authenticate
> once per priv-key operation)?
> 

Oops, I forget the 2nd half of your question.

Currently NSS only really supports dual key. TLS certs are selected from 
any cert capable of signing. We do not yet really have support for true 
tri-key systems (exchange, authenticate, sign).

bob

Reply via email to