Hi,
    The certificates do not have the same subject, and are from the same
certification authority. The problem *can* be sorted by selecting 'ask
every' but then, when trying to access every page that is cert protected,
the prompt comes up asking to choose a cert. Is it not possible to have an
option like that in Opera 6 which asks once per session (the way that IE
also works)?

Thanks
Bob

"Robert Relyea" <[EMAIL PROTECTED]> wrote in message
news:[EMAIL PROTECTED]...
>
> 1) If all the certs are with the same subject, they are considered the
> same 'personality' by NSS. If these certs have different semantics, then
> they *MUST* had different subjects. This is because users will often
> have multiple certs that have varying expiration times, and it's a
> burden to on the user to be acked which to use all the time when the
> system can more accurately select the correct cert.
>
> 2) Another thing that may be happening is the company issues different
> certs under different intermediate CA's. When the SSL connection is
> made, only those intermediate CA's relevant for that site are requested.
> Since you would have only one cert for that intermediate CA, that's the
> cert SSL will use. It would be correct behavior, and a corrrectly
> configured PKI system.
>
> 3) A final problem may be you have 'select automatically' turned on in
> your preferences. Go to 'preferences->certificates' and click on 'ask
> every'.
>
> If you are running into either case 1 or case 3, please write an
> evangelism bug up for the web site. May people are starting to deploy
> pki for the first time and often make mistakes in configurations that
> become unsupportable in the future.
>
> bob
>
>
> >
> >
> >
>



Reply via email to