I forgot to send my reply on Friday.  :( 
My browser works fine with various certs, but no other browser I've
tried does.  Not one.  They all have problems with secclab.  They either
don't have it, or it is broken.

The secclab plugin for mozilla <= 1.6 actually breaks mozilla, and
causes it to fail on startup with stupid errors, some other secclab
plugin version apparently works, but if so it's incorrectly labelled on
their site.

Other browser versions that do have secclab can sign the challenge with
the plugin dialog, but then don't send the correct reply.  I added some
debug to the javascript output to display what the plugin was replying
with, and on my browser it sends a big long signed challenge as you
would expect, but on other browsers, it sends

error:internalError

Which must mean secclab is still broken.  It gets picked up by a line of
javascript that says if a reply is less than 100 chars, display an error
saying "sign is needed to enter".

I found a link to wamcom, the fixed version of mozilla with a working
javascript crypto.signText() function, but it's a bit too old to use in
linux.  I'm stumped still.  There's not many options still open to me,
other than trying to add the javascript crypto.signText() patch to a new
version of firefox.

Are other people out there able to use the crypto.signText() function
reliably in a production environment?  I'm running into problem after
problem, and I want to find a way for it to work for non technical admin
staff (probably in windows, yuck.)

Damon

On Thu, 2004-08-12 at 17:43, Michael Bell wrote:
> Damon Smith wrote:
> > Hi, x509 login using firefox 0.9.1 under gentoo linux works fine for me
> > (with SecCLAB plugin).  
> > My colleague tried it under mandrake with firefox 0.9.3, and it would
> > bring up the secCLAB window, show the data to be signed, prompt for the
> > master password (all correct behaviour) then when he hits ok, it just
> > brings up a new challenge string, instead of logging in.
> 
> This is a bug. The only question is what happens exactly. Does the 
> browser load something before it displays the second challenge string or 
> does the challenge string pop up automatically?
> 
> > I'm looking for a browser to recommend to RAO's, almost all of whom are
> > linux users.  Any ideas as to the best browser for the x509 login job?
> 
> - Mozilla 1.7.2 without SecCLAB
> - Mozilla <1.7 with SecCLAB
> 
> Firefox should have the same codebase like Mozilla.
> 
> Michael



-------------------------------------------------------
SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media
100pk Sonic DVD-R 4x for only $29 -100pk Sonic DVD+R for only $33
Save 50% off Retail on Ink & Toner - Free Shipping and Free Gift.
http://www.shop4tech.com/z/Inkjet_Cartridges/9_108_r285
_______________________________________________
Openca-Users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to