Re: OCSP/CRL handling in Firefox

2006-09-02 Thread Nelson B
GaryK wrote: .NET CLR 2.0.50727; .NET CLR 1.1.4322),gzip(gfe),gzip(gfe) Injection-Info: m73g2000cwd.googlegroups.com; posting-host=65.205.251.51; posting-account=bqHXlg0AAABIeE5JRZLSrHSri2ZbRXKH What's all that stuff? I am a technical director at VeriSign and was asked a question that

Re: Certificate Import Bug/Feature?

2006-09-02 Thread Anders Rundgren
Thanx for the super quick response! c-i-l Nelson B wrote: I created a certificate path consisting of root CA, sub CA and EE cert and put it in a PKCS 12 file including the private key to the EE cert. When I import it in MSIE 6 I get the question if I want to install the root CA. In FF I

Re: Certificate Import Bug/Feature?

2006-09-02 Thread Anders Rundgren
Have you ever tried that phrase on consumers? They don't know what a CA is and I hope they never will. Ah, then apparently you hope consumers will never get certs. Maybe you are not familiar with consumer/citizen PKIs in the EU? They are mostly designed for on-line services. For such

The Mozilla trust model FIPS201

2006-09-02 Thread Anders Rundgren
Have I gotten this right? 1. Mozilla PKI client support (FF's TLS-client-auth, FF's signText and TB's S/MIME), requires that the CA certificate is known and trusted by the local client software? If that is true I would consider it a major bug or at least a major nuisance because there is no