Re: Pending roots and EV enablements

2009-05-20 Thread Gen Kanai
On May 19, 2009, at 10:23 AM, Nelson B Bolyard wrote: Now, I don't want to set unrealistic expectations, so I must inform you that I have NO idea whether Mozilla Corporation will accept any additional NSS changes at this point or not. Three weeks ago, Bob Relyea and I wrote to MoCo power

Re: Roots that are identical except for signature algorithm and serial number

2009-05-20 Thread Nelson Bolyard
On 2009-05-20 13:58, Kathleen Wilson wrote: When processing a cert chain, does Mozilla use a specified algorithm/ order for determining which root to use when there are two roots included that are identical except for signature algorithm and serial number? The algorithm for choosing from among

Re: Roots that are identical except for signature algorithm and serial number

2009-05-20 Thread Arshad Noor
Certificate-chain validation, primarily, works based on the Subject Key Identifier and the Authority Key Identifier extensions. When validation code is presented with multiple certificates that have the same AKIs in the chain, a good programmer will attempt to use the stronger certificate if it c

Roots that are identical except for signature algorithm and serial number

2009-05-20 Thread Kathleen Wilson
When processing a cert chain, does Mozilla use a specified algorithm/ order for determining which root to use when there are two roots included that are identical except for signature algorithm and serial number? Are there cases when Firefox might see a full cert chain, including the root (which n

Re: Pending roots and EV enablements

2009-05-20 Thread Eddy Nigg
On 05/19/2009 09:35 PM, Frank Hecker: Nelson B Bolyard wrote: Now, I don't want to set unrealistic expectations, so I must inform you that I have NO idea whether Mozilla Corporation will accept any additional NSS changes at this point or not. Three weeks ago, Bob Relyea and I wrote to MoCo p