Re: Alerts on TLS Renegotiation

2010-04-12 Thread Jean-Marc Desperrier
On 12/04/2010 15:29, Eddy Nigg wrote: updated servers need updates clients and break older ones, whereas old servers will not allow new clients. I haven't seen one yet, that doesn't have a flag to accept older clients. If you set that flag, *and* disable renegotiation at least for older clien

Re: What is this?

2010-04-12 Thread Eddy Nigg
On 04/12/2010 11:27 PM, Nelson B Bolyard: Yup, just test files used by the automated QA scripts run in Tinderbox. They must be replaced every year or so. http://tinderbox.mozilla.org/showbuilds.cgi?tree=NSS Nice :-) and thanks. -- Regards Signer: Eddy Nigg, StartCom Ltd. XMPP:start.

Re: What is this?

2010-04-12 Thread Nelson B Bolyard
On 2010/04/12 11:16 PDT, Eddy Nigg wrote: > On 04/12/2010 08:18 PM, Eddy Nigg: >> http://bonsai.mozilla.org/cvsview2.cgi?command=DIRECTORY&subdir=mozilla/security/nss/tests/libpkix/certs&files=OCSPCA1.cert:OCSPCA1.p12:OCSPCA2.cert:OCSPCA2.p12:OCSPCA3.cert:OCSPCA3.p12:OCSPEE11.cert:OCSPEE12.cert:OCS

Re: What is this?

2010-04-12 Thread Eddy Nigg
On 04/12/2010 08:18 PM, Eddy Nigg: http://bonsai.mozilla.org/cvsview2.cgi?command=DIRECTORY&subdir=mozilla/security/nss/tests/libpkix/certs&files=OCSPCA1.cert:OCSPCA1.p12:OCSPCA2.cert:OCSPCA2.p12:OCSPCA3.cert:OCSPCA3.p12:OCSPEE11.cert:OCSPEE12.cert:OCSPEE13.cert:OCSPEE14.cert:OCSPEE15.cert:OCSPEE2

What is this?

2010-04-12 Thread Eddy Nigg
http://bonsai.mozilla.org/cvsview2.cgi?command=DIRECTORY&subdir=mozilla/security/nss/tests/libpkix/certs&files=OCSPCA1.cert:OCSPCA1.p12:OCSPCA2.cert:OCSPCA2.p12:OCSPCA3.cert:OCSPCA3.p12:OCSPEE11.cert:OCSPEE12.cert:OCSPEE13.cert:OCSPEE14.cert:OCSPEE15.cert:OCSPEE21.cert:OCSPEE22.cert:OCSPEE23.cert:

Re: Certificate Patrol error (or malformed ssl certificate?)

2010-04-12 Thread Kai Engert
On 12.04.2010 16:22, Kai Engert wrote: On 12.04.2010 07:36, Kurt Seifried wrote: Right but I can't find any contact info for certificate patrol and I figured if anyone knew about it, they're probably on this list. That and I couldn't find an add-ons mailing list (how does on get on contact with

Re: ocsp check problem: sec_error_bad_database

2010-04-12 Thread Rafa
Are there any news about it? I can capture an OCSP response if necessary. Thanks in advance, Rafa On 17 mar, 08:44, Nelson Bolyard wrote: > On 2010-03-16 22:04 PST, Kyle Hamilton wrote: > > > Your profile's certificate and trust database appears to be corrupted, > > and therefore it can't chec

Re: Certificate Patrol error (or malformed ssl certificate?)

2010-04-12 Thread Kai Engert
On 12.04.2010 07:36, Kurt Seifried wrote: Right but I can't find any contact info for certificate patrol and I figured if anyone knew about it, they're probably on this list. That and I couldn't find an add-ons mailing list (how does on get on contact with them?). The word "contact" doesn't occu

Re: Alerts on TLS Renegotiation

2010-04-12 Thread Eddy Nigg
On 04/12/2010 05:48 AM, Nelson Bolyard: .. The warnings will come -- WHEN? In 2010? In 2011? Whenever it will be, it will become an entire mess. That's because updated servers need updates clients and break older ones, whereas old servers will not allow new clients. Basically i

Re: Certificate Patrol error (or malformed ssl certificate?)

2010-04-12 Thread Nelson Bolyard
On 2010-04-11 22:36 PST, Kurt Seifried wrote: >> Kurt, I suggest you try posting this again, without the image, but WITH >> the certificate that caused Certificate Patrol to complain. As it is, >> there's no information in this posting with which anyone can help you. > > That would be the PEM fi