Re: set default on for SHA2 for TLS1.1+ on firefox

2013-10-14 Thread Mountie Lee
Hi. TLS1.2 with SHA256 can be enabled manually.(default disabled) advanced users have to to as following about:config at address bar == agree using advanced feature == set value of security.tls version.max to 3 see the link https://support.mozilla.org/en-US/questions/959936 On Tue, Oct 8,

Re: reduce default OCSP timeouts.

2013-10-14 Thread Gervase Markham
On 11/10/13 21:50, Wan-Teh Chang wrote: I would use a timeout of 5 seconds. 3 seconds seem a little short. I agree 10 seconds are too long. Can you expand on what criteria you are using to make these judgements? Fetching the OCSP response takes 2RTT, as Camilo said. So if your RTT is 1000ms