Re: Explicitly distrusted certificates in certdata.txt (NSS built-in root CA certificate list)

2011-10-10 Thread Nelson B Bolyard
On 2011/10/10 12:16 PDT, Wan-Teh Chang wrote: > [...] > The certdata.txt file in the NSS source tree > (http://mxr.mozilla.org/security/source/security/nss/lib/ckfw/builtins/certdata.txt) > is the master source of the NSS built-in trusted root CA list, so > people have written scripts to extract th

Re: Explicitly distrusted certificates in certdata.txt (NSS built-in root CA certificate list)

2011-10-10 Thread Robert Relyea
On 10/10/2011 12:16 PM, Wan-Teh Chang wrote: > After you match a trust object to a certificate, check the > CKA_TRUST_SERVER_AUTH, CKA_TRUST_EMAIL_PROTECTION, and > CKA_TRUST_CODE_SIGNING attributes in the trust object. > > In the current version of certdata.txt, these attributes may have only > th

Explicitly distrusted certificates in certdata.txt (NSS built-in root CA certificate list)

2011-10-10 Thread Wan-Teh Chang
Florian Weimer reported this issue to us. The certdata.txt file in the NSS source tree (http://mxr.mozilla.org/security/source/security/nss/lib/ckfw/builtins/certdata.txt) is the master source of the NSS built-in trusted root CA list, so people have written scripts to extract the trusted root CA c