Re: OCSP/CRL handling in Firefox

2006-09-02 Thread Nelson B
GaryK wrote: .NET CLR 2.0.50727; .NET CLR 1.1.4322),gzip(gfe),gzip(gfe) Injection-Info: m73g2000cwd.googlegroups.com; posting-host=65.205.251.51; posting-account=bqHXlg0AAABIeE5JRZLSrHSri2ZbRXKH What's all that stuff? I am a technical director at VeriSign and was asked a question that

RE: OCSP/CRL handling in Firefox

2006-08-10 Thread Krall, Gary
Nelson B Bolyard wrote: On a related topic, perhaps you can speak to whether Verisign still considers Alex Deacon's bug report https://bugzilla.mozilla.org/show_bug.cgi?id=234129 to be an issue? I spoke with Alex this morning and yes he feels that this is still a bug and should be fixed. We

Re: OCSP/CRL handling in Firefox

2006-08-08 Thread Kai Engert
Nelson B Bolyard wrote: Presently, A user must initiate the first fetch of a CRL from the CA. CRLs are fetched asynchronously from cert chain validation. CRLs are stored on disk locally, IIRC. After fetching the first one, mozilla clients will fetch subsequent CRLs automatically on a periodic

Re: OCSP/CRL handling in Firefox

2006-08-08 Thread Frank Hecker
Nelson B Bolyard wrote: Presently, A user must initiate the first fetch of a CRL from the CA. To clarify, AFAIK all that is required is for a user to click on a link to the CRL, *if* the CRL data is returned with a MIME type of application/pkix-crl. Firefox then imports the CRL and prompts

OCSP/CRL handling in Firefox

2006-08-07 Thread Krall, Gary
I am a technical director at VeriSign and was asked a question that Gerv recommended that I post to this mailist. As you know, VeriSign has spent a fair of time, money and effort to roll out our OCSP service which is currently supported as an option in FF. Having said that we're also