Re: J-PAKE in NSS

2011-03-04 Thread Brian Smith
Jean-Marc Desperrier wrote: I notice the committed code extracts the generated shared symmetric key up to the javascript level, so takes no real advantage from having generated it inside NSS (I'd expect it instead to leave the AES256 key inside NSS and just get back the handle to it to

Re: Root certificate authorities

2011-03-04 Thread Brian Smith
Ritmo2k wrote: Anyone know if its possible to configure Firefox to implicitly trust all certificate authorities installed in the Windows Trusted Root Certification Authorities Store? Firefox does not support this yet. See: https://bugzilla.mozilla.org/show_bug.cgi?id=454036

Re: Root certificate authorities

2011-03-04 Thread Brian Smith
Ritmo2k wrote: I took a look at http://www.mozilla.org/projects/security/pki/nss/tools/index.html but it wasn’t obvious to me if this was even possible using those tools. In theory you could write a script that exports all the CA certificates from the Windows certificate store and then uses