Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Fraser Tweedale
On Fri, Jan 08, 2016 at 01:26:57PM +0100, Martin Kosek wrote: > Hi Fraser and other X.509 SMEs, > > I wanted to check with you on what we have or plan to have with respect to > certificate/cipher strength in FreeIPA. > > When I visit the FreeIPA public demo for example, I usually see following >

Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Rob Crittenden
Alexander Bokovoy wrote: > On Fri, 08 Jan 2016, Martin Kosek wrote: >> On 01/08/2016 02:17 PM, Fraser Tweedale wrote: >>> On Fri, Jan 08, 2016 at 02:02:07PM +0100, Martin Kosek wrote: On 01/08/2016 01:56 PM, Fraser Tweedale wrote: > On Fri, Jan 08, 2016 at 01:26:57PM +0100, Martin Kosek

[Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Martin Kosek
Hi Fraser and other X.509 SMEs, I wanted to check with you on what we have or plan to have with respect to certificate/cipher strength in FreeIPA. When I visit the FreeIPA public demo for example, I usually see following errors with recent browsers: * Your connection to ipa.demo1.freeipa.org is

Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Fraser Tweedale
On Fri, Jan 08, 2016 at 02:02:07PM +0100, Martin Kosek wrote: > On 01/08/2016 01:56 PM, Fraser Tweedale wrote: > > On Fri, Jan 08, 2016 at 01:26:57PM +0100, Martin Kosek wrote: > >> Hi Fraser and other X.509 SMEs, > >> > >> I wanted to check with you on what we have or plan to have with respect to

Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Christian Heimes
On 2016-01-08 13:26, Martin Kosek wrote: > Hi Fraser and other X.509 SMEs, > > I wanted to check with you on what we have or plan to have with respect to > certificate/cipher strength in FreeIPA. > > When I visit the FreeIPA public demo for example, I usually see following > errors with recent

Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Alexander Bokovoy
On Fri, 08 Jan 2016, Martin Kosek wrote: On 01/08/2016 02:17 PM, Fraser Tweedale wrote: On Fri, Jan 08, 2016 at 02:02:07PM +0100, Martin Kosek wrote: On 01/08/2016 01:56 PM, Fraser Tweedale wrote: On Fri, Jan 08, 2016 at 01:26:57PM +0100, Martin Kosek wrote: Hi Fraser and other X.509 SMEs,

Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Martin Kosek
On 01/08/2016 02:24 PM, Christian Heimes wrote: > On 2016-01-08 13:26, Martin Kosek wrote: >> Hi Fraser and other X.509 SMEs, >> >> I wanted to check with you on what we have or plan to have with respect to >> certificate/cipher strength in FreeIPA. >> >> When I visit the FreeIPA public demo for

Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Martin Kosek
On 01/08/2016 02:17 PM, Fraser Tweedale wrote: > On Fri, Jan 08, 2016 at 02:02:07PM +0100, Martin Kosek wrote: >> On 01/08/2016 01:56 PM, Fraser Tweedale wrote: >>> On Fri, Jan 08, 2016 at 01:26:57PM +0100, Martin Kosek wrote: Hi Fraser and other X.509 SMEs, I wanted to check with

Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Martin Kosek
On 01/08/2016 01:56 PM, Fraser Tweedale wrote: > On Fri, Jan 08, 2016 at 01:26:57PM +0100, Martin Kosek wrote: >> Hi Fraser and other X.509 SMEs, >> >> I wanted to check with you on what we have or plan to have with respect to >> certificate/cipher strength in FreeIPA. >> >> When I visit the

Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Petr Spacek
On 8.1.2016 13:56, Fraser Tweedale wrote: > On Fri, Jan 08, 2016 at 01:26:57PM +0100, Martin Kosek wrote: >> > Hi Fraser and other X.509 SMEs, >> > >> > I wanted to check with you on what we have or plan to have with respect to >> > certificate/cipher strength in FreeIPA. >> > >> > When I visit

Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Petr Spacek
On 8.1.2016 16:57, Christian Heimes wrote: > On 2016-01-08 16:49, Petr Spacek wrote: >> On 8.1.2016 13:56, Fraser Tweedale wrote: >>> On Fri, Jan 08, 2016 at 01:26:57PM +0100, Martin Kosek wrote: > Hi Fraser and other X.509 SMEs, > > I wanted to check with you on what we have or plan

Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Martin Kosek
On 01/08/2016 03:02 PM, Rob Crittenden wrote: > Alexander Bokovoy wrote: >> On Fri, 08 Jan 2016, Martin Kosek wrote: >>> On 01/08/2016 02:17 PM, Fraser Tweedale wrote: On Fri, Jan 08, 2016 at 02:02:07PM +0100, Martin Kosek wrote: > On 01/08/2016 01:56 PM, Fraser Tweedale wrote: >> On

Re: [Freeipa-devel] FreeIPA and modern requirements on certificates

2016-01-08 Thread Christian Heimes
On 2016-01-08 16:49, Petr Spacek wrote: > On 8.1.2016 13:56, Fraser Tweedale wrote: >> On Fri, Jan 08, 2016 at 01:26:57PM +0100, Martin Kosek wrote: Hi Fraser and other X.509 SMEs, I wanted to check with you on what we have or plan to have with respect to certificate/cipher