Re: OCSP nonce was: RE: cvs commit: openssl/ssls3_lib.cssl.hssl_algs.cssl_ciph.cssl_locl.h tls1.h

2001-02-09 Thread Peter Gutmann
Richard Levitte - VMS Whacker [EMAIL PROTECTED] writes: From: [EMAIL PROTECTED] (Peter Gutmann) pgut001 Given that (statistically speaking) the client will be a pgut001 Windoze box with a time which is more or less random, the use pgut001 of absolute timestamps doesn't add much, it would have

RE: OCSP nonce was: RE: cvs commit: openssl/ssls3_lib.cssl.hssl_algs.cssl_ciph.cssl_locl.h tls1.h

2001-02-08 Thread Peter Gutmann
"Florian Oelmaier" [EMAIL PROTECTED] writes: We do the same, as we directly connect to the CA-database, but we set thisUpdate to the actual time as this seems to make more sense. It would be fine to have an option within OpenSSL that says: "Trust only responses with a thisUpdate not more than x