Re: OpenSSL usage liability, RHSWS, and toothbrushes

1999-11-22 Thread Leland V. Lammert
Jeeze, boobie! Lighten UP!! There have been no court cases on the issue (are you a lawyer or a judge??), .. and your analogy to piece parts is invalid. Quit giving bogus legal advice! Lee At 09:39 AM 11/18/99 , you wrote: >-Original Message- >From: Leland V. Lammert &

Re: Internal CA & Generating my own Certificates

1999-11-22 Thread Leland V. Lammert
bove, > >Thank You, > >A. www.openca.org ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet Cons

Re: Another RSApkc Primer

1999-11-29 Thread Leland V. Lammert
very interested in pros and cons. TIA, Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet Consultants

Re: Another RSApkc Primer

1999-11-30 Thread Leland V. Lammert
At 01:08 PM 11/30/99 , you wrote: >"Leland V. Lammert" <[EMAIL PROTECTED]> writes: > > 1) Purchase an Apache like Stronghold (at $1K+ not an option for a small company). >Completely legal in the US? >Frankly, I find this baffling. I work for a small company (two p

Re: Another RSApkc Primer

1999-12-01 Thread Leland V. Lammert
ssl_pricing.html > >and what is your opinion? Interesting, .. reasonable price ($95) for an SSL toolkit. No help with the RSA license issue however, .. they also pass through the 2% fee. Lee ==== Leland V. Lammert

Re: ca/cert key gen?

1999-12-01 Thread Leland V. Lammert
ither > > the client nor the server are checking certificates, we're just using > > the encryption for now. Check out openca.org - we have not used their system, but it is supposed to be a standard CA implementation. Lee =========

Re: configuration

1999-12-22 Thread Leland V. Lammert
on is on the web site - http://www.openssl.org/docs/openssl.html Another source is the system you are integrating openssl *with* (e.g. Apache). Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist

Re: Seeking officers for Free-software-friendly CA

1999-12-22 Thread Leland V. Lammert
which they are not aware in most cases. I created our own cert two years ago, and just renewed it (recreated for another 365 days) for the second time. Nobody has complained to date! Lee ============ Leland V. Lammert

Re: openssl deperately needs some intro docs

1999-12-23 Thread Leland V. Lammert
At 04:56 PM 12/22/99 , you wrote: >"Leland V. Lammert" wrote: > >i don't want to sound ungrateful, but that document is useless for >someone >who wants to learn how to operate the thing. if the openssl people want >to get >people to start using it, they'

Re: Is it legal?

1999-12-27 Thread Leland V. Lammert
is a SW patent gone WAY off track. Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/I

Re: New Server Certificate

1999-12-28 Thread Leland V. Lammert
the location of the CERT in the httpsd.conf file. BTW - Verisign SHOULD have FAQs and docs for this process, .. you might want to contact them also. Lee ============ Leland V. Lammert[EMAIL PROTEC

Re: client cert is rejected - y2k?

2000-01-03 Thread Leland V. Lammert
the server did not see it. HTH, Lee ======== Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Net

Re: Seeking officers for Free-software-friendly CA

2000-01-04 Thread Leland V. Lammert
server to install the proper CERT you are no worse (to the user) than using a self-signed CERT (which we do). Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corp

Re: How to install openssl after download the tar file ?

2000-01-06 Thread Leland V. Lammert
Lee ==== Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet Consultants www

Re: How to install openssl after download the tar file ?

2000-01-06 Thread Leland V. Lammert
ile?? In any case, a tarball is typically source code, .. which is a REAL pain to compile on Win32. A far better approach would be to acquire one of the pre-build binaries. Lee ==== Leland V. Lammert[EMA

Re: Question

2000-01-08 Thread Leland V. Lammert
to use it after being asked to cease and desist, RSA may also be able to win a court case for damages. If you are worried about that, you can purchase one of the commercial flavors - Stronghold or RedHad Secure Server. Lee ========

Re: Need some help

2000-01-11 Thread Leland V. Lammert
ration and security installations for companies with international branches." Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corpo

Re: openssl deperately needs some intro docs

2000-01-11 Thread Leland V. Lammert
lly > > *knows* the library. > > > >Unfortunately you're in the US which may well cause problems :-( > >Steve. Steve, Please elaborate. With the current relaxation on US export regulations, I would think this no longer a problem?? Lee ======

New Export Restrictions

2000-01-13 Thread Leland V. Lammert
n without risk in the US to help clean up the openssl docs? Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Netw

Re: pine + ssl?

2000-01-21 Thread Leland V. Lammert
far easier to run over an SSH connection, would it not? Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet Consultants

Re: Building a Corporate CA

2000-01-25 Thread Leland V. Lammert
At 05:00 AM 1/24/00 , you wrote: >I've been quite unsucessfull in finding documentation about setting up a >corporate CA. > >Does anyone have some pointers for me? > >Thanks, > >A. www.openca.org (and mirrors) =========

Re: Commercial SSL in the US

2000-03-09 Thread Leland V. Lammert
ort encryption, .. but as long as we use international code there are no restrictions. Lee ======== Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Ne

Re: Commercial SSL in the US

2000-03-10 Thread Leland V. Lammert
happily mix the two, taking the 'trod upon' viewpoint, .. but I would recommend checking with your own lawyers to make a decision. Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist

Re: Commercial SSL in the US

2000-03-11 Thread Leland V. Lammert
ation. Those selling SSL applications, certainly, have reason to be cautious of RSAREF and patent issues, .. however your confirmation above about corporate use is exactly what we do, and I have been recommending for five years. Lee ========

Verisign/Thawte Atternatives?

2000-03-28 Thread Leland V. Lammert
rience pro/con?? TIA, Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Inte

Re: Verisign -- Want some free certificate over the Internet?

2000-03-28 Thread Leland V. Lammert
At 08:04 PM 3/28/00 , you wrote: >Want some free certificate from the Internet? >Try www.secureage.com What does this have to do with certs? The site is about a security application, .. not certs - have I missed something? Lee ==== Le

Re: Verisign -- Want some free certificate over the Internet?

2000-03-31 Thread Leland V. Lammert
nSSL (self certifying). Thanks, Lee ======== Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet Consultants

Re: [Re: ssh login, urgent help needed]

2000-04-20 Thread Leland V. Lammert
At 04:58 PM 4/19/00 , you wrote: >On Wed, 19 Apr 2000, Leland V. Lammert wrote: > >SSH has never had a GPL version, ssh-1.2.16 and previous were under >a free license but later versions were under successively more >restrictive licenses. > >Use OpenSSH :) *BUT* OpenSSH

Re: Certi

2000-04-26 Thread Leland V. Lammert
s. Lee ======== Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet Consultants

Re: certificate

2000-04-28 Thread Leland V. Lammert
.. so you might wish to revert back to the original again. Lee Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet Co

Re: Certificate Authority

2000-05-23 Thread Leland V. Lammert
Directory!?!?!?), so why cannot there be an Opensource one?!?!? I must have missed something in this thread? Is there a problem with openca (www.openca.org)?? Lee Leland V. Lammert[EMAIL PROTECTED]

Re: Free CA

2000-06-13 Thread Leland V. Lammert
connection. Other than that, I, for one, will continue to use our self-generated certs . Lee ==== Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Netwo

Re: Certificates

2000-07-24 Thread Leland V. Lammert
. >Can anyone give me some advice about this? You can also check out EquiFax - they have a standard CERT for $45, last time I checked. Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist

Re: Certificates

2000-07-24 Thread Leland V. Lammert
Lee ======== Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet Consultants w

Re: Specifying seprate Document roots for SSL VirtualHosts

2000-07-27 Thread Leland V. Lammert
Tom, The virtual hosts you have configured will not work. You must have a unique IP/Port combination for EACH SSL server. Use a separate IP for your hosts [or port] and everything will be copasetic. Lee At 01:03 PM 7/27/00, you wrote: >I can be more specific: > >Here's how I have it s

Re: transferring digital cert.

2000-08-28 Thread Leland V. Lammert
At 10:37 AM 8/28/00 -0500, you wrote: >Quick question. > >We are getting ready to do some major upgrades on our network, thus >moving everything off the old. How would I go about transfering our >digital certificates, ect. from one server to another? > >The reason I ask is that we use Verisign an

Re: OpenCA.org

2000-08-30 Thread Leland V. Lammert
At 10:39 PM 8/30/00 +0200, you wrote: >On Wed, Aug 30, 2000 at 09:58:21PM +0200, Arne Borkowski (borko.net) wrote: > > Hi, > > > > someone mentioned the URL http://www.openca.org/ > > > > However, I cannot establish a link with my browser to it. Is the URL wrong? > > Is the site down? Could somebo

Re: AW: OpenCA.org

2000-08-30 Thread Leland V. Lammert
At 01:21 AM 8/31/00 +0200, you wrote: >Hi, > >somewhere with *.interbusiness.it the tracert dies. > >But still I cannot access the site from here. However, I do not want to >bother the whole list with that problem. I'll keep on trying without >complainig here :-) 10 mi5-ny2-1.seabone.net (195.22

Re: Changing the information in certificate request

2000-09-05 Thread Leland V. Lammert
At 02:14 PM 9/5/00 +0200, you wrote: >Hello, > >Suppose that a user generates a certificate request, but enrolls partially >incorrect information in it (let's say (s)he filled the OU in other format >than how I'd like it to be; for example "Dept. 870" instead of just "870"). Ivan, I do not think

Re: install

2000-09-21 Thread Leland V. Lammert
At 08:39 AM 9/18/00 -0700, you wrote: >how do I get it to work on win 98. I have perl and turbo C++ by Borland. HELP Build a server. Lee __ OpenSSL Project http://www.openssl.org User Su

Re: changing of passphrase

2000-09-25 Thread Leland V. Lammert
At 05:53 PM 9/25/00 -0700, you wrote: >Hi, can someone help me? I'm trying to change the >passphrase that is use to start the ssl-apache. Thanks. Buy a new Cert. Lee __ OpenSSL Project h

Re: Error Message : IP address does not match the server name

2000-10-30 Thread Leland V. Lammert
At 11:17 AM 10/29/00 +0800, you wrote: >When I try to send mail or receive mail using the SSL >connection using Outlook 98 , the following error >message occurs . "IP address does not match the server >name" . > >So , I am wondering if this is due to DNS error ? That would mean that the Reverse

Re: Always ask password when start Apache httpsd?

2000-11-15 Thread Leland V. Lammert
(which we always do here, .. I, for one, would not wish to schlep down to the NOC in case the UPS ran out!), you need to remove the passphrase from the key. IIRC, the procedure is in the FAQ. >Thank you in advance! You're welcome. Lee ====

RE: Certs: where to get them?

2001-01-02 Thread Leland V. Lammert
of solving! I, for one, *use* 'snake oil' certificates because I wish to *remind* the user that they must trust the issuer of the certificate (displayed in the dialog box), .. paying $125 (or even $400) a year is not the proper way to earn that trust. I guess that makes 6 cents! Lee

Re: Expired CA certificate

2001-01-10 Thread Leland V. Lammert
this CA certificate, or am I going to have to >generate a new CA? > >Thanks, >Wade When you generate the cert, specify '-days 365' for a year. Lee ======== Leland V. Lammert[EMAIL PROTECTED]

Re: Expired CA certificate

2001-01-10 Thread Leland V. Lammert
that would provide a very BIG security hole ! Lee ======== Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet Consultants

Re: Secure Telnet

1999-03-19 Thread Leland V. Lammert
that *seems* like the best option for this choice. Thanks again, .. SSH might be the solution after all, but NOT (most likely) with the standard client program. Lee ======= Leland V. Lammert, PhDChief Scientist Omnitec

RE: Secure Telnet

1999-03-19 Thread Leland V. Lammert
At 11:41 AM 3/18/99 -0600, you wrote: >J. River's ICE.PPN might be just what you need. >http://www.jriver.com/ > Thanks! Someone else had mentioned jriver, .. but I did not notice that ICE.PPN product! Lee ======= Leland V

Re: While there is a discussion on RSA

1999-04-28 Thread Leland V. Lammert
ood question! I thought RedHat Secure Server used mod_ssl? How can that include an RSA license? Lee ======= Leland V. Lammert, PhDChief Scientist Omnitec Corporation Network Consulting [

Re: OT: Hardware proxy?

1999-07-22 Thread Leland V. Lammert
altime security updates (daily). Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Inte

Re: Build-your-own Certificate Authority

1999-07-28 Thread Leland V. Lammert
inking that all I have to do is generate a separate >certificate and use it to sign the site certificates? > Steven, Check out www.openca.org - I have seen it mentioned in threads here, .. though I have not checked it out myself. Lee ============

Re: Huh? Waiting for pass phrase?

1999-07-30 Thread Leland V. Lammert
1) Enter the pass phrase every time you reboot the server or start Apache 2) Remove the pass phrase via your SSL toolkit (may require the proper mail list) Lee ======== Leland V. Lammert[EMAIL PROTECTED] Chief Sci

Re: please help a newbie

1999-08-16 Thread Leland V. Lammert
ices model (e.g. https). Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet Con

Re: CA and Certificates

1999-08-20 Thread Leland V. Lammert
I just copy it over the old >dummy certificate currently being used by my apache server? > Yes, assuming the names match. Lee Leland V. Lammert[EMAIL PROTECTED] Chief Scientist

Re:

1999-08-26 Thread Leland V. Lammert
At 12:56 AM 8/27/99 , you wrote: >anybody somebody Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet Consultants www.omnitec.

Re: problems

1999-08-30 Thread Leland V. Lammert
not inside a virtual host). Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet

Re: U.S. To Allow Export Of Encryption Products

1999-09-17 Thread Leland V. Lammert
rewall and cannot even download 128-bit encryption products! Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation Network/Internet

Re: Problems with Outlook Express 5 (SMTP) and stunnel

1999-10-06 Thread Leland V. Lammert
eyond your capabilities, you might look for an ISP that offers secure web hosting. Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation

Re: open source COMMUNITY?

1999-10-07 Thread Leland V. Lammert
Root //secure/html >ErrorLog //secure/logs/error_log >TransferLog //secure/logs/access_log > Lee ==== Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corporation

RE: Alert

1999-10-13 Thread Leland V. Lammert
they often are innocent parties to virus spread. Only with valid signatures (i.e. trusted vendors) is it even safe to consider opening executable content. Of course, .. those of you with Outlook have a problem before you open the program !! Lee =========

Re: Apologies

2001-02-21 Thread Leland V. Lammert
Sorry folks, I meant to direct the previous message directly to the miscreant that does not know how to use a mailing list. Lee __ OpenSSL Project http://www.openssl.org User Support Mai

Re: REMOVE

2001-02-21 Thread Leland V. Lammert
At 06:24 PM 2/21/01 +0600, you wrote: >REMOVE Hey dufus, THIS IS SPAM! It is NOT polite, .. nor it is appreciated by the rest of us. There are a lot of folks out here that see enough email at the present time, .. please do NOT bother us with YOUR problems. There is ABSOLUTELY NO BENEFIT to tr

Re: NAT + mod_ssl

2001-02-22 Thread Leland V. Lammert
someone else responded, many of the NAT boxes will do this, .. but I have seen some that will not. Lee ============ Leland V. Lammert[EMAIL PROTECTED] Chief Scientist Omnitec Corpora