On 05.05.2010 11:05, M.Hunstock wrote: > In the meanwhile it appears in the correct tab, but the trust chain > cannot be built. It says something like "this certificate could not be > verified for an unknown reasen" (I have a localized version of FF).
Well.. "if you do everything right, everthing works fine" I forgot to set some attributes in the PKCS#11 storage object containing the certificate, including the issuer DN. Apparently that was the reason for the failing behaviour. I haven't found that earlier because I assumed NSS looks for the values in the X.509 certificate itself... Thanks to all who replied Matthias -- dev-tech-crypto mailing list dev-tech-crypto@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-tech-crypto