Re: Multiple certificate databases with NSS 3.11

2006-09-12 Thread Kai Engert
Bob Relyea wrote: Matthew Gertner wrote: We want our extension to have its own certificate database, separate from the one used by Firefox. Apparently this will be possible with NSS 3.11, but I was told that there might be an issue with the internal data structures. If PSM handles global initi

Re: Multiple certificate databases with NSS 3.11

2006-09-12 Thread Bob Relyea
Matthew Gertner wrote: We want our extension to have its own certificate database, separate from the one used by Firefox. Apparently this will be possible with NSS 3.11, but I was told that there might be an issue with the internal data structures. If PSM handles global initialization, will ou

signText() was: The Mozilla trust model & FIPS201

2006-09-12 Thread Anders Rundgren
According to other people, this is just one of many flaws in signText (). Apparently it does not accept the NR bit either. Essentially the whole filtering thing is upside-down. In an on-line scenario it is the relying party that should specify what kind of clients certs that it will accept. The

Multiple certificate databases with NSS 3.11

2006-09-12 Thread Matthew Gertner
We want our extension to have its own certificate database, separate from the one used by Firefox. Apparently this will be possible with NSS 3.11, but I was told that there might be an issue with the internal data structures. If PSM handles global initialization, will our shared lib be able to