Creating a certificate with elliptic curve keys

2006-12-07 Thread aaron . brice
I was trying to use certutil tool (from nss-3.11.4) to create a certificate with elliptic curve key, but I was getting an error about invalid algorithm. I had built the tools with NSS_ENABLE_ECC defined. I tracked the error down to lib/cryptohi/secsign.c file, in the SGN_NewContext() function: #i

Re: EDH only SSL server certificate : Do they need key agreement ?

2006-12-07 Thread Nelson B
Jean-Marc Desperrier wrote: > This is quite a generic question about SSL, but it might have an impact > on NSS. > > Let's imagine you have a strict policy of separating signature and > encryption certificates and want to apply it to your SSL server certificate. Today, NSS's libSSL only lets you

EDH only SSL server certificate : Do they need key agreement ?

2006-12-07 Thread Jean-Marc Desperrier
This is quite a generic question about SSL, but it might have an impact on NSS. Let's imagine you have a strict policy of separating signature and encryption certificates and want to apply it to your SSL server certificate. If you restrict your SSL server to only use to EDH protocols, you don

Re: Problem with crypto.Signtext and A PKCS #9 signing timeattribute

2006-12-07 Thread Alexis MUNYANDEKWE
Thank you Dave I got them Alexis On 12/6/06, David Stutzman <[EMAIL PROTECTED]> wrote: Alexis MUNYANDEKWE wrote: > Hi everybody > > I am trying to build an rpm package of this new release > nss-3.11.4-with-nspr-4.6.4.tar.gz > The problem i am getting is that i can not get files which were in