Re: Problem with JSS PFX when attempting to decode a p12 file

2006-12-08 Thread neil williams - Sun Microsystems - Santa Clara United States
I'll be looking into this problem. At first glance at the code I noticed a comment which says "this code still has some problems reading PKCS12 file generated with Communicator". Is your PFX file one of these? There some comments in the pk12 code that mention problems with old implementations.

Re: EDH only SSL server certificate : Do they need key agreement ?

2006-12-08 Thread Jean-Marc Desperrier
Jean-Marc Desperrier wrote: The second usage is much more recent and I think it might be in error. If not, then in order to be coherent the requirement for key exchange in DSA certificates must be removed. I forgot one possibility : Update the definition of key encipherment to say that it ful

Re: EDH only SSL server certificate : Do they need key agreement ?

2006-12-08 Thread Jean-Marc Desperrier
Nelson B wrote: Jean-Marc Desperrier wrote: >> [Key agreement with DHE/DH ssl ciphersuites] So theorically should it be required or not ? And does NSS required it ? I think the answer might be "no" to the first and "yes" to the second, which would then be a bug in NSS. https://bugzilla.mozi