Using Microsoft Authenticode cert with signtool?

2007-03-14 Thread kcsasquatch
Hi, I have a MS Authenticode code signing cert from Verisign that I use to sign executables on Windows. I would also like to use this to generated signed .jar files for use with the firefox browser. I am currently facing the roadblock that signtool (v 3.11.2) expects the cert and its private key

Re: Using Microsoft Authenticode cert with signtool?

2007-03-14 Thread Arshad Noor
See if the MS-certutil version gives you an option to convert your private-key and certificate to a PKCS#12 file (PFX). If it does, then do so and then you can import the P12 file into the Mozilla keystore with Mozilla-certutil. Arshad Noor StrongAuth, Inc. kcsasquatch wrote: Hi, I have a MS

Re: Expiration of trust roots

2007-03-14 Thread Paul Hoffman
At 10:00 AM + 3/14/07, Gervase Markham wrote: Paul Hoffman wrote: A related question that I was intending to do some research on: if a trust anchor ("trusted root" in this thread) has an expiration date in the past, doe NSS still treat it as a trust anchor, or does it ignore it? I can't

Revision of Contributors Agreement

2007-03-14 Thread Gervase Markham
We are revising the Mozilla project Contributors Agreement (CVS access agreement) to address deficiences caused by the passage of time, and the upcoming problem that if and when we migrate away from CVS, a lot of the document will become inappropriate. The new document is an agreement with a le

Re: Debugging a SSL transaction on Firefox 2.0.x

2007-03-14 Thread Jean-Marc Desperrier
Nelson Bolyard wrote: Jean-Marc Desperrier wrote: Of these, I would say that TLS hello extensions have experienced the most problems, due to servers that do not ignore them (which the RFCs require) and instead reject the connections. Interesting, I didn't know it was alredy sent by default. T

Re: Expiration of trust roots

2007-03-14 Thread Gervase Markham
Paul Hoffman wrote: A related question that I was intending to do some research on: if a trust anchor ("trusted root" in this thread) has an expiration date in the past, doe NSS still treat it as a trust anchor, or does it ignore it? I can't say for certain because I haven't seen the code, but

Re: Restricting roots to one TLD

2007-03-14 Thread Gervase Markham
Bob Relyea wrote: In addition, we only parse these kinds of constraints on intermediate certs (we currently don't have a mechanism to place name constraints on a trusted root. Even if the trusted root had constraints itself, they would be ignored once we identify the cert as trusted. Would so