Re: Amending Mozilla's Root CA cert policy with key size requirements

2007-05-01 Thread Paul Hoffman
At 11:54 AM -0400 5/1/07, Frank Hecker wrote: >Paul Hoffman wrote: >> At 2:12 PM -0700 4/30/07, Robert Relyea wrote: >>> I don't see a way around the legacy 1024 bit certs, but I would >>> definately want to see wording that will discourage the issuance of >>> new root certs that are less than

Re: Thunderbird S/MIME: Interoperability problem with gpgsm (KMail / Claws Mail)

2007-05-01 Thread Robert Relyea
Martin Hoefling wrote: Nelson B wrote: Hi Nelson and others... Nelson Bolyard wrote: I will send an encrypted reply to the email I received. We'll see if my correspondent can decrypt it. Just to reduce confusion about my mail: I am Martin Hoefling (using KMail/Kontact), and

Re: Amending Mozilla's Root CA cert policy with key size requirements

2007-05-01 Thread Paul Hoffman
At 2:12 PM -0700 4/30/07, Robert Relyea wrote: >I don't see a way around the legacy 1024 bit certs, but I would >definately want to see wording that will discourage the issuance of >new root certs that are less than 2048. From a cryptographic standpoint, such a policy would not make sense. All

Re: Dumping RC2/40

2007-05-01 Thread Nicholas Sushkin
Thunderbird already has a bug which could be interpreted as a request to disable RC2/40 - "S/MIME should not support weak crypto" (https://bugzilla.mozilla.org/show_bug.cgi?id=84213) Also, here's a thread in which author of gpgsm Werner Koch explains why he doesn't support RC2 and what he thinks a

Re: Amending Mozilla's Root CA cert policy with key size requirements

2007-05-01 Thread Frank Hecker
Paul Hoffman wrote: > At 2:12 PM -0700 4/30/07, Robert Relyea wrote: >> I don't see a way around the legacy 1024 bit certs, but I would >> definately want to see wording that will discourage the issuance of >> new root certs that are less than 2048. > > From a cryptographic standpoint, such a p

Re: Thunderbird S/MIME: Interoperability problem with gpgsm (KMail / Claws Mail)

2007-05-01 Thread Martin Hoefling
Nelson B wrote: Hi Nelson and others... > Nelson Bolyard wrote: > >> I will send an encrypted reply to the email I received. We'll see if >> my correspondent can decrypt it. Just to reduce confusion about my mail: I am Martin Hoefling (using KMail/Kontact), and Wurstsemmel is using Thunderbird

Re: Thunderbird S/MIME: Interoperability problem with gpgsm (KMail / Claws Mail)

2007-05-01 Thread Nelson B
Nelson Bolyard wrote: > I will send an encrypted reply to the email I received. We'll see if > my correspondent can decrypt it. I remembered that mozilla doesn't "import" (save) an encryption cert from an email unless it can validate that cert. That means the cert has to have been issued by a t