Re: Amending Mozilla's Root CA cert policy with key size requirements

2007-05-04 Thread Robert Relyea
Eddy Nigg (StartCom Ltd.) wrote: Hi Robert, I just wondered about that one: Robert Relyea wrote: There is also a critical difference between the Hashing and the keysize. Once a CA chooses it's keysize, then all certs signed by that CA will be signed with that key. If 1024 bits is weak, t

Re: Thunderbird S/MIME: Interoperability problem with gpgsm (KMail / Claws Mail)

2007-05-04 Thread Nicholas Sushkin
Robert Relyea wrote: > Now technically KMail MUST implement RC2-40 (is the implementers > confusing RC2 with RC5?) according to the S/MIME spec (all > implementations must support RC2-40. I read the S/MIME spec differently. Quoting Section 2.7 from http://www.apps.ietf.org/rfc/rfc3851.html#sec-2.