Adding certificates to the nss database

2007-07-02 Thread cdolivei . bugzilla
I'm having a tricky problem. What I am trying to do is to add an object signing certificate to the NSS database. This can be done using certutil, yes. But this is a xulapp that uses nsINSSCertCache, which I fear is causing problems. I need to know how to import object signing certificates to the d

Re: libnssckbi.so problems with ROOt ca ceritifcate Trust flags

2007-07-02 Thread Nelson B
samrat saha wrote: > Dear Nelson, Below is the problem in detail.. > > I am trying to extract the built in Root CA certificate in the nss to a > certificate bag file (PEM format dumbed from libnssckbi.so). Using the > about certificate bag file i am trying to build a database during > intilization

Re: Link-fingerprints: weak unless link received securely

2007-07-02 Thread David E. Ross
On 7/2/2007 2:39 AM, Gervase Markham wrote [in part]: > At the moment, spotting things like the Wordpress download tarball > trojan took quite a while, because someone had to bother to check the > code against the published MD5sum manually - and who does that? Maybe > just you :-) When an MD5 o

Re: Verifying Signature produced by crypto.signText: signVer not working

2007-07-02 Thread dev
Hey, Both commands work perfectly fine, and I get my keys as well the cert. [EMAIL PROTECTED] bin]# ./certutil -L -d ~/.mozilla/firefox/ 3y9snp1l.totallynew/ CA Cert Signing Authority - Root CA CT,C,C CAcert WoT User's Root CA ID u,u,u [EM

Re: Link-fingerprints: weak unless link received securely

2007-07-02 Thread Gervase Markham
Nelson B wrote: > One needs a trusted source AND a trusted channel to that source. Yes, although there's also a "herd immunity" feature, as I discuss below. At the moment, spotting things like the Wordpress download tarball trojan took quite a while, because someone had to bother to check the c