Re: Personal crypto device (or smart card) success stories?

2007-09-06 Thread Nelson Bolyard
No other success stories? Are there really no other readers of this list using their own personal crypto devices for reading/writing signed and/or encrypted email? Maybe NSS is way overkill for the needs of mozilla users? ___ dev-tech-crypto mailing lis

KeyGen2 - Replacement for [KeyGen/generateCRMFrequest/Xenroll]

2007-09-06 Thread Anders Rundgren
Hi All, I don't know if any of you following this list are interested in new standards for on-line provisioning of PKI. In case you are, you may contact me regarding the specification of a scheme that is intended to eventually replace the hodgepodge of sub-standard and entirely proprietary scheme

Re: Enabling FIPS mode

2007-09-06 Thread Wan-Teh Chang
Geoff, Just wanted to provide some additional info to Bob's reply. There are three ways to configure NSS in the FIPS mode. In our FIPS Security Policy, we describe the low-level method for people who use only the NSS software cryptographic module (i.e., libsoftokn3.so/softokn3.dll only). Most of

RE: Enabling FIPS mode

2007-09-06 Thread Gatfield, Geoffrey
I had read the security policy and thought that was the case. Seemed too easy so I just wanted confirmation. Thanks Geoff -Original Message- From: Robert Relyea [mailto:[EMAIL PROTECTED] Sent: Thursday, September 06, 2007 2:31 PM To: Gatfield, Geoffrey Cc: dev-tech-crypto@lists.mozilla.o

Re: Enabling FIPS mode

2007-09-06 Thread Robert Relyea
Gatfield, Geoffrey wrote: Hello, I'm working on converting our server to FIPS compliance. We provide user authentication using LDAP (with Mozilla LDAP C SDK) which uses NSS. To provide FIPS compliance can we just replace the NSS library with the FIPS compliant version? Does NSS automatically