Re: Comment on tls-srp enhancement?

2007-12-07 Thread Steffen Schulz
On 071208 at 01:25, Nelson Bolyard wrote: > In your case, you have attached a patch, and (I gather) you're seeking > review of the patch (a necessary precursor to commitment). Bugzilla has > a way to mark a patch with a review request. Doing so causes that > patch to appear on some reviewers queu

Re: PKI Book reccomendation?

2007-12-07 Thread Brad Hards
On Saturday 08 December 2007 11:31:50 am Nelson Bolyard wrote: > I need a way to bring some people up to speed on the details of PKI and > RFC 3280, ideally without me spending a lot of time teaching. > > I'm hoping there's a good book that offers a tutorial about PKI, and > explains certs, CRLs, O

Re: PKI Book reccomendation?

2007-12-07 Thread Kyle Hamilton
I haven't read it yet, but a quick Google search turns up http://ospkibook.sourceforge.net/, the Open-Source PKI Book? -Kyle H On Dec 7, 2007 4:31 PM, Nelson Bolyard <[EMAIL PROTECTED]> wrote: > I need a way to bring some people up to speed on the details of PKI and > RFC 3280, ideally without me

PKI Book reccomendation?

2007-12-07 Thread Nelson Bolyard
I need a way to bring some people up to speed on the details of PKI and RFC 3280, ideally without me spending a lot of time teaching. I'm hoping there's a good book that offers a tutorial about PKI, and explains certs, CRLs, OCSP, and the (IETF) standard extensions for certs and CRLs. It needs to

Re: Comment on tls-srp enhancement?

2007-12-07 Thread Nelson Bolyard
Steffen Schulz wrote, On 2007-12-07 07:43: > I was hoping for some feedback on bug 405155, which adds support for TLS-SRP. > Are the core devs that busy right now? The NSS team has lost 3 staff members this year, and those of us who remain are very busy, yes. We're (hopefully) nearing the end of

Re: Terminating SSL on the web proxy

2007-12-07 Thread Nelson Bolyard
Florian Weimer wrote, On 2007-12-07 02:54: > Is it possible to configure NSS (or, more precisely, Firefox) to > terminate SSL connections on the web proxy, so that the proxy receives > requests in the clear (and handles the certificate verification)? I think, but am not certain, that you're descri

Re: SwissSign root CA certificate inclusion request

2007-12-07 Thread Frank Hecker
Frank Hecker wrote: > Therefore absent objection tomorrow (Friday November 30) I am going to > officially approve inclusion of the three SwissSign root CA > certificates, and proceed with the other steps needed to get the certs > into NSS. Well, I was a week late, for which I apologize. My appr

Comment on tls-srp enhancement?

2007-12-07 Thread Steffen Schulz
Hi all, I was hoping for some feedback on bug 405155, which adds support for TLS-SRP. Are the core devs that busy right now? (I also thought subscribing to this list would enable me to follow the current development around nss/psm. Do you just use bugzilla?) regards, steffen -- Bildet Olsenb

Re: TURKTRUST root CA certificate inclusion request

2007-12-07 Thread Eddy Nigg (StartCom Ltd.)
Michael Ströder wrote: > Well, I think if the CA clearly states in its CP/CPS that the users > (subscribers and relying participants) of the issued certificates SHALL > be solely "local" users it does not matter whether Mozilla is a product > used globally. But for most CAs issuing SSL/TLS certs th

Re: TURKTRUST root CA certificate inclusion request

2007-12-07 Thread Michael Ströder
Eddy Nigg (StartCom Ltd.) wrote: > Michael Ströder wrote: >> I agree with Eddy on this. When defining cert profiles for CAs I always >> take into consideration the set of relying participants. If the certs >> are to be used globally they SHOULD be readable to the international >> public like other

Re: TURKTRUST root CA certificate inclusion request

2007-12-07 Thread Eddy Nigg (StartCom Ltd.)
Michael Ströder wrote: > I agree with Eddy on this. When defining cert profiles for CAs I always > take into consideration the set of relying participants. If the certs > are to be used globally they SHOULD be readable to the international > public like other international legal documents. This is

Terminating SSL on the web proxy

2007-12-07 Thread Florian Weimer
Is it possible to configure NSS (or, more precisely, Firefox) to terminate SSL connections on the web proxy, so that the proxy receives requests in the clear (and handles the certificate verification)? ___ dev-tech-crypto mailing list dev-tech-crypto@list

Re: TURKTRUST root CA certificate inclusion request

2007-12-07 Thread Michael Ströder
Eddy Nigg (StartCom Ltd.) wrote: > > Now, you are right that this is certainly fine for people in the > knowledge of the respective language and character set. But what about > the rest? How can somebody make a judgment on the basis of the > certificate details if the vast majority can't read it?