Re: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Eddy Nigg (StartCom Ltd.)
Frank Hecker: > > Robin Alden has already responded to questions 1.a, 1.b, and 1.c. I > don't see any outstanding issues relating to these questions. > Your list is correct and Robin Alden has addressed all issues which were raised. I intend to reply to each in a summarized form. > Question 2

Re: Failed to decrypt on smart card based-PKCS module

2008-03-24 Thread joemar . mante
Wow Thanks.. should I also specify some parameters on my make command ?? I'm currently using this: make -e -f client.mk build Im kinda new in Linux, been developing most stuff in windows TIA ___ dev-tech-crypto mailing list dev-tech-crypto@lists.mozil

Re: certificate database of Thunderbird

2008-03-24 Thread Frank Hecker
Ron Lu wrote: > i have another question concernig the licence of nss and jss. > we have made use of nss security tools and jss and now we want to integrate > our > program into another software "CardManager" which manage Chipcards we use at > our university. Does it matter to choose any of the thr

Re: certificate database of Thunderbird

2008-03-24 Thread Wan-Teh Chang
On Mon, Mar 24, 2008 at 2:58 PM, Ron Lu <[EMAIL PROTECTED]> wrote: > Wan-Teh wrote: > > The issues you need to consider include: > > - Do you need to link NSS with your own code? If so, is your own code > > open source? Under what license? > > - Do you modify NSS or just use NSS unmodified?

Re: certificate database of Thunderbird

2008-03-24 Thread Ron Lu
Wan-Teh wrote: > The issues you need to consider include: > - Do you need to link NSS with your own code? If so, is your own code > open source? Under what license? > - Do you modify NSS or just use NSS unmodified? if i only use NSS unmodified, what would you say is the more appropriate licen

Re: certificate database of Thunderbird

2008-03-24 Thread Wan-Teh Chang
On Mon, Mar 24, 2008 at 1:55 PM, Ron Lu <[EMAIL PROTECTED]> wrote: > > i have another question concernig the licence of nss and jss. > we have made use of nss security tools and jss and now we want to integrate > our program into another software "CardManager" which manage Chipcards we use > at

Re: certificate database of Thunderbird

2008-03-24 Thread Ron Lu
hi, thank you for your reply. i have another question concernig the licence of nss and jss. we have made use of nss security tools and jss and now we want to integrate our program into another software "CardManager" which manage Chipcards we use at our university. Does it matter to choose any of

Re: Failed to decrypt on smart card based-PKCS module

2008-03-24 Thread Nelson Bolyard
[EMAIL PROTECTED] wrote, On 2008-03-24 03:17: > Thanks! > > I just built a debug version of Thunderbird but it doesn't seem to be > logging (no log file was created) I'm using MINGW32 with WindowsXP and > MSVC 6.0 > > i have followed the Technical Notes "Using the PKCS #11 Module Logger" > and ha

RE: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Eddy Nigg (StartCom Ltd.)
Thanks to Robin from Comodo to address all issues I've raised (I think you've touched everything so far). Thanks to Frank for your reply as well. Please give me some time to evaluate all your answers, thoughts and suggestions and prepare a decent reply. Most likely I'll be ready to post tomorro

RE: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Robin Alden
Eddy, You said: > - Unlucky formulation of "4.2.1 Secure Server Certificates Validation > Process" (Code Signing versus Server Certs). I agree. 4.2.1 could do with a different sub-title, given its frequent re-use. > - Subsection 1 doesn't apply I guess. Subsection 1 did not apply for code

RE: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Robin Alden
Eddy, You said: > 3.) The Comodo Certification Practice Statement, Version 3.0 and > other CPS amendments state certificate validity of up to ten years > and beyond. I couldn't find any provision in case the domain name > expires. It isn't clear what happens if an identity or organizatio

Re: certificate database of Thunderbird

2008-03-24 Thread Wan-Teh Chang
On Sun, Mar 23, 2008 at 4:04 PM, Ron Lu <[EMAIL PROTECTED]> wrote: > Hi, > > in firefox certificates are stored in cert8.db. Can someone tell me where > the corresponding database file for Thunderbird is located? And do you know > whether there are tools enabling access to and modification of th

Re: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Frank Hecker
Eddy Nigg (StartCom Ltd.) wrote: > I suggest the following at this stage: > > Adding an entry at the bug that > - requests officially a statement and answering of the issues which have > been raised [3]; As far as I can tell, here are the most recent questions you've raised (first four in a mes

Re: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Eddy Nigg (StartCom Ltd.)
Florian Weimer: > * Eddy Nigg: > > >> The CAs should prevent issuance of certificates which are suspected to >> be used for phishing attempts and other fraud. This includes cases like >> real domain names (mic0s0ft.com, paypa1.com) and sub domain names >> (paypal.nelson.com). >> > > Is t

Re: Failed to decrypt on smart card based-PKCS module

2008-03-24 Thread joemar . mante
Thanks! I just built a debug version of Thunderbird but it doesn't seem to be logging (no log file was created) I'm using MINGW32 with WindowsXP and MSVC 6.0 i have followed the Technical Notes "Using the PKCS #11 Module Logger" and have set the proper Environment variables. I can run thunderbird

Re: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Florian Weimer
* Eddy Nigg: > The CAs should prevent issuance of certificates which are suspected to > be used for phishing attempts and other fraud. This includes cases like > real domain names (mic0s0ft.com, paypa1.com) and sub domain names > (paypal.nelson.com). Is there any CA which is part of the browse

RE: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Robin Alden
Eddy, You said: > 2.) The Comodo Certification Practice Statement, Version 3.0 and other > CPS amendments state that wild card certificates are domain name > validated only (depending on product or trade mark). How does Comodo > prevent or control misuse of wild card certifi

RE: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Robin Alden
Eddy, You asked: > Additionally I would like to know to whom belongs the company LITESSL > CA, INC. and its relationship to Comodo CA Ltd. as referenced in the > audit report from KPMG > (https://cert.webtrust.org/SealFile?seal=636&file=pdf). What are its > relations to AddTrust AB, Swe

Re: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Eddy Nigg (StartCom Ltd.)
Robin Alden: > As to your request to "refrain from further advancing of their > inclusion/upgrade request" - well, I'd rather answer the questions in this > forum, if possible. > > Hi Robin, Yes, we were promised that you or some other representative of Comodo would address the questions raise

RE: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Robin Alden
Eddy, I'm sorry I haven't got around to answering your questions until now. You wrote: > 1.) The audit report for non-EV operations refers to the CA operation at > Manchester. The audit report for EV refers to the CA operations at New > Jersey. One of the roots is from a company operatin

RE: Comodo request for EV-enabling 3 existing roots

2008-03-24 Thread Robin Alden
Eddy, I'm sorry I haven't got around to answering your questions until now. You wrote: > 1.) The audit report for non-EV operations refers to the CA operation at > Manchester. The audit report for EV refers to the CA operations at New > Jersey. One of the roots is from a company operatin