Re: Update on DigiNotar and Entrust

2008-06-22 Thread Frank Hecker
Eddy Nigg wrote: > Perhaps Nelson can provide more information about the road map for CRL > fetching, but it will be soon supported by NSS. This would solve the > problem once it is. Note that there are other things besides CRL checking per se that I'd like to see in NSS. There seem to be a lot

Re: Update on DigiNotar and Entrust

2008-06-22 Thread Eddy Nigg
Frank Hecker: > For the record, Entrust understands what our concern is and has been > cooperative in trying to come up with a way to address it. However the > problem is that even if Entrust were to revoke DigiNotar's intermediate > CA certificate that would not help resolve the problem, for the r

Importing exporting JKS key to NSS db

2008-06-22 Thread Yevgeniy Gubenko
Hello, I need to create 2 public private key pairs: one on windows machine in JKS format (by keytool command) and the other on Solaris 10 machine in NSS database (certutil -G), on which NSS db exists. Then I have to 1.export public key from Solaris to Windows in JKS format 2.import public key fro

Re: Update on DigiNotar and Entrust

2008-06-22 Thread Kyle Hamilton
This sounds rather dangerously like a security-related design and implementation failure. In fact, this sounds so much like such that if it were up to me, I'd mark this lack of functionality as 'critical/urgent' in the NSS design path and get it done before anything else. -Kyle H On Sun, Jun 22,

Re: Update on DigiNotar and Entrust

2008-06-22 Thread Frank Hecker
David E. Ross wrote: > Has the failure by Entrust to enforce its policies against DigiNotar > been brought to the attention of Entrust's auditors? I think it should. For the record, Entrust understands what our concern is and has been cooperative in trying to come up with a way to address it. Ho