Re: Dealing with third-party subordinates of T-Systems and others

2008-10-09 Thread Eddy Nigg
On 10/10/2008 01:48 AM, Ian G: > > Wl whatever it is, you'd like it; read on. > Actually I did :-) > > IN CONSIDERATION OF YOUR AGREEMENT TO THESE TERMS, YOU ARE ENTITLED > TO USE VERISIGN INFORMATION AS SET FORTH HEREIN. > > https://www.verisign.com/repository/rpa.html > > Now, curi

Re: Dealing with third-party subordinates of T-Systems and others

2008-10-09 Thread Ian G
Eddy Nigg wrote: > On 10/09/2008 05:33 PM, Ian G: >> The goals of Mozo are written somewhere else, and they only speak >> softly to the issue of security from memory > > I obviously meant the goals of the Mozilla CA Policy and NSS, which > isn't used only by Mozilla (Firefox) but lots of differen

Re: Dealing with third-party subordinates of T-Systems and others

2008-10-09 Thread Eddy Nigg
On 10/09/2008 05:33 PM, Ian G: > > The goals of Mozo are written somewhere else, and they only speak > softly to the issue of security from memory I obviously meant the goals of the Mozilla CA Policy and NSS, which isn't used only by Mozilla (Firefox) but lots of different software. NSS is a cry

Re: Unable to change password of FIPS enabled internal key token

2008-10-09 Thread Wan-Teh Chang
2008/10/9 Ian G <[EMAIL PROTECTED]>: > > Why is there DSA key generation but not RSA key generation? e.g., > page 10, pt 23. This is because CMVP doesn't test RSA key generation. On the RSA validation list at http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsaval.html you can see that only Si

Re: Unable to change password of FIPS enabled internal key token

2008-10-09 Thread Kyle Hamilton
2008/10/9 Ian G <[EMAIL PROTECTED]>: > David Stutzman wrote: >> The security policy in case anyone is interested and doesn't have it: >> http://www.mozilla.org/projects/security/pki/nss/fips/secpolicy.pdf > > Thanks Dave, > > I'm interested, and flicked through, but most of it is way above my > pay

Re: Microtec CA inclusion request

2008-10-09 Thread István Zsolt BERTA
> A plain text version would be extremely helpful. Concerning machine > translation, I think I'll be alright ;-) I have attached a plain text version to Bug 370505, it is available here: https://bugzilla.mozilla.org/attachment.cgi?id=342436 I still don't think a machine translation will be of any

Re: Dealing with third-party subordinates of T-Systems and others

2008-10-09 Thread Ian G
Eddy Nigg wrote: > On 10/02/2008 10:23 PM, Frank Hecker: > > > > Our goal here is to avoid having to evaluate lots and lots of > > subordinate CAs, and instead have the roots take care of their own > > subordinates and ensure they're compliant to policy. > > > > I'd like to pick this discussi

Re: Dealing with third-party subordinates of T-Systems and others

2008-10-09 Thread Eddy Nigg
On 10/02/2008 10:23 PM, Frank Hecker: > > Our goal here is to avoid having to evaluate lots and lots of > subordinate CAs, and instead have the roots take care of their own > subordinates and ensure they're compliant to policy. > I'd like to pick this discussion up once again and evaluate wha

Re: About the Cybertrust Educational CA certificate

2008-10-09 Thread Joe Orton
On Wed, Sep 17, 2008 at 05:06:55PM -0700, Wan-Teh Chang wrote: > On Wed, Sep 17, 2008 at 4:52 PM, Eddy Nigg <[EMAIL PROTECTED]> wrote: > > > > I've been banging my head against a wall here because of this FUD and > > about misinformation which is absolutely incorrect. Sad, because there > > are man

Re: Unable to change password of FIPS enabled internal key token

2008-10-09 Thread Ian G
David Stutzman wrote: > The security policy in case anyone is interested and doesn't have it: > http://www.mozilla.org/projects/security/pki/nss/fips/secpolicy.pdf Thanks Dave, I'm interested, and flicked through, but most of it is way above my pay grade. It looks like a huge investment put into

RE: Unable to change password of FIPS enabled internal key token

2008-10-09 Thread David Stutzman
The security policy in case anyone is interested and doesn't have it: http://www.mozilla.org/projects/security/pki/nss/fips/secpolicy.pdf Dave smime.p7s Description: S/MIME cryptographic signature ___ dev-tech-crypto mailing list dev-tech-crypto@lists.