Re: NSS and PKCS#11 versions of modules

2008-12-09 Thread Nelson Bolyard
Robert Relyea wrote: > Martin Paljak wrote: >> Thanks for tips! Could you point me to the line in spec where it says >> that slots can only be added. I cant find the place where it forbids >> removing. >> > That's what I get for not checking the spec after the meeting in which > we discussed th

Re: mod_nss OCSP failover to CRL

2008-12-09 Thread Robert Relyea
sg4all wrote: Hi, I'm trying to set up a apache webserver with mod_nss. When available, OCSP should be used to verify the validity of the certificate. When the OCSP is unavailable, CRLs are used. I installed the CRLS, and configured everything. (My nss.conf is included in this message). Wh

mod_nss OCSP failover to CRL

2008-12-09 Thread sg4all
Hi, I'm trying to set up a apache webserver with mod_nss. When available, OCSP should be used to verify the validity of the certificate. When the OCSP is unavailable, CRLs are used. I installed the CRLS, and configured everything. (My nss.conf is included in this message). When I comment out "

Re: SECOM Trust EV root inclusion request

2008-12-09 Thread Frank Hecker
Frank Hecker wrote: There was apparently some sort of mix-up between the SECOM Trust folks and Kathleen and me regarding getting the latest audit report; they thought they had sent us something, but we apparently didn't get it. Kathleen is going to try to straighten it out. As it turns out, t

Re: SECOM Trust EV root inclusion request

2008-12-09 Thread Frank Hecker
Eddy Nigg wrote: Frank, it's not clear to me why their audit report is secret. One report from 2007 is posted at bugzilla, an updated one isn't. Why is that? There was apparently some sort of mix-up between the SECOM Trust folks and Kathleen and me regarding getting the latest audit report; th

Re: NSS and PKCS#11 versions of modules

2008-12-09 Thread Robert Relyea
Martin Paljak wrote: Thanks for tips! Could you point me to the line in spec where it says that slots can only be added. I cant find the place where it forbids removing. That's what I get for not checking the spec after the meeting in which we discussed this. The original agreement was that

Re: UTF8 support in the Firefox certificate store?

2008-12-09 Thread Nelson B Bolyard
[EMAIL PROTECTED] wrote, On 2008-12-09 01:55: > Just uploaded the certificate in DER and PEM file format. > It can be found here: > www.boraxx.nl/Mozilla/Thai.der > www.boraxx.nl/Mozilla/Thai.crt The CN and OU attributes in that cert, which (as I understand it) you have said are UTF8 strings, are

Signature and Encryption with Mozilla

2008-12-09 Thread Tóth Zoltán
Hello, I am quite new with Mozilla crypto. My aim is to port a smartcard-based application into a Firefox application with Javascript. After surfing the internet for days I am still unsure about what Mozilla is able to do with smartcards. I need signing/encrypting/decrypting XML-s. I tried to inve

Re: UTF8 support in the Firefox certificate store?

2008-12-09 Thread michael
Just uploaded the certificate in DER and PEM file format. It can be found here: www.boraxx.nl/Mozilla/Thai.der www.boraxx.nl/Mozilla/Thai.crt The required CA chain can be found here: www.boraxx.nl/Mozilla/ChainUCAcert.pem ___ dev-tech-crypto mailing list