Re: Do big parts of security in "mozilla" suck?

2009-07-22 Thread Ian G
On 22/7/09 17:03, Udo Puetz wrote: On 21 Jul., 14:34, Eddy Nigg wrote: Udo, that's all fine and understood. What are the improvements you think should be made to Thunderbird (and/or Firefox) besides what you claim to be a bug in TB? Is the bug the only thing which prevents hardware tokens and c

Re: Do big parts of security in "mozilla" suck?

2009-07-22 Thread Udo Puetz
On 21 Jul., 14:34, Eddy Nigg wrote: > Udo, that's all fine and understood. What are the improvements you think > should be made to Thunderbird (and/or Firefox) besides what you claim to > be a bug in TB? Is the bug the only thing which prevents hardware tokens > and certificates to become mainstre

Re: CRMF encoding issues with window.crypto.generatedCRMFRequest()

2009-07-22 Thread nk
> >> That does seem strange.  We have a [2] explicitly encoding a [0] which > >> is an implicit bit string with no unused bits, apparently encapsulating > >> another bit string of length zero.  :-/ > > I have now modified our decoder to correctly recognize POPOPrivKey > > encoded as thisMessage, i.

RE: NSS, AIA, Bridge

2009-07-22 Thread Varga Viktor
>FF 3.5.0 and FF 3.5.1 do not support fetching of certs from AIA extension >URIs, nor fetching of CRLs from CDP extension URIs. The code to fetch >certs from AIA URIs is present, but Firefox has not yet put it into use. What was the cause to disable it?? >The code to do CRL fetching is not yet