Re: (nss-3.12.6) unable to engage FIPS mode: "security library: invalid arguments."

2010-06-10 Thread Robin H. Johnson
On Fri, Jun 11, 2010 at 05:59:27AM +, Robin H. Johnson wrote: > On Thu, Jun 10, 2010 at 10:45:03PM +, Robin H. Johnson wrote: > > Testcase 2: > > (see attached minimal C code, based on posts to the list and used in the > > modutils source AND Mozilla). > Bah, forgot the actual file. > > Th

Re: (nss-3.12.6) unable to engage FIPS mode: "security library: invalid arguments."

2010-06-10 Thread Robin H. Johnson
On Thu, Jun 10, 2010 at 10:45:03PM +, Robin H. Johnson wrote: > Testcase 2: > (see attached minimal C code, based on posts to the list and used in the > modutils source AND Mozilla). Bah, forgot the actual file. The testcase has been run on Arch and Fedora now, and both of those cases it works

Re: S/MIME interop issue with Outlook 2010 beta

2010-06-10 Thread Kaspar Brand
On 10.06.2010 21:00, Nelson B Bolyard wrote: > Kaspar, would you care to clarify what you mean by "old" format there? > It appears to me that it always uses the KeyID format for the > SignerIdentifier. I'd call the KeyID format the "new" format. > > Maybe you mean "old" as in the Outlook 2010 def

Re: how to create a soft token using NSS?

2010-06-10 Thread 蓝黑王朝
hi,Robert Thanks for your reply.I want to add additional crypto services,and it use to disabling the pkcs12 certificate exporting.I don't want that user can export the pkcs12 certificate.Do you know other way that can disable the pkcs12 certificate exporting? thanks. 在 2010年6月11日 上午12:34,Robert

(nss-3.12.6) unable to engage FIPS mode: "security library: invalid arguments."

2010-06-10 Thread Robin H. Johnson
I was trying to package up the hmaccalc application from Fedora so we can have it in Gentoo as well, and noticed that it was failing when it tried to engage FIPS mode. Doing some backtracing, it seems FIPS isn't enabling at all on my system, as the DeleteInternalModule call is returning INVALID_AR

Re: S/MIME interop issue with Outlook 2010 beta

2010-06-10 Thread Nelson B Bolyard
On 2010-06-03 21:52 PDT, Kaspar Brand wrote: > On 03.06.2010 22:57, PDF3 SecureEmail wrote: >> I suspect that NSS is not supporting "sender key ID" yet/properly. > > If you replace "sender key ID" by RecipientIdentifier, then that > statement is true, yes. (Note, however that the MSFT moderator mi

Re: how to create a soft token using NSS?

2010-06-10 Thread Robert Relyea
On 06/09/2010 09:15 PM, 蓝黑王朝 wrote: > hi,all > > I want to create a soft token same as the firefox's "NSS Generic > Crypto Services" token. I've done many searches, including this group > for every message with *pkcs*11 in its title, and couldn't find > answers which would satisfy me. I'd appreciat

Re: Thunderbird problem with the search for certificates in the S-TRUST trust list service

2010-06-10 Thread Nelson B Bolyard
On 2010-06-10 07:49 PDT, Jean-Marc Desperrier wrote: > Nelson B Bolyard wrote: >> Fame and Glory await.:-) > > Which means a mention in http://www.mozilla.org/credits/ or about:credits : >We would like to thank our contributors, whose efforts make this > software what it is. [...] >Any su

Re: Thunderbird problem with the search for certificates in the S-TRUST trust list service

2010-06-10 Thread Jean-Marc Desperrier
Nelson B Bolyard wrote: Fame and Glory await.:-) Which means a mention in http://www.mozilla.org/credits/ or about:credits : We would like to thank our contributors, whose efforts make this software what it is. [...] Any such contributors who wish to be added to the list should send mail