Re: Policy Update Discussion: Third-Party SubCAs

2011-04-27 Thread Robert Relyea
On 04/27/2011 06:42 AM, Jean-Marc Desperrier wrote: > Jean-Marc Desperrier wrote: >> Johan Sys wrote: >>> [...] >>> We did some tests with name constraints with positive results: >>> SubCA with name constraint as follows : >>> Permitted >>> [1]Subtrees (0..Max): >>> DNS Name=.goodcompany.globalsign

Re: Policy Update Discussion: Third-Party SubCAs

2011-04-27 Thread Wan-Teh Chang
On Wed, Apr 27, 2011 at 6:42 AM, Jean-Marc Desperrier wrote: > Jean-Marc Desperrier wrote: >> >> Johan Sys wrote: >>> >>> [...] >>> We did some tests with name constraints with positive results: >>> SubCA with name constraint as follows : >>> Permitted >>> [1]Subtrees (0..Max): >>> DNS Name=.goodc

Re: Policy Update Discussion: Third-Party SubCAs

2011-04-27 Thread Jean-Marc Desperrier
Jean-Marc Desperrier wrote: Johan Sys wrote: [...] We did some tests with name constraints with positive results: SubCA with name constraint as follows : Permitted [1]Subtrees (0..Max): DNS Name=.goodcompany.globalsign Excluded=None Issued cert www.goodcompany.globalsign passes. Anything else i

Re: Importing client SSL certificate onto external PKCS#11 token

2011-04-27 Thread james07
> There used to be a 'logout all' button somewhere in the browser. I don't > know if it still exists. That button would flush all our SSL caches and > force full handshakes. Thanks... logoutAndDropAuthenticatedResources() did it for me. -- View this message in context: http://old.nabble.com/Im