Re: Combining OCSP stapling with advance MITM preparation

2012-04-06 Thread Brian Smith
Kai Engert wrote: > The domain owner > could configure their server to include this OCSP response in all TLS > handshakes, even though this OCSP response is unrelated to the server > certificate actually being used. For complete protection, the real domain holder would have to staple all the OCSP

Re: Alternative for SGN_DecodeDigestInfo

2012-04-06 Thread Brian Smith
Robert Relyea wrote: > Why are they linking with Freebl anyway? It's intended to be a > private interface for softoken. It's a very good way to find > yourself backed into a corner. Right. This was a long time ago. You helped me add the J-PAKE implementation to Softoken after we discovered this p

NSS 3.13.4

2012-04-06 Thread Kai Engert
The NSS team has released NSS 3.13.4 CVS tag: NSS_3_13_4_RTM ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_13_4_RTM/ Please refer to https://bugzilla.mozilla.org/show_bug.cgi?id=741135 for the list of changes contained in this update. Kai -- dev-tech-crypto mailing list dev