Re: reduce default OCSP timeouts.

2013-10-14 Thread Gervase Markham
On 11/10/13 21:50, Wan-Teh Chang wrote: > I would use a timeout of 5 seconds. 3 seconds seem a little short. > > I agree 10 seconds are too long. Can you expand on what criteria you are using to make these judgements? Fetching the OCSP response takes 2RTT, as Camilo said. So if your RTT is 1000m

Re: set default on for SHA2 for TLS1.1+ on firefox

2013-10-14 Thread Mountie Lee
Hi. TLS1.2 with SHA256 can be enabled manually.(default disabled) advanced users have to to as following "about:config" at address bar ==> agree using advanced feature ==> set value of security.tls version.max to "3" see the link https://support.mozilla.org/en-US/questions/959936 On Tue, Oct