Re: New wiki page on certificate revocation plans

2014-08-07 Thread fhw843
Curious to know the process by which cert holders will get their certs‎ added to these lists. How much of that flow and the necessary security measures have been worked out?    Original Message   From: Richard Barnes Sent: Thursday, August 7, 2014 3:59 PM To: Rob Stradling Cc: mozilla-dev-tech-c

Re: Announcing Mozilla::PKIX, a New Certificate Verification Library

2014-08-07 Thread Richard Barnes
On Aug 5, 2014, at 1:25 PM, Brian Smith wrote: > On Tue, Aug 5, 2014 at 9:51 AM, wrote: >> Since updating to 31, I have not been able to log into a self signed web >> page: >> >> Secure Connection Failed >> >> An error occurred during a connection to taiserver:444. Certificate key >> usage

Re: New wiki page on certificate revocation plans

2014-08-07 Thread Richard Barnes
On Aug 7, 2014, at 9:47 AM, Rob Stradling wrote: > http://dev.chromium.org/Home/chromium-security/crlsets says: > "The limit of the CRLSet size is 250KB" > > Have Mozilla decided what the maximum OneCRL size will be? No, we haven't. The need for a limit largely depends on whether we cover E

Re: New wiki page on certificate revocation plans

2014-08-07 Thread Rob Stradling
http://dev.chromium.org/Home/chromium-security/crlsets says: "The limit of the CRLSet size is 250KB" Have Mozilla decided what the maximum OneCRL size will be? On 01/08/14 03:07, Richard Barnes wrote: Hi all, We in the Mozilla PKI team have been discussing ways to improve revocation checking i