Re: Certificate usage guide

2009-11-05 Thread Wes Kussmaul
does one get around that without turning off AV? Anyone know? Barbara is here to collect all that information. Wes Kussmaul aerow...@gmail.com wrote: Let's see. Difficulties: Everything. Management of expired certificates, both your own and others'. Management of revoked ce

Re: Making OCSP soft fail smarter

2009-10-13 Thread Wes Kussmaul
Not OK: 300 OCSP blocked by AV software, vendor fined $1 for each occurrence Wes Kussmaul Gervase Markham wrote: Firefox uses OCSP but, by default, any response other than a definite "is revoked" response is treated as "is not revoked". There is a user pref that allow

Re: How-to guide for email encryption

2008-11-18 Thread Wes Kussmaul
protracted, well planned, well executed educational effort to get it to where it reaches the flash point, after which the adoption curve will look like fax in 1980. Wes Kussmaul boilingfrog.edu The information contained in this electronic message and any attachments to this message are intended f

Re: DNSSEC? Re: MITM in the wild

2008-11-15 Thread Wes Kussmaul
Eddy Nigg wrote: On 11/15/2008 05:19 PM, Florian Weimer: * Alaric Dailey: DNSSEC is an assertion of validitity of the DNS. EV certs assert that the business behind the cert is legit. Only that a legal entity exists (whether its "legitimate" is not checked). EV certificates are routinely issu

Re: MITM in the wild

2008-10-20 Thread Wes Kussmaul
on this page... http://osmio.org/cityhall_vehicles.html ...and click on the Apply link. And please keep in mind that this is just an illustration, not a live site. Wes Kussmaul QE Alliance ___ dev-tech-crypto mailing list dev-tech-crypto