Re: TLS ESNI and HelloRetryRequest in Firefox 64, Firefox Nightly

2019-01-04 Thread sjw
Is this already implemented? [1] is not yet fixed and [2] does not work for me with current Nightly. [1] https://bugzilla.mozilla.org/show_bug.cgi?id=1494901 [2] https://www.cloudflare.com/ssl/encrypted-sni/ Am 04.01.19 um 17:13 schrieb Hubert Kario: > On Thursday, 3 January 2019 11:45:25 CET Al

SHA-1 with 'notAfter >= 2017-1-1'

2016-01-19 Thread sjw
Hi We're already having some discussions about SHA-1, but I'll split this up into a new thread. The initial goal of bug 942515 was to mark certs as insecure, that are valid 'notBefore >= 2016-01-01' (means issued to use in 2016+) AND also for certs that are valid 'notAfter >= 2017-1-1' (means sti