Re: Subtracting trust anchors

2007-03-27 Thread Paul Hoffman
At 1:15 AM -0700 3/27/07, Nelson B wrote: >Here's a suggestion for the participants in this thread. >Instead of all this conjecture, imagining various bad designs for NSS and >then criticizing them, try to figure out how the products *really* work. Did that and failed. It may be my stupidity, or i

Re: Subtracting trust anchors

2007-03-27 Thread Nelson B
Here's a suggestion for the participants in this thread. Instead of all this conjecture, imagining various bad designs for NSS and then criticizing them, try to figure out how the products *really* work. There are major clues in Certificate Manager. Here are some hints. 1. The root CA list that c

Re: Subtracting trust anchors

2007-03-26 Thread Kyle Hamilton
On 3/26/07, Paul Hoffman <[EMAIL PROTECTED]> wrote: > At 10:10 AM + 3/23/07, Gervase Markham wrote: > >Kyle Hamilton wrote: > >> The Mozilla Foundation is the authority which determines whether a > >> given root certificate is included in its default certificate list. > >> If you're going to

Subtracting trust anchors

2007-03-26 Thread Paul Hoffman
At 10:10 AM + 3/23/07, Gervase Markham wrote: >Kyle Hamilton wrote: >> The Mozilla Foundation is the authority which determines whether a >> given root certificate is included in its default certificate list. >> If you're going to assert that it's "provable", you suddenly create a >> lot mo