On 10/13/09 5:14 PM, Lucas Adamski wrote:
For the small percentage of (power) users that can really understand the
implications of a question like "the OCSP URL provided by this
certificate does not appear to be valid at this moment, would you like
to continue",

Just to be clear at no point did I propose a modal click-through type UI. Just a visible UI notification like an info bar, door hanger notification, a lock with a question-mark over it... something visible but not interfering. I was envisioning an info bar because that leaves us space to put some explanatory text in it, but I didn't want to get specific.

Like the slashed-lock that indicates mixed mode (and is far too subtle for my tastes) I expect a lot of users wouldn't even notice, but hope that enough will to nudge things in the right direction.

In the longer run we can get some decent non-EV CA guidelines and then switch on the hard-fail. Given Johnath's lack of love for the suggestion the longer run might be the short path.

-Dan
_______________________________________________
dev-security mailing list
dev-security@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security

Reply via email to