Martin v. Löwis wrote:

> So I think it would be best if the browser detected that there is
> a better-suited certificate (one which doesn't need explicit user
> interaction); the browser should then also invoke explicit approval
> if the NR certificate is used even though "select automatically"
> was configured (explaining that this specific certificate is a
> formal signature).

That's an interesting idea.  Please file an Enhancement request "bug"
in bugzilla.mozilla.org.  But I wouldn't expect it to be implemented in
the next 6 months, because there's no much work scheduled ahead of it.
So in the meantime, get an EKU extension if you can.

-- 
Nelson B
_______________________________________________
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto

Reply via email to