pkcs#7 envelopeddata decoding

2006-08-14 Thread Michiel van Meersbergen
Hello list, I'm running into some trouble with the SEC_PKCS7DecodeItem function. The input for this function is a PKCS#7 EnvelopedData object, which contains just one recipient, a session key (encrypted with the recipients' public key) and the encrypted contents, encrypted with the above

Re: pkcs#7 envelopeddata decoding

2006-08-14 Thread Nelson B
Michiel van Meersbergen wrote: Another 'oddity' I should mention, is that the PKCS#11 DLL which provides access to the appropriate certificates and keys will ask for the proper authentication itself - in other words, when a private-key function like 'decrypt', 'sign' or 'unwrap' is called, it

Re: Forcing specific CA for domain

2006-08-14 Thread Nelson B
Balint Balogh wrote: Hello Suppose Example Ltd. runs its own local CA that issues certificates to servers and email addresses at example.com and its subdomains. The certificate of this CA is installed as a trusted CA certificate into every browser (Firefox) and email client (Thunderbird) of