Re: Alerts on TLS Renegotiation

2010-04-18 Thread johnjbarton
On 4/18/2010 10:36 AM, Matt McCutchen wrote: On Sat, 2010-04-10 at 08:10 -0700, johnjbarton wrote: On 4/9/2010 6:06 PM, Matt McCutchen wrote: Are you saying that Mozilla shouldn't encourage users to bother their server operators because if the problem were real, the server operators would alrea

Re: Alerts on TLS Renegotiation

2010-04-18 Thread Matt McCutchen
On Sat, 2010-04-10 at 08:10 -0700, johnjbarton wrote: > On 4/9/2010 6:06 PM, Matt McCutchen wrote: > > Are you saying that Mozilla shouldn't encourage users to bother their > > server operators because if the problem were real, the server operators > > would already have fixed it? I think you give

Re: Alerts on TLS Renegotiation

2010-04-18 Thread Matt McCutchen
On Fri, 2010-04-09 at 02:45 +0200, Kai Engert wrote: > On 09.04.2010 00:41, Matt McCutchen wrote: > > On Thu, 2010-04-08 at 09:59 -0700, Robert Relyea wrote: > >> The yellow larry is a good proposal, and probably implementable much > >> sooner than noisy warnings. > > > > I'm glad you like it. I g

Re: ocsp check problem: sec_error_bad_database

2010-04-18 Thread Nelson B Bolyard
On 2010-04-18 01:49 PST, Nelson B Bolyard wrote: > On 2010-03-15 05:25 PST, Rafa M wrote: >> Hi all, >> >> I'm testing some SSL sites in order to check SSL cert chains up to new >> root certificate from FNMT-RCM (Spanish Mint). >> >> I've tried to connect several Official sites >> (https://www.ag

Re: ocsp check problem: sec_error_bad_database

2010-04-18 Thread Nelson B Bolyard
On 2010-03-15 05:25 PST, Rafa M wrote: > Hi all, > > I'm testing some SSL sites in order to check SSL cert chains up to new > root certificate from FNMT-RCM (Spanish Mint). > > I've tried to connect several Official sites > (https://www.agenciatributaria.gob.es https://sedemeh.gob.es/) and I go