RE: Removal of "Revocation Lists" feature (Options -> Advanced -> Revocation Lists)

2013-05-02 Thread Varga Viktor
Hello, A normat certificate user never go to this menu, but maybe developers does... (ad remove crls- to test your application works well with revoked state or not, etc... my opinion, remove it, but ask the right people too, please. :) Üdvözlettel/Regards, Varga Viktor Üzemeltetési és

RE: how to use mozzila root certs

2013-01-25 Thread Varga Viktor
Hello, Because the subject is "how to use", maybe my answer can help you too, but i see your questions are not releated to the subject. The best usage of the Mozzilla cert store I found in the wild was the openoffice certificate handling on linux. they simply just use the certificates stored

RE: Question for CA representatives about PKCS#10 CSRs you accept

2010-07-21 Thread Varga Viktor
At us, none of them used. We are dropping the ATTRIBUTES, the content of certificate relies on the defined certificate profile. Üdvözlettel/Regards, Varga Viktor Üzemeltetési és Vevőszolgálati Vezető IT Service and Customers Service Executive Netlock Kft. > -Original Mess

dev-tech-crypto@lists.mozilla.org

2009-11-13 Thread Varga Viktor
Ok. :) Now i got some opinion back, that i have right with the deadlines, but of-course, its not an option to switch on a function like this int he Firefox against the CAs. Üdvözlettel/Regards, Varga Viktor Üzemeltetési és Vevőszolgálati Vezető IT Service and Customers Service Executive

RE: About assgining 1024-bit encrypted certificates & encoding of authority information

2009-10-20 Thread Varga Viktor
Maybe answer was not for me, but i am subscribed. :) Üdvözlettel: Varga Viktor üzemeltetési és vevőszolgálati vezető Netlock Kft. > -Original Message- > From: dev-tech-crypto-bounces+varga_v=netlock...@lists.mozilla.org > [mailto:dev-tech-crypto-bounces+varga_

RE: mobile phone certificates. Re: why client certs

2009-10-16 Thread Varga Viktor
> > Will this one day reach the PC? No, you will still use the phone as > the token > > (and token selector/executor) while the PC crypto will be bypassed. > NFC > > does the connection together with Wi-Fi. > > > Hmmm! Interesting thoughts. There is a total different approach too: 1. store th

RE: Making OCSP soft fail smarter

2009-10-14 Thread Varga Viktor
> IMO putting OCSP or CRLs in public SSL certificates was never a > particularly good idea because the only likely case for a revocation > is when a CA fails to validate a customer. That has happened > but not often enough to motivate the building of new infrastructure. Dont forget the sale of t

RE: About assgining 1024-bit encrypted certificates & encoding of authority information

2009-08-31 Thread Varga Viktor
Yes, the MS started the rollover process in its root program, and they follow the NIST recommendations. regards, Varga Viktor üzemeltetési és vevőszolgálati vezető Netlock Kft. -Original Message- From: dev-tech-crypto-bounces+varga_v=netlock...@lists.mozilla.org [mailto:dev-tech

RE: NSS, AIA, Bridge

2009-07-22 Thread Varga Viktor
>FF 3.5.0 and FF 3.5.1 do not support fetching of certs from AIA extension >URIs, nor fetching of CRLs from CDP extension URIs. The code to fetch >certs from AIA URIs is present, but Firefox has not yet put it into use. What was the cause to disable it?? >The code to do CRL fetching is not yet

RE: Full Listing of Included CAs

2009-06-23 Thread Varga Viktor
Thank you, this info lost somewhere for me. Now already subscribed. :D üdvözlettel/best regards: Varga Viktor rendszerüzemeltetési és vevőszolgálati vezető Netlock Kft. -Original Message- From: dev-tech-crypto-bounces+varga_v=netlock...@lists.mozilla.org [mailto:dev-tech-crypto

RE: Full Listing of Included CAs

2009-06-23 Thread Varga Viktor
The collection of info is excellent. Is it possible to get our rollover certificates into this update? :D I didn't see too much root public discusion nowadays. üdvözlettel/best regards: Varga Viktor rendszerüzemeltetési és vevőszolgálati vezető Netlock Kft. -Original Message-

RE: Questions about Potentially Problematic Practices

2009-03-19 Thread Varga Viktor
attached picture uploaded to http://www.kepfeltoltes.hu/view/090319/asn1parse_www.kepfeltoltes.hu_.jpg üdvözlettel/best regards: Varga Viktor rendszerüzemeltetési és vevőszolgálati vezető Netlock Kft. From: dev-tech-crypto-bounces+varga_v=netlock...@lists.mozilla.org [mailto:dev-tech-crypto

RE: Questions about Potentially Problematic Practices

2009-03-19 Thread Varga Viktor
> Will be then the multiple OCSP inclusion? (This time ok, the software can > only check the first, but later the others too.) Yes, including multiples of these things won't hurt. Firefox won't crash or refuse to connect because multiple URIs for these things exist. It will just ignore som

RE: Questions about Potentially Problematic Practices

2009-03-18 Thread Varga Viktor
I agree completely. The RFC does not exclude it. It's not a bad idea. > Does the Firefox handle it? Alas, no. I believe it always uses the first one it finds in the cert, and only that. Will be then the multiple OCSP inclusion? (This time ok, the software can only check the first, but later

Multiple CAIssuer and OCSP in AIA field (previously: Questions about Potentially Problematic Practices)

2009-03-17 Thread Varga Viktor
Dear readers, Previously i drop a mail about three question, and I got answer ont he OCSP multiple request quiestion. Other were not answered, so I cutted one part of it out, and posted it again. I would like to know, how the Firefox (NSS) handle this case: Multiple caIssuers and OCSP in AIA f

RE: SV: Questions about Potentially Problematic Practices

2009-03-11 Thread Varga Viktor
Thank you, now i know that Firefox doesnt want to create a request like this. üdvözlettel/best regards: Varga Viktor rendszerüzemeltetési és vevőszolgálati vezető Netlock Kft. -Original Message- From: dev-tech-crypto-bounces+varga_v=netlock...@lists.mozilla.org [mailto:dev-tech-crypto

RE: SV: Questions about Potentially Problematic Practices

2009-03-10 Thread Varga Viktor
As I see, the correct way to handel this the malformed reply. Thanks. Comments on my other questions? üdvözlettel/best regards: Varga Viktor rendszerüzemeltetési és vevőszolgálati vezető Netlock Kft. -Original Message- From: dev-tech-crypto-bounces+varga_v=netlock

Questions about Potentially Problematic Practices

2009-03-09 Thread Varga Viktor
bject Alternative Name field of the certificate. It is possible to these request have FQDN for external, and internal names without valid FQDN, for internal access. Is this UCC profile in under this üdvözlettel/best regards: Varga Viktor rendszerüzemeltetési és vevőszolgálati vezető Netloc