Re: Two-factor auth for Bugzilla

2011-02-01 Thread aerowolf
On Tue, Feb 1, 2011 at 1:19 PM, Marsh Ray wrote: On 02/01/2011 02:41 PM, Anders Rundgren wrote: What about the client cert in a smart card? That's old and standard and supported by Mozilla. I don't know what kind of prices you'd have to pay for small quantities though. $119 if you go with

Re: Two-factor auth for Bugzilla

2011-02-01 Thread aerowolf
On Tue, Feb 1, 2011 at 12:02 PM, Marsh Ray wrote: can meet the requirement of "implement it only for some accounts" (with the implicit requirement that it doesn't bother or affect people who are not using it). Can a client certificate solution be made to work? Those accounts would probably h

Thank you, Mozilla.

2011-01-09 Thread aerowolf
Everyone, It has occurred to me that many, many open source software projects use Mozilla's vetted CA list. None of them, to my knowledge, compensate Mozilla for its time and fiscal expenditure in vetting that list. (Also, I do not know if there are any actual contracts that CAs have entered

Re: What's the reason for not caching token objects for internal tokens?

2010-09-12 Thread aerowolf
One of the main features of the sqlite key storage engine is that multiple processes can read from and write to it at once, using sqlite's file locking ACID semantics. This prevents it from becoming corrupted by multiple accessors. In order to implement this, I would guess that they decided n

Re: Question for CA representatives about PKCS#10 CSRs you accept

2010-07-21 Thread aerowolf
I can tell you that Eddy Nigg's (Startcom) system drops all ATTRIBUTE requests, relying on the CSR simply as a means of knowing what the public key is and proof of possession of the private key. and believe me, it'd be much easier if it didn't. -Kyle H On Thu, Jun 17, 2010 at 11:45 AM, Nelson

Re: How to refresh Firefox keystore

2010-07-05 Thread aerowolf
Wasn't a new version of NSS released (and thus JSS) that had a cert9.db and key4.db? Those are SQLite3 databases, and are the only versions that actively support multiple processes writing to them. -Kyle H On Mon, Jul 5, 2010 at 4:13 PM, james07 wrote: I notice the cert8.db and key3.db fil

Re: "Permanently store this exception" selected by default

2010-06-06 Thread aerowolf
File a bug. (If we're going to annoy the users every time they first encounter a security exception, we might as well go whole-hog and do it every time they encounter a security exception.) -Kyle H, the embittered On Fri, Jun 4, 2010 at 7:21 PM, TEO Tse Chin wrote: Hello, I encountered an

Re: Problems importing PKCS #12 client certs

2010-03-07 Thread aerowolf
On Thu, Mar 4, 2010 at 6:42 AM, Eddy Nigg wrote: Chris Hills wrote: Perhaps there is place for a fork of firefox (perhaps an "enterprise" version) that uses the windows certificate store and dispenses with the local certificate store. I understand that support for MSI installation is already

Re: Certificate usage guide

2009-11-05 Thread aerowolf
Let's see. Difficulties: Everything. Management of expired certificates, both your own and others'. Management of revoked certificates, both your own and others'. Management of keys. Management of certificate requests. Management of multiple certificates with differing Subjects, on a bro

Re: why no client cert validation in Firefox

2009-10-07 Thread aerowolf
On Wed, Oct 7, 2009 at 4:11 PM, Ian G wrote: I *know* that it does not check that the cert is issued by a CA that is trusted for client auth, because in Firefox, NO CAs are trusted for client auth.  (Does that surprise you?) Yes! why? Firefox doesn't have clients, so it doesn't need to au

Re: S/MIME in Thunderbird (and why its assumptions are bogus)

2009-07-10 Thread aerowolf
2009/6/26 Michael Ströder : Nelson B Bolyard wrote: But only a small minority of mail users use MUAs that reside on their own computers today.  Webmail rules, That might be true in the U.S. It's not true here in Germany. and entrusting your private key to your free webmail provider makes n

Re: S/MIME in Thunderbird

2009-06-25 Thread aerowolf
I really hate the licensing on that add-on, by the way -- it flies in the face of what freedom is, and they call it the "doubly-free" license by removing the freedom associated with the GPL? -Kyle H On Thu, Jun 25, 2009 at 2:31 AM, Gervase Markham wrote: On 24/06/09 23:49, Nelson B Bolyard wr