Re: A bunch of ideas, again

2009-01-05 Thread Jan Schejbal
Hi, I'm sure such a flexible system would have its uses. Glad to hear I am not the only one... I have already entered it into bugzilla (forgot to put the link here), please see https://bugzilla.mozilla.org/show_bug.cgi?id=472038 Should the discussion be moved there? Coordinate with the NS

Re: A bunch of ideas, again

2009-01-05 Thread Gervase Markham
Jan Schejbal wrote: > I suggest an universal mechanism (integrated or as an extension) than > can be fed rules about certificates, CAs and sites and showing warnings > or interrupting connections where necessary. I'm sure such a flexible system would have its uses. Coordinate with the NSS and PSM

A bunch of ideas, again

2008-12-30 Thread Jan Schejbal
Hello all, I have proposed a few changes to SSL handling in response to the debian openssl disaster. I also mentioned earlier that a way to limit CAs would be nice, giving quite hypothetical cases where it would be useful. With the recent Commodo verification failure and the MD5 weakness just