Re: Do we have a signing tool for Windows 2000 by Netscape?

2002-02-10 Thread Ben Bucksch
Leee wrote: >I can't find a SignTool 1.3 for Windows 2000 from >http://developer.netscape.com/software/signedobj/jarpack.html. > eh, try the NT4 one?

Risks using downled Mozilla builds

2002-02-10 Thread Sven Krohlas
Hi, yesterday there was an interestind discussion on the irc about security and downloaded files, and especially the net installer. I'd like to summarize it here (as far as I don't forget someting ;) and hope that someone has some good ideas to improve the situation. OK, imagine the following s

Re: Risks using downled Mozilla builds

2002-02-10 Thread Ben Bucksch
Sven Krohlas wrote: > One solution might be to get the installer from a "secure source" > (well, a nice > word for something that doesn't exist in relity, imho), Yes, this is exactly the problem here. > Another idea was to provide md5 sums of all Mozill builds, but this > only semms > to ma

Re: Risks using downled Mozilla builds

2002-02-10 Thread Sven Krohlas
Hi, > Personally, I trust the ftp.mozilla.org I see more than the CD I get I also trust ftp.mozilla.org, but the problem is that you can't trust the networks between your computer and ftp.mozilla.org > software, and probably just run Norton AV over it and that's it. Sad thing, what to do aga

Re: Risks using downled Mozilla builds

2002-02-10 Thread Ben Bucksch
(reposting, because I got "Service unavailable" from the news server.) Sven Krohlas wrote: > One solution might be to get the installer from a "secure source" > (well, a nice > word for something that doesn't exist in relity, imho), Yes, this is exactly the problem here. > Another idea was

Re: Risks using downled Mozilla builds

2002-02-10 Thread Ben Bucksch
Sven Krohlas wrote: >> Personally, I trust the ftp.mozilla.org I see more than the CD I get > > I also trust ftp.mozilla.org, but the problem is that you can't trust > the networks between your computer and ftp.mozilla.org I understood that. ThatÄs why I said "the ftp.mozilla.org *I see*". I t

Re: Risks using downled Mozilla builds

2002-02-10 Thread Christian Biesinger
Ben Bucksch wrote: > I wouldn't use the net installer at all and instead use the > tarballs/zipfiles or the full installer. Well, that's useless - anybody who can manipulate the files that the installer downloads can manipulate the installer itself as well so that it would trust the binaries.

Re: P3P plans

2002-02-10 Thread Jiri Znamenacek
some help with XSLT in P3P. If this is really XSLT what can we do about that? Jirka

Re: Risks using downled Mozilla builds

2002-02-10 Thread Ben Bucksch
Christian Biesinger wrote: > Ben Bucksch wrote: > >> I wouldn't use the net installer at all and instead use the >> tarballs/zipfiles or the full installer. > > Well, that's useless - anybody who can manipulate the files that the > installer downloads can manipulate the installer itself as well

addtrust.com certificates

2002-02-10 Thread mbordas
Has anyone tried to add a certificate from www.addtrust.com? I'm experiencing two problems: If I try to add a certificate with a 2048 bit key, I get an error Policy Rule: RSAKeyRule - Key Size Violation occurred: Actual: 2048, Constraints(Min: 512, Max: 1024). Is there a way to configure the

Re: addtrust.com certificates

2002-02-10 Thread Kryptolus
[EMAIL PROTECTED] wrote: > > Has anyone tried to add a certificate from www.addtrust.com? I'm > experiencing two problems: > > If I try to add a certificate with a 2048 bit key, I get an error > > Policy Rule: RSAKeyRule - Key Size Violation occurred: Actual: 2048, > Constraints(Min: 512, Max

Re: addtrust.com certificates

2002-02-10 Thread mbordas
Kryptolus wrote: > > What build #? > > 0.9.8 release for win32 (20020204).

Re: Risks using downled Mozilla builds

2002-02-10 Thread Thorsten
Ben Bucksch wrote: > Date: Sun, 10 Feb 2002 13:22:05 +0100 > From: Ben Bucksch <[EMAIL PROTECTED]> > To: [EMAIL PROTECTED] > Subject: Re: Risks using downled Mozilla builds > > > The net installer is very helpful for Netscape, because it allows them > to manage download streams (even the act

Re: Risks using downled Mozilla builds

2002-02-10 Thread Ben Bucksch
Thorsten wrote: > Wouldn't it be possible to modify the installer to be able to Download > the Files being a normal user > Is there any real reason, why almost the entire installation needs to > be done as root, just because someone wants a system wide install? I agree that downloading should

Re: IMAPS (imap over ssl) problem with local builds

2002-02-10 Thread Jungshik Shin
In <[EMAIL PROTECTED]>, Travis Crump wrote: : Jungshik Shin wrote: :> both under Win2k and Linux (RH 7.1). :> :> I have a patch to test for mail rendering. With the patch applied, :> I found IMAPS (secure IMAP) connection to my school IMAPS server (via :> port 993: UW IMAPd version?) didn't