mozilla-xp.com | Post Question | Search | About | Groups | Contact | Register | Login



mozilla feedback firefox (6093)

mozilla feedback (2053)

mozilla feedback firefox prerelease (1988)

mozilla feedback companion ebay (1608)

mozilla feedback thunderbird (855)

mozilla support thunderbird (791)

mozilla support seamonkey (503)

mozilla dev tech crypto checkins (460)

mozilla support firefox (399)

mozilla support bugzilla (386)

mozilla dev extensions (354)

mozilla feedback thunderbird prerelease (332)

netscape public mozilla reviewers (272)

mozilla dev mdc feedback (270)

netscape public beta feedback (268)

netscape public mozilla crypto checkins (265)

mozilla dev apps thunderbird (248)

netscape public mozilla jobs (224)

mozilla dev tech plugins (193)

mozilla dev apps firefox (189)

mozilla dev tech xul (188)

mozilla dev apps calendar (185)

mozilla dev embedding (181)

netscape public mozilla embedding (177)

netscape public mozilla test (174)

netscape public dev xul (169)

mozilla dev planning (166)

mozilla support calendar (166)

mozilla dev tech js-engine rhino (163)

mozilla test (162)

netscape public mozilla jseng (160)

netscape public mozilla crash-data (159)

netscape public mozilla xpcom (159)

mozilla dev platforms mobile (157)

mozilla dev platform (155)

mozilla jobs (153)

mozilla marketing (153)

mozilla dev builds (152)

netscape public mozilla layout xslt (151)

mozilla dev tech xpcom (150)

mozilla dev accessibility (147)

mozilla support webtools (146)

netscape public mozilla webtools (141)

netscape public mozilla gtk (136)

mozilla dev tech java (135)

netscape public mozilla calendar (135)

mozilla community drumbeat (134)

mozilla dev tree-management (131)

mozilla dev apps bugzilla (130)

netscape public mozilla i18n (130)

netscape public mozilla prefs (129)

netscape public mozilla qa general (129)

mozilla dev amo (128)

netscape public mozilla rdf (126)

netscape public mozilla xpinstall (126)

netscape public mozilla xml (124)

netscape public mozilla xpfe (123)

netscape public mozilla plugins (122)

netscape public mozilla java (122)

netscape public mozilla ui (119)

netscape public mozilla accessibility (118)

netscape public mozilla wishlist (117)

netscape public mozilla mac (116)

mozilla dev tech js-engine (116)

mozilla dev apps seamonkey (116)

netscape public mozilla general (113)

netscape public mozilla mathml (112)

netscape public mozilla crypto (112)

netscape public mozilla beos (111)

netscape public mozilla jsdebugger (110)

netscape public mozilla license (109)

mozilla dev tech crypto (109)

netscape public mozilla qa browser (109)

mozilla wishlist (107)

mozilla dev tech xforms (106)

netscape public mozilla directory (106)

netscape public mozilla editor (106)

mozilla dev quality (106)

netscape public mozilla macosx (106)

mozilla dev apps js-debugger (105)

netscape public mozilla performance (103)

netscape public mozilla builds (100)

mozilla dev ports os2 (100)

netscape public mozilla qt (98)

netscape public mozilla mail-news (97)

mozilla announce (96)

netscape public mozilla documentation (94)

netscape public mozilla os2 (93)

netscape public mozilla nspr (93)

netscape public mozilla netlib (93)

netscape public mozilla style (92)

mozilla support planning (92)

netscape public mozilla patches (91)

mozilla dev l10n web (90)

mozilla dev tech nspr (89)

mozilla dev mdc (87)

mozilla dev tech network (86)

mozilla dev tech css (86)

mozilla dev l10n cs (85)

netscape public mozilla layout (84)


netscape.public.mozilla.crypto Post New
Items(111) /2 Next >> Last >|
Subject Posted Replies From
What is TYPO3?

TYPO3 is a free development framework for Web sites, which was originally developed by Kasper. TYPO3 is based on the PHP scripting language. As a MySQL database, but can also be used as PostgreSQL or Oracle. The system is powered by two teams, one for each version 4 and one for version 5, developed. Many functions can be integrated with the extensions of its own programming without writing code. Currently over 4000 extensions are for the most part from other providers, and are available for free. Available include news, shop systems or discussion forums. The system for different lan

2/6/2010 11:39:54 AM 0 daisy michael <daisymichae...@gmail.com>



Finger Print Premium Lock

Specification: =95Memory Capacity: maximum 120 fingerprints divided into four groups =95One can erase individual fingerprint or group of fingerprints =95Fingerprint an be enrolled and erased on the lock directly. No PC Connection is required =95Rotating handle upward can lock deadbolt =95Blue background light, convenient for night use =95Unique passage mode for meeting or gathering =95Operated by AA alkaline batteries with low voltage alert =95External stand-by socket for 9V battery for emergency =95Antistrike function: When the door is closed, the antistrike latch is pressed agains

11/5/2009 11:49:35 AM 0 Nilma Shehrawat <nilimashera...@gmail.com>
0.1887848 I Want To Look In Here ... 0.1567408

0.2528728 I Want To Look In Here ... 0.9644768 0.1887848 Now Visit Tobacco Is Drugs 0.1567408

5/9/2009 2:41:15 AM 0 0.2528728realizeitist...@0.9644768now.com
"The New Encryption Generation: Closing the Gap"

This white paper examines the limitations of first-generation encryption processes that often deliver less-than-promised performance, spur user resistance, conflict with operational infrastructure and process requirements, and can even leave data stored in unencrypted locations where it is easily visible to unauthorized users. This white paper covers: * Data in the Line of Fire * Changing Needs of Security Management * Data on the Move * Endpoint Data Protection Prepared by IDG; Sponsored by CREDANT Technologies. <a href="http://ebooksick.tradepub.com/free/w_cr

3/10/2009 2:18:27 PM 0 Mike <mkbornto...@gmail.com>
How to use libpkix in custom application?

Hi ALL, does anybody know how to use the libpkix library in custom application (on Windows). I've tried to use the libpkix + NSPR, but library interface is hidden beyond NSS. Is it possible to use the libpkix without NSS? Thank you!

2/18/2009 7:15:16 AM 0 Valentine R <valentine.rozen...@gmail.com>
Rado Cerix Large Diamond Accented Ladies Watch R25474722, Best Luxury Watch - www.luxury-gift.org

Rado Cerix Large Diamond Accented Ladies Watch R25474722, Best Luxury Watch - www.luxury-gift.org Luxury Gift : http://www.luxury-gift.org Rado Watches : http://www.luxury-gift.org//rado-watches.html Rado Cerix Large Diamond Accented Ladies Watch R25474722 Link : http://www.luxury-gift.org/Watches/rado-watch-2296.html Rado Cerix Large Diamond Accented Ladies Watch R25474722 Information : Brand : Rado Watches Series : Rado Cerix Code : rado-cerix-diamond-accented-R25474722 Gender : Ladies Case Material : Ceramic Dial Color :

7/2/2008 9:25:07 AM 0 yxs...@gmail.com
Dior Sunglasses SG_DI0704051 - www.luxury-gift.org

Dior Sunglasses SG_DI0704051 - www.luxury-gift.org Luxury Gift : http://www.luxury-gift.org Christian Dior sunglasses : http://www.luxury-gift.org/Sun-Glasses/Christian-Dior-sunglasses.html Dior Sunglasses SG_DI0704051 Link : http://www.luxury-gift.org/Sun-Glasses/Dior_Sunglasses_SG_DI0704051.html Dior Sunglasses SG_DI0704051 Information : Brand : Christian Dior sunglasses Code : SG_DI0704051 Description : fashion Dior Sunglasses SAME AS PICTURE2008 new arrivel fashion Dior sunglasses and welcome to wholesale2 Pair 39.USD /1PC6 pair 32.USD /1PC12 pair 24

7/2/2008 9:25:00 AM 0 yxs...@gmail.com
Omega Aqua Terra 35mm Quartz 2518.80, Best Luxury Watch - www.luxury-gift.org

Omega Aqua Terra 35mm Quartz 2518.80, Best Luxury Watch - www.luxury-gift.org Luxury Gift : http://www.luxury-gift.org Omgea Watches : http://www.luxury-gift.org//omgea-watches.html Omega Aqua Terra 35mm Quartz 2518.80 Link : http://www.luxury-gift.org/Watches/omega-watch-1585.html Omega Aqua Terra 35mm Quartz 2518.80 Information : Brand : Omgea Watches Series : Aqua Terra Mid-Size Quartz Code : 2518.80 Gender : Mens - Midsize Case Material : Stainless Steel Dial Color : Blue Bracelet Strap : Stainless Steel Movement

7/2/2008 9:24:51 AM 0 yxs...@gmail.com
Why C_FindObjectsInit input session handle to "0"

This is a multi-part message in MIME format. ------=_NextPart_000_0080_01C8CF1D.73838720 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Hi all, In Firefox 2.0, custom PKCS#11 modules is called, but when call function = C_FindObjectsInit, the input session handle is 0, why? I'm not sure is = there session handle valued 0 is created before call this function. The = function failed with return value SESSION HANDLE INVALID, is there any = suggestions? Thanks=20 Robin ------=_NextPart_000_0080_01C8CF1D.73838720 Content-Type: text/html;

6/15/2008 11:24:37 AM 2 "robin" <digitalhu...@hotmail.com>
The status of pkcs11 module always be "Disabled"

This is a multi-part message in MIME format. ------=_NextPart_000_002C_01C8CF17.388CAD00 Content-Type: text/plain; charset="gb2312" Content-Transfer-Encoding: quoted-printable Hi all, I'm developing custom pkcs#11 module, when I test it in mozilla firefox = 2.0,=20 the status of the module always be "Disabled", any suggestions ? The module loaded successfully, slot info displayed ok, but the token = info=20 not displayed, the token is soft token, slot is CKF_TOKEN_PRESENT. If you want detailed information or any suggestion, please tell me, = thank=20 you very much. Robi

6/15/2008 10:40:01 AM 1 "robin" <its...@gmail.com>
Help me remember an encryption methods name please.

I am trying to remember a method for further scrambling text messages by replacing letters from each word while keeping the message human readable. Does anyone know the name? Or have a link? Thanks.

5/26/2008 7:01:52 AM 0 Condor2200 <Condor.2...@gmail.com>
__CERT_DecodeDERCertificate

Hi, Using NSS libraries we've written a program to verify signature and when run in parallel mode (spawning multiple threads) a JVM crash is observed at the call of __CERT_DecodeDERCertificate method. Strangely, this is observed in HP-UX machine only and the same code is working well in Linux 2.6. Has anyone come across such kind of a problem earlier? What could be causing this? Any kind of inputs are most welcome. Regards Mohan

3/10/2008 4:30:48 PM 0 mohanban...@gmail.com
Mutual Assets Securities, Government/Corporate Tax-Exempt, Tax Free, and Municipal Bond

Global Institutional Fund Analytics - Pension Assets Prognostic CWM WORLDWIDE - Principal Assets Prognostication Ascribe. A Certificate means of the Directors opinion that, having made due and careful enquiry, the working capital available to the Company will be sufficient for its present requirements, that is for a coming to the date of Admission right to the consolidated audited accounts prepared. The financial information set out does not constitute statutory accounts of the Company within the meaning of section 240 of the Act. As a company incorporated in Guernsey, it has not

2/20/2008 11:33:34 AM 0 "rogerkols...@yahoo.co.uk" <rogerkols...@yahoo.co.uk>
C_WrapKey

Ok here is my problem I have a wrap key in an HSM under a label"MYLABEL" . I am trying to use C_WrapKey to get privatekeys werapped under this wrapkey. based on the documenattion i m supposed to do C_Initialise // Ok C_OpenSession // OK C_Login //OK But when it comes to calling the C_WrapKey it returns back an error code 0x60 CKR_KEY_HANDLE_INVALID meaning obviosuly teh handle is not set. How Do i get this handle as it seems a not initialised valued is being passed on.. I tried to read about C_FindObjectsInit & C_FindObjects but they dont seem to be wiling to offer me a h

1/7/2008 4:57:59 AM 0 CTG <BadMul...@gmail.com>
oprah

MAKE MONEY AS SEEN ON OPRAH" TURN $6 INTO THOUSANDS IN ABOUT 30 DAYS...HERES HOW. **Proven by various, highly-respected U.S. TV and Radio programs as being 100% legal, feasible and true.** **Oprah Winfrey and ABC's investigation team 20/20 also prove it can be done.*** Note from PayPal: **Dear Member, it has come to our attention that there is a paypal scheme floating around at the moment you may have heard or seen the $6 scheme. You may have even taken part in it well we have been asked a lot of questions about this scheme the answer is yes it does work and yes it is safe t

11/20/2007 3:47:07 PM 0 scooterben <scooter...@btinternet.com>
Seeking help with server authentication

Hi!!! I've been trying to test the SSL client-server executables given in the bin folder of the NSS package binary: I'm using selfserv.exe & strsclnt.exe. The server side is getting initialized alright. But I have problems with server authentication: I tried many hit-&- trial approaches to obtain a successful connection but for one reason or the other, the client is not recognising the issuer CA(self-signed and added to the client DB with certutil -t "CTU, CTU, CTU") as trusted. I created three DB directories: one for each, the client, the server & the CA. The DBs, keys, and t

10/23/2007 6:58:39 AM 0 "D3|\||\|!$" <e.kaba...@gmail.com>
Fatloss computer program

I have been using this computer program for a couple weeks now and i am very pleased with the results so far. its a software fatloss program, if your looking for a diet/weightloss plan i reccomend you check this place out first: http://fatloss9.50webs.com

10/15/2007 11:47:38 PM 0 Angel vasquez<vange...@yahoo.com>
HP Desktop for sale!

Hi, I have an unused HP Pavilion with the fallowing specs: # Processor: AMD Athlon 64 X2 4000+ (2.1GHz, 2000MT/s System Bus) # Memory: 2048MB PC2-5300 DDR2 SDRAM memory (2x1GB) (expandable to 8 GB (4 x 2 GB) (64-bit OS)/ 4 GB (4 x 1 GB) (32-bit OS)) # Hard Drive:320GB 7200RPM SATA 3G (3.0 Gb/sec) hard drive # Optical Drive: 16X DVD(+/-)R/RW 12X RAM (+/-)R DL LightScribe SATA drive # Expandable Drive Bay: HP Pocket Media Drive bay # Video Graphics: Integrated graphics # Network Interface: Integrated 10/100BaseT network interface # Sound: High Definition 8-channel audio # Fax/Modem:

10/14/2007 8:28:31 AM 0 pbdude<pbdude...@yahoo.com>
A Killer Email Message - How to Write Killer Email Promos that Get Results

If you market products or services online, this is a MUST have tool to success. Click here: http://tinyurl.com/2j652s How to Write Killer Email Promos that Get Results! Click here: http://tinyurl.com/2j652s --- MAF Anti-Spam ID: 20070208151850P9n0NqC4

9/28/2007 11:42:06 PM 0 "RED" <redNOSPAMredd...@yahoo.com>
Hot personal ads women dating , personal ads women looking , personal ads women

http://www.all-women-dates.com/index127.html http://www.all-women-dates.com/index128.html http://www.all-women-dates.com/index129.html http://www.all-women-dates.com/index130.html http://www.all-women-dates.com/index131.html http://www.all-women-dates.com/index132.html http://www.all-women-dates.com/index133.html http://www.all-women-dates.com/index134.html http://www.all-women-dates.com/index135.html http://www.all-women-dates.com/index136.html http://www.all-women-dates.com/index137.html http://www.all-women-dates.com/index138.html http://www.all-women-dates.com/index139.html ht

7/22/2007 5:05:11 PM 0 skfisfwei939e...@yahoo.com
Firefox does not display imported certificate

After importing a certificate into the Firefox either using certutil.exe utility or programatically using NSS API (P12U_ImportPKCS12Object / PK11_ImportCert), I can see that the certificate has been successfully imported (%certutils.exe -L) , however Firefox does not display it (Tools->Options->Advanced->View Certificates) until I restart the browser. I am wondering is it a way to instruct the already running Firefox to reload its security database (containing certs) without restarting it (e.g. this happens when I import cert. from Firefox UI)?

7/19/2007 11:43:45 AM 1 Andrei Korostelev <and...@korostelev.net>
Generating cross certificates?

At my work, I've been attempting to build (what I believe is called) a "cross-signed certificate" for a set of files distributed within the same type of "jar" file used to distribute executable Java classes over the network. Ring any bells with anyone? Right now, software enhancements/updates are delivered in jar files because the jar signing mechanism should protect the appliance from invalid updates. We've been using certification authority "A" so far, and we recently gave another group a certificate "X" that had "A" in its trust chain. So jars signed with "X"'s are allowed by t

6/8/2007 2:37:52 PM 2 Romain Kang <rom...@kzsu.stanford.edu>
CERT_VerifyCertNow fails

Hi All, I am trying to run NSS SSL sample program with a self signed test certificate. I modified the client program to initialize using NSS_NoDB_Init instead of NSS_Init. An error occurs on the client side when validating the certificate. The call to CERT_VerifyCertNow fails with error code -8156 (SEC_ERROR_CA_CERT_INVALID). Any idea what is wrong ? Thanks John Smith

5/25/2007 9:20:24 AM 1 "John Smith" <jsm...@unknown.com>
I can't decrypt mail message using mozilla thunderbird 1.5.0.10 on linux

I can sign and crypt the mail messages, but i can't decrypt them. I am using the smart card, if i do the same procedure with mozilla on windows pc, all works. but on linux the decrypt is not possible. If i try to read the crypted messages i obtain the following error message: "Mail/News cannot decrypt this message: The sender encrypted this message to you using one of your digital certificates, however Mail/News was not able to find this certificate and corresponding private key." someone can help me? thanks

4/2/2007 3:18:28 PM 0 mau.lo...@gmail.com
Turning on OCSP verification generates many errors

As part of my company's rollout to use OCSP I decided to turn on OCSP checking in FireFox 2 on my Mac. I've been surprised at the number of OCSP-related error messages I'm now getting when browsing websites that I didn't expect to be using SSL or OCSP. In a few cases it looks like it's the Verisign "seal" that is displayed on websites that's actually triggering the error (how ironic!) or causing slower than normal page downloads. One error I get while attempting to authenticate to an internal site with my certificate-on-a-smartcard is this one: "Alert: An internal failure has bee

3/28/2007 4:06:49 PM 1 "Bill Burns" <x50...@gmail.com>
Call For Papers: SECURECOMM 2007

CALL FOR PAPERS SECURECOMM 2007 Third International Conference on Security and Privacy for Communication Networks Nice, France, Sept. 17 - Sept. 21, 2007 URL: http://www.securecomm.org Co-Sponsored By: IEEE Communications Society (www.comsoc.org) CreateNet(www.create-net.it) PAPER SUBMISSION DEADLINE March 7, 2007 ******************************************************************* Securecomm seeks high-quality research contributions in the form of well-developed full papers. Topics of interest encompass research advances in ALL areas of secure communications and net

2/15/2007 9:23:00 AM 0 "Alcaraz Tello" <alcarazte...@gmail.com>
International Conference on Information Theoretic Security (ICITS'07)

*** Apologies for multiple copies *** C A L L F O R P A P E R S International Conference on Information Theoretic Security (ICITS) Madrid, Spain, May 25-29, 2007 http://www.escet.urjc.es/~matemati/maribel/ICITS/ITS07.htm **Note: Eurocrypt is May 20-24, 2007 in Barcelona, Spain. BACKGROUND: For the last years we have plenty of conferences and workshops on specialized topics in cryptography. Examples are CHES, FSE, PKC and TCC. The modern unclassified research on cryptography started with Shannon's work on cryptography using information theory. Since then we

2/8/2007 9:16:36 AM 0 "Alcaraz Tello" <alcarazte...@gmail.com>
EuroPKI'07 (+ Journal Special Issue)

** Apologies for multiple copies ** F i n a l C a l l F o r P a p e r s Fourth European PKI Workshop: Theory and Practice (EuroPKI'07) 28-30 June 2007 Palma de Mallorca, Balearic Islands, Spain http://dmi.uib.es/europki07 The 4th European PKI Workshop: Theory and Practice is focusing on all research aspects of Public Key Applications, Services and Infrastructures. Submitted papers may present theory, applications or practical experiences on topics including, but not limited to: - Architecture and Modeling - Authentication - Authorization and Delegation -

1/24/2007 9:43:20 AM 0 "Cristina" <alcarazte...@gmail.com>
BBC links:Privacy Concerns over States/Corporations'Use of Personal Info

Hello, The BBC news articles below address privacy concerns over states' and corporations' use of personal data. I think you will find the links useful. Thanks, Mashi The basic summary is the following: 1. States collect personal info by various methods (eg:CCTV/closed-circuit TV in roadways). Corporations collect personal info by various means (eg:credit card transactions). 2. The info collected by a single entity (state/corporation) is considered SEPERATELY BY ITSELF. The combination of data collected by different entities is NOT considered by many people. 3. Corporations

12/23/2006 8:40:20 AM 0 "mashi3...@yahoo.com" <mashi3...@yahoo.com>
EuroPKI07 Call for Papers

F i r s t C a l l F o r P a p e r s EUROPKI'07 Fourth European PKI Workshop: Theory and Practice 28-30 June 2007 Mallorca, Spain http://dmi.uib.es/europki07 The 4th European PKI Workshop: Theory and Practice is focusing on all research aspects of Public Key Applications, Services and Infrastructures.Submitted papers may present theory, applications or practical experiences on topics including, but not limited to: - Architecture and Modeling - Authentication - Authorization and Delegation - Bridge CA - Case Studies - Certificates Status - Certification Po

12/20/2006 4:12:05 PM 0 krypo...@hotmail.com
server certificate compatibility

I'm generating selfsigned certificates with openssl for use with a web service running on IIS. I can retrieve the WSDL fine with IE but not with Firefox. Firefox complains that it can't establish an encrypted connection (error code -8101 anyone know exactly what this error means?). I'm thinking that Firefox doesn't like something about my certificate but I'm not sure what. One thing about my certificate is that the server name and the certificate CN don't match (if Fire fox doesn't like this is there a way to configure it to except the cert anyway?). Aside from this name issue does can

12/20/2006 1:11:57 AM 0 txt...@gmail.com
Certificate import fails with "already exists on the security device"

Hi, I have tried a number of things to make Thunderbird import a certificate and key, with no success. Originally it was in PKCS12 format, issued by my organization as my personal certificate. Whenever I try to import it, I get the error message "The certificate and private key already exist on the security device" (which was definitely not true - it even failed with an empty certificate db). The certificate was made for signing and came together with another certificate (made for encryption) with which I had no problems. In the same package, I also got two CA certs in pkc

12/8/2006 6:05:25 PM 2 Martin Wilck <martin.wi...@fujitsu-siemens.com>
Regarding CMS

Hello, Could anyone of you clarify if CMS related API's are to be used for performing signing of data. In one of the threads it is mentioned that the SEC_PKCS7 APIs functions are depricated This is the thread for your reference http://groups.google.com/group/netscape.public.mozilla.crypto/browse_frm/thread/19dd407ba0b19b63/c34a7aeb79966c36?lnk=gst&q=CMS+apis&rnum=3#c34a7aeb79966c36 Also please let us know if we can find any samples for using the CMS API. Regards Mohan

12/8/2006 10:16:45 AM 0 mohanban...@gmail.com
Netscape PKCS#11 test suite

Hi all, I am searching for the Netscape Pkcs#11 test suite windows executables. If any of you point me the link from where i can download this executables it will be very helpful. Regards, Kamal.

11/17/2006 1:37:20 PM 0 skamalaku...@yahoo.com
Call Javscript function

Hello friends i developed a tollbar for Firefox browser. Now This toolbar contains a menu item. A web page will be opened by the user of the Toolbar. This Web page source code has included many .JS fiels in it. These JS files defined various functions , Now i want to call these functions from my toolbar menu command. How can i do that? I know function name which i have to call. I tried to call function directly by its name but it is giving error that this function is not exist? How should i call that function. I got success to implement same functionality for IE by using IHTMLW

11/1/2006 9:08:30 AM 0 harishdix...@gmail.com
problem with multiple certificates from 1 card PKCS11

I am seeing some behavior from Thunderbird that I cannot explain. I have a PIV card with 3 certs on it -- all of which are suppose to be meant for different things. Thunderbird correctly sees the one applicable for digital signature, and correctly sees the one for encryption. 2 things: Whenever I select a cert it asks me if I want to use it for the complementary job as well. That's OK if the cert can do both, but in this case, these certs have exclusively different uses and I should never be prompted (The key usage is set accordingly). I guess that's just a usability issue.

10/26/2006 7:30:32 PM 0 Christian Bongiorno <christian.bongio...@google.com>
Trying to sign javascript... not working

I'm trying to sign some javascript code. I have read just about everything there is to read but the whole thing won't budge. I have a certificate store with one lonely test certificate in there (I tried countless ways of putting in a cerificate, none of them showed any difference) and signed some html+javascript into a rar. everything SEEMS to work beatifully. Now I let firefox run the html and it turns out the HTML loads fine, but the javascript doesn't. I quote the javascript console: Signature Verification Error: the signature on privlib.html is invalid because the certi

10/24/2006 1:35:10 PM 2 Martijn Saly <mart...@circumflex.removethespammer.com>
SSL connection fails on the server with SSL_ERROR_HANDSHAKE_FAILURE_ALERT

Hi all, I would like to ask for advise. We are building a firefox extension and we are using our own implementation of SSL server and client implemented closely to the ssl sample (security\nss\cmd\SSLsample). We are not using PSM socket provider implementation. All certificates (CAs and client/server) are RSA/SHA1 signed. We are using a root CA + several intermediate CAs to sign user's certificates. The user's certificates are used for SSL server and SSL client authentication too. All CAs are added to the software token and marked as trasted CA. The user certificate is also add

10/23/2006 12:54:20 PM 1 "Honzab" <hon...@allpeers.com>
trying to sign data in tbird -- pkcs11

I am currently trying to sign some data in tbird and the signature is not valid. The incoming data I get (C_Sign()) is an ASN1_STRING of the SHA1 hash of the message. Currently, I am encrypting the whole thing and returning raw data back. Should I be decoding the ASN1 input, encrypting the hash, then returning it as ASN1 encoded? Not sure what it expects. Christian

10/13/2006 8:13:22 PM 1 Christian Bongiorno <christian.bongio...@google.com>
need help w tbird and pkcs11

Ok, I have spent over a week tweaking and toying with things and, although I believe I am dead on, for some reason, thunderbird will not accept the certificate on my card as valid. I have included the open-sc spy logs inline-- The last success I have show's NSS looking fro CKO_PRIVATE_KEY, which tell it I have 1, and then it never checks the follow on attributes for it! It almost appears as if it begins to loop on getInfoXXX Can someone please tell me WHAT I am missing? Compared to the logs I have for another working card everything looks to be in order As an aside, I wil

10/10/2006 7:34:32 PM 1 Christian Bongiorno <christian.bongio...@google.com>
ECC support in Mozilla

Does Mozilla (SeaMonkey 1.0.5) currently has ECC (Elliptic Curves Cryptography) support? Or is there any other project browser that has ECC support? I tried viewing a ECDSA cert with Mozilla but receive the error 'SeaMonkey and localhost cannot communicate securely because they have no common encryption algorithms'. Am I missing anything? Thanks in advance!

10/9/2006 8:58:37 AM 1 "Serline" <zhilia...@yahoo.com.sg>
Looping C_OpenSession problem in tbird pkcs11

I am currently developing a PKCS11 module for a new card and I am seeing some strange behavior: For some reason, thunderbird continually repeats the same 7 functions over and over eventhough it "installs" the module successfully. Most of them are just "getInfo" functions but it also continues to call C_OpenSession which is a problem since that calls attempts to access the card. I have returned CKR_SESSION_COUNT and it still loops. So, my guess is that it is due to something else I have done I just don't know what. Below I have an example output of the calls using pkcs11-spy f

10/4/2006 3:09:20 PM 0 Christian Bongiorno <christian.bongio...@google.com>
C_OpenSession looping

I am currently developing a PKCS11 module for the PIV card and for some reason, the NSS subsytem in thunderbird infinintely loops on 7 startup calls -- you know, all the 'getInfo' functions as well as the C_OpenSession. Inlined is my spylisting using the opensc spy tool. The module is already installed and this what happens once installed and FF loads Can someone explain to me what I might be telling thunderbird that makes it think it's ok to go NUTS and query dll? Christian ------------------------------ *************** OpenSC PKCS#11 spy ***************** Loaded: "C:\dev

10/3/2006 9:23:59 PM 0 christian.bongio...@gmail.com
How to map a selected certificate from the certificate manager list to PKCS11

Hi there, I installed my PKCS11 module into the Firefox browser. I can see my certs on my token from the Certificates Manager of the browser. Turn on the option -- "Ask me evey time". Then I started a Client Site SSL connection to my web server. The browser popped up the cert selection list box. I selected one. However, my pkcs11 module cannot get the correct selection. It always picks up the first cert. Can someone tell me how the browser passes the pkcs11 module a selected cert index? Basically I use a selected cert index to locate its private in the key store and then do a

9/20/2006 1:07:14 AM 2 "ben" <...@tricipher.com>
Flashes of Light on the Faith

In this article of mine, the believer will find incontestable historic-archaeological support to his Faith, the undecided one will perhaps be capable of making a decisive step forward to live the "Blessed Hope", the atheist will get irritated at seeing his thought being based absolutely on nothing. In this site, there are links with other writings of mine, which have had more than 100.000 readers all over the world. Nowadays, we are living on the surface and on the loss of information. Let us think of the Vinci's Code which, even among many other anti-historical events being therein d

9/16/2006 6:49:32 AM 0 book...@lorenzocrescini.it
signing javascript

Hello all, I am trying to sign javascript files and running into some issues. Hopefully someone can point me into the right direction. I did obtain a code signing certificate from Certum. They issue the certificate as part of a chain: certum root CA -> certum level I -> mycert. I created a cert db with the certutils prg: 1. certutil.exe -N -d I have three cer files: one for each cert in the chain. Since certum root ca is already contained in the list of root certs, I do not bother to import this one. However, I do import certum level I and mysert: 2. certutil.exe -A -t Cu -n "C

8/26/2006 3:23:43 AM 2 christian.seif...@gmail.com
Add money to your Paypal account with OPRAH s>aO3

Read this message until the end, and you will find out how the money flows in easy !!!!. Follow the steps and it WILL work. Trust me !!!!!. It's NOT illegal and it is NOT a scam !!!!!. PROVEN ON OPRAH! Reported in the Wall Street Journal!!!! The only thing you need is : - E-MAIL ACCOUNT - PREMIER (FREE) or BUSINESS PAYPAL ACCOUNT - $6 on this account (The only investment) - 30 minutes of your time There is no limit on how much money you can recieve, and you haven't got anything to lose with this Business program. I will explain how it works !!!!!. Follow these 4 easy s

8/15/2006 10:52:43 PM 0 "NSI" <af.ir...@afyhpami.com>
SECURITY/ C++/ CONTRACT/ CA

OMNI GROUP tgugger@sbcglobal.net 419-537-9447 ENCRYPTION�C/C++ -- SSL/TLS -- CONTRACT � ASAP�CA If interested and qualified, email resume to: tgugger@sbcglobal.net. JOB DESCRIPTION Position: - Apps Systems Engineer 6 - Encryption Projects San Francisco- 5 months, renewable possible Possible future opening in Phoenix area Contract Term: 5 months with the p

8/10/2006 2:17:24 PM 0 "OMNI GROUP" <tgug...@sbcglobal.net>
Windows Zip Util for XPI's?

I've seen this asked many times, but I haven't seen any solutions posted. What zip utility can I use under windows to create a signed XPI? I can't find any that let me control the order of the files. Also, what's the easiest way to tell whether my XPI is properly signed? Is there an NSS utility that does this? Thanks in advance, Paul

7/7/2006 5:51:38 PM 1 "suckerformimi" <crem...@gmail.com>
Build NSS on windows with mingw

It's my understanding that msvc and VC++ are supported for NSS builds. I have even been able to find some msvc binaries of nss floating around. However, I'm stuck on compiling NSS with mingw/gcc. Does anybody have any hints? Thanks, Wesley Leggette

6/23/2006 6:30:05 AM 0 "Wesley Leggette" <wlegge...@gmail.com>
Software security device on standard USB disk

Hi, I'd like to put the Mozilla "software security device" on a standard USB disk to use as a poor-man's security token. Does anyone know if it's possible to add an extra "software security device" to the internal PKCS #11 module in Mozilla/Firefox and specify what path to use? Alternatively, is it possible to add a second internal PKCS #11 module and similarly specify the path to use? I would also be reasonably satisfied if I could just reconfigure the default device to use a different path. I'd prefer not to use a solution that involves symlinking the .db files from the USB d

6/21/2006 8:37:46 PM 1 david.ocallag...@gmail.com
Associate Research Fellow - Cryptography - UoW Australia

associate research fellow - cryptography Faculty of Informatics � Fixed Term (3 years), Full-time position UOWs Centre for Information Security, which is a part of the Faculty of Informatics, is seeking to appoint a suitably qualified individual to work on the ARC Discovery project entitled: �Credential Systems and Their Applications in Securing Electronic Health Records�. To be successful, you will possess a PhD in Cryptography / Mathematics or equivalent area and demonstrate your experience in Cryptography and its applications. Ideally, you will a

6/2/2006 10:05:13 AM 0 Willy Susilo <wsus...@iinet.net.au>
OpenSSL CA certificates and Firefox

I am attempting to create two CAs that will handle two different types of requests. One would take care of servers and one would take care of clients and email. When you view the certificate in Firefox it should say something along the lines of, "This certificate has been trusted for the following uses: SSL Certificate Authority" in one, and "Email Signer/Recipient Certificate" in the other. Unfortunately, after I import the "server" CA certificate (ca.server.crt) it says, "Could not verify this certificate for unknown reasons." I have checked all of the "trust" boxes that come up wh

5/26/2006 8:47:47 PM 1 alex...@gmail.com
certutil - import client certificates?

I'm currently trying to find a way of automatically importing a client certificate into Firefox - such that its 'resting place' is in the 'your certificates' part of the database. I want to create a different certificate for a number of clients on a web server, and use a local script on the client to grab this certificate and add it to the browser automatically. I can't seem to find any options on certutil that allow me to do insertion of client certificates. Is this something that is possible in any way? Matthew

4/26/2006 8:36:11 AM 0 "Matt" <mat.richard...@gmail.com>
couple of certificate usage questions

Hi, Sorry if this has already been answered, I searched for an answer before asking. 1. What should be trust args for a self-signed certifcate, that needs to be used as a server cert? Should that be valid peer or trusted peer? Can self-signed cert be used with NSS for server authentication? 2. What is the difference between valid peer and trusted peer? Is there any doc or notes out there describing how to use these trust flags 3. What is the relationship between trust flags and extensions in the certificate? If the certificate can itself describe it's type and usage, is th

4/14/2006 9:40:39 AM 0 star_ni...@my-deja.com
LEARN

LINKS OF SITES TO STUDY CRYPTOGRAPHY http://www.freewebtown.com/hax4u/cryptography.html

4/11/2006 8:51:05 AM 0 hax4u.t...@gmail.com
pkcs#11 testsuite for AIX

Hi, I would like to run pkcs #11 tests on AIX platform. Anybody know how to run these tests and the required software? Thanks for your help.

3/17/2006 6:41:27 AM 0 Rupesh <rupes...@gmail.com>
JSS interop with crypto.generateCRMFrequest

I've generated a CRMF request from Firefox with the simplest possible javascript snippet: function showcrmf() { document.write(crmf.request); } crmf = crypto.generateCRMFRequest("cn=frog,ou=frog", "regtoken", "authenticator", null, "showcrmf();", 1024, null, "dsa-nonrepudiation"); I'm trying to load the resultant base64 into JSS using equally simple code: CertReqMsg.Template t = new CertReqMsg.Template(); ASN1Value a = t.decode(new BufferedInputStream(new Base64InputStream(new FileInputStream("/home/dichro/crmf")))); System.err.println(a); Which bombs with: Exception

3/15/2006 2:29:31 PM 0 dichro-goo...@rcpt.to
Client-Side Certificates

Hey All, Here's our setup. We have a Solaris Certificate server running openssl. On this server we sign certs with our own Root CA. 1) What we currently do is when a user needs a 'server' based cert, they send us a CSR and we sign it and return the signed cert so they can install on their server application Problem: We have a request to create a 'server' based cert and we will sign it. They also want to have a client cert installed in the user's browser that will authenticate to the server. I am new to this, what do I need to get from them? Do they need to send a 'CLIENT C

2/24/2006 4:28:14 PM 0 "RogerTown" <rogert...@gmail.com>
sign/crypt forms

Hi all, I'm needing a way to sign/crypt webmail forms using pki functions, so, standalone mail clients (thunderbird) can to check sign and decrypt the messages. I have based in secclab (http://secclab.mozdev.org/index.html) but without success. Anyone have any orientation about how to make this? Thank you a million. Best Regards, Fernando Ribeiro

2/20/2006 6:03:12 PM 0 Fernando Ribeiro da Silva <ferna...@staff.nerdgroup.org>
How do I import a CRL import Firefox under Fedora Core 3?

Hi, I am trying to import a CRL into firefox, but I have not been able to discover the right combination to things to get it to work. The CRLs are in binary DER format and are called "blah.crl". I tried just putting the file URL (e.g. file:///blah.crl) without any luck (it just tries do save the file to disk). I tried changing the name to "blah.der". I have tried importing PEM format as well. The version of mozilla is: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.12) Gecko/20050922 Fedora/1.0.7-1.1.fc3 Firefox/1.0.7 What is very curious is that I am able to import the same

2/11/2006 7:00:33 PM 1 "Bruce Keats" <bruceke...@gmail.com>
How to build the NSS cmds on Mac OS X?

Hi all, Can someone tell me how I can build NSS lib and its utility cmds on Mac OS X? I have downloaded the Mozilla source code and successfully built it on OS X, but checked with the output obj dir, I didn't find the Security/nss was created and built. How I can include the NSS into my build? Thanks, Ben

2/8/2006 11:56:17 PM 1 "ben" <...@tricipher.com>
Re: Help with invalid certificate problem

I am facing the same problem: a client certificate working with IE but not with FF/ Mozilla/NSS "Could not establish an encrypted connection because certificate presented by is invalid or corrupted. Error code: -8102" Could any one please tell me how to set the server extension to include "Key encipherment" for "key usage",.. Currently it has only digital signature as its value. While creating the server cert I could not see any option to inclue such an option also. We set up the CA using Entrust and I am using IIS 6.0 for the web-server,.. Please help, I am a newbie with CA

2/7/2006 2:04:05 PM 0 "Vivek" <viveque.ku...@gmail.com>
Are You Living Life The Way You Choose???

I spend as much time as I want with my family. We go on vacation whenever we choose and we even make money while we're tanning on the beach. We have NO bosses to answer to, NO long commutes in the morning, and we decide when it's time to wake up! The Internet makes this possible for anyone, and you can make money 24 hours a day 7 days a week... even while you are sleeping! I do this everyday along with hundreds of thousands of others. In the next 15 minutes you can have your very own Affiliate Cash Vault system which will virtually run itself. You just wait for the checks to come home and c

2/1/2006 2:27:13 AM 0 "Matthew" <affiliatec...@hotmail.co.uk>
Get Rich

Take advantage of a great deal

1/31/2006 6:18:13 AM 0 "Daun Johnson" <jment...@ildmsnka.com>
VeriSign digital certificates with Firefox

Hello all! At the school where I work, our student information system has a digital certificate installed from VeriSign. Because it is a 128bit certificate, there are three parts to it: the middle part is an intermediate portion also from VeriSign that bumps it up from 64bit to 128bit. The Firefox browser in both versions 1.0.7 and 1.5 initially came up with a message box title of "Web Site Certified by an Unknown Authority" and the content of the message box of "Unable to verify the identity of sis.cgu.edu as a trusted site" when we went to the SSL signon page. Firefox sh

1/25/2006 1:16:21 AM 1 "Stuart Fermenick" <stuart.fermen...@cgu.edu>
[ADMIN] This list is now closed!

If all goes according to plan, this should be the last post you receive on the mailing list version of this group. All subscribers to the mailing list should shortly receive a subscription notice for dev-tech-crypto@lists.mozilla.org. If you are reading this via the netscape.public.mozilla.crypto newsgroup, this newsgroup is now considered officially abandoned. We have moved to mozilla.dev.tech.crypto, which is available via the news.mozilla.org news server. -- Dave Miller System Administrator, Mozilla Corporation http://www.mozilla.com/

1/23/2006 3:21:31 AM 0 Dave Miller <justd...@mozilla.com>
n.p.m.crypto is moving

I am forwarding this message to the secnews.netscape.com server, which seems to have stopped updating this newsgroup at the end of 2005. /Nelson - ------------------------------------------------------------------ It should be no secret these days that the Mozilla Foundation and its related projects are no longer a pet project of Netscape, yet the newsgroups we are using for public discussions still bear the Netscape name. We've been planning for years to move from netscape.public.mozilla.* to just mozilla.*, and the time has finally come! In August, we announced a partnership wi

1/22/2006 12:37:06 AM 0 Nelson B <NOnelsonS...@NObolyardSPAM.com>
[ADMIN] mozilla-crypto-checkins is moving!

The mozilla-crypto-checkins mailing list and the n.p.m.crypto.checkins newsgroup are being replaced, tomorrow. I am the moderator of mozilla-crypto-checkins@mozilla.org, and I will be the moderator of the new dev-tech-crypto-checkins@lists.mozilla.org list. The newsgroup netscape.public.mozilla.crypto.checkins has been unmoderated but the new newsgroup mozilla.dev.tech.crypto.checkins will be moderated. I will moderate both the mailing list and the newsgroup. I am forwarding the official announcement (below) on behalf of Dave Miller, System Administrator for mozilla.com. It seems

1/21/2006 11:14:12 PM 0 Nelson B <NOnelsonS...@NObolyardSPAM.com>
Basic Firefox signing/encryption question

An OASIS TC is currently toying with the idea that Mozilla Firefox can, without adding any native extension code, perform XML Signatures and possibly also XML Encryption, by an invocation from a web page: http://www.oasis-open.org/committees/download.php/16304/agsc-tpki-requirements-00.txt To my knowledge the only thing available in a standard distribution is the "signText()" function. signText only supports the signing of a plain/text string (at least if the user is taken in consideration...). In addition the signature is limited to PKCS #7. Could somebody ON THIS LIST (not o

1/21/2006 1:03:06 PM 1 "Anders Rundgren" <anders.rundg...@telia.com>
[ADMIN] mozilla-crypto is moving!

It should be no secret these days that the Mozilla Foundation and its related projects are no longer a pet project of Netscape, yet the newsgroups we are using for public discussions still bear the Netscape name. We've been planning for years to move from netscape.public.mozilla.* to just mozilla.*, and the time has finally come! In August, we announced a partnership with Giganews Newsgroups (http://www.giganews.com/) to provide NNTP services for our news.mozilla.org domain. It's taken a few months of planning to make it happen, but we're now in the process of moving all of those newsgrou

1/21/2006 12:18:19 PM 0 Dave Miller <justd...@mozilla.com>
The Browser Digital Signature Riddle

Although S/MIME has its uses, WebSigning (signing web forms), is already a much more significant tool for many e-governments. This is mostly due to the fact that interactive services are considerably more flexible than static e-mail, but it also depends on the ease of establishing confidentiality (https). However, there is a fly in the soup. There is no standard for WebSigning, making this facility costly to deploy as well as non-interoperable. Recently a number of leading pharmaceutical companies who have formed a strong authentication consortium (SAFE), launched an internally d

1/20/2006 7:43:09 PM 1 "Anders Rundgren" <anders.rundg...@telia.com>
PKCS #11 Test Suite

Hi, I need some tools to test my PKCS#11 module under Windows. I'm looking for Netscape PKCS #11 Utility Package but I have not been successful yet. Could you give me right link to this packgae, or link to some other nice tool to test PKCS11 module. Thank in advance Beep

1/19/2006 3:08:29 PM 3 B...@post.cz
JSSE & JSS Provider Conflict

I was wondering if anyone had this problem before. It seems that JSS 3.4 (and new versions) does not support all Cipher algorithms (like RC4) that are needed for SSL connection server-client handshake and key exchange processes. I get a NoClassDefFoundError when trying to connect to a SSL server (when RC4 cipher is used) using the Mozilla JSS provider as the default. Now, when I set the first provider in the java.security file like this: security.provider.1=sun.security.provider.Sun security.provider.2=org.mozilla.jss.JSSProvider .... The handshake completes, but of course th

1/19/2006 8:41:43 AM 0 tron...@gmail.com
are DH and anonymous DH cipher suites implemented?

In the SSL_ImplementedCiphers data structure in sslenum.c, I don't find any cipher suites that use non-ephemeral Diffie-Hellman key exchange that doesn't involve elliptic curve cryptography. In particular, the cipher suites I am interested in are: SSL_DH_RSA_WITH_3DES_EDE_CBC_SHA and SSL_DH_ANON_WITH_3DES_EDE_CBC_SHA Is it really the case that NSS implements only ephemeral DH cipher suites? If yes, why is that the case? Regards, Peter

1/17/2006 6:41:49 AM 2 "Peter Djalaliev" <peter.djalal...@gmail.com>
Multiple certificate databases with NSS?

Apparently there is some work being done to enable use of multiple certificate databases with NSS. Does anyone know what the timetable is for this? Are there any APIs that we can take a look at? Any pre-release version we can try out? Cheers, Matt

1/16/2006 10:00:33 AM 1 "Matthew Gertner" <matt...@allpeers.com>
generating a .DEF file when adding code to the NSS source tree

Hello, There are some external files that I want to compile into NSS, they contain functions that I call from within the SSL module (during the establishment of the SSL3/TLS handshake). I tried creating another folder, called tcpa, in mozilla/security/nss/lib. I modified the manifest.mn file to include 'tcpa' in the DIRS variable. Then, I created the Makefile and manifest.mk files in 'tcpa'. I didn't use a local 'config.mk' file. My local 'manifest.mn' file looks like this: CORE_DEPTH = ../../.. # DEFINES = -DTRACE LIBRARY_NAME = tcpa LIBRARY_VERSION = 1 EXPORTS =

1/15/2006 12:56:29 AM 1 "Peter Djalaliev" <peter.djalal...@gmail.com>
Thunderbird says: "Could not verify this certificate for unknown reasons" to the certs I made with CA.pl

I'm trying to be my own, personal CA. The plan is to create my own, self-signed CA cert, import that cert as a trusted authority on Thunderbird, Firefox, whatever.... and then create certs (signed by my new CA cert) for use on the various servers that I and a few other friends use. Using the openssl CA.pl script, I did the following: CA.pl -newca CA.pl -newreq CA.pl -sign At this point, I've got my cacert.pem, newreq.pem, newkey.pem, and newcert.pem. newcert.pem includes both a "-----BEGIN CERTIFICATE----- " section as well as what looks to be the human-readable output

1/14/2006 11:35:07 AM 2 ...@emenaker.com
The new High Assurance SSL Certificates

Apparently a number of commercial issuers of certificates are currently considering creating a new class of "High Assurance" (HA) SSL server-certificates, in order to improve the somewhat bad reputation associated with the current scheme. In a recent Mozilla blob, it was suggested that Firefox in order to recognize that it is really dealing with a high assurance certificate (and presumably showing that to the user in some way), should rely on a specific set of agreed-upon RFC 3280 policy identifiers. This is in my opinion a not very good idea for two reasons: 1. SSL server-certi

1/14/2006 10:56:40 AM 3 "Anders Rundgren" <anders.rundg...@telia.com>
com.netscape.jss.ssl package

We're using Sun's iPlanet as our LDAP server and are trying to implement LDAP via SSL in our Java apps (we're using the Directory SDK 4.1 for Java). I'm using the class netscape.ldap.factory.JSSSocketFactory, which makes reference to another class: com.netscape.jss.ssl.SSLCertificateApprovalCallback.ValidityStatus But I can't find that class anywhere, and when I run the app I get a NoClassDefFoundError. I have found tons of references to a mozilla package with a similar name, but nothing for the package my code is looking for. Is there another jar I need to include or downloa

1/12/2006 8:46:49 PM 1 pra...@gmail.com
When do we call FlushHandshake()?

I am modifying the TLS protocol inside NSS by adding two more handshake messages between the certificate verify message that the client sends to the server and the change cipher specs also from the client to the server So, the TLS handshake now looks as follows: -> client_hello <- server_hello <- server certificate <- key exchange <- certificate request (mandatory) <- hello done -> client certificate -> client key exchange -> certificate verify <- ADDITIONAL MESSAGE 1 -> ADDITIONAL MESSAGE 2 ->change cipher spec ->finished <-change cipher spec <-finished For

1/12/2006 4:13:59 AM 3 "Peter Djalaliev" <peter.djalal...@gmail.com>
Own key and certificate token

Hi, I have been developing an extension to the FireFox witch directly uses NSS and creates own PKI. I would like to ask, if there is some way in the NSS to establish my own key and certtificate token. I'd like to run my own token parallel with existing softoken device, manage password and authentication to this slot my own way and store all my certificates and private/public keys into this own slot. Currently I am using token obtained with PK11_GetInternalKeySlot() for key management (generation/search etc.) and CERT_GetDefaultCertDB() for access to the cert database. Waht is glob

1/5/2006 4:33:23 PM 2 "honzab" <bam...@acepoint.cz>
Stephan Ducharme just became a millionaire on the Internet

Stephan Ducharme just became a millionaire on the Internet ... and he was caught on tape, revealing everything totaly free ! Click here : http://freeadguru.com/cgi-bin/i.pl?c=a&i=31222 Rush on the page before it gets banned! --- MAF Anti-Spam ID: 20051203191355N7m2AnV9

1/3/2006 4:06:17 PM 0 "Matthew" <affiliatec...@hotmail.co.uk>
Paypal Magic... Make money by 5 bucks, give it a try

PAYPAL MAGIC!!! TURN $5 INTO $15,000 IN ONLY 30 DAYS...HERES HOW! This is a Money Scheme and Not, I repeat... This is Not a Scam!!! You have most likely seen or heard about this project on TV programs such as 20/20 and Oprah, or you may have read about it in the Wall Street Journal. If not, here it is below - revealed to you in step-by-step detail. This program is by no means new. It has been in existence in many forms for at least a decade. But in the early days, it required a lot more time and effort, as well as an investment of a few hundred dollars. Howe

1/1/2006 4:32:19 PM 0 "eddy" <edru...@yahoo.com>
Disabling default Software Security Device

------=_Part_6682_28043328.1135205686265 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Hello, How can I disable the 'Software Security Device' on FireFox and Netscape under any circumsatances ? Thanks, Oscar ------=_Part_6682_28043328.1135205686265 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline <div>Hello,</div> <div>&nbsp;</div> <div>How can I disable the 'Software Security Device' on FireFox and Netsca= pe </div> <div>under any

12/21/2005 10:54:46 PM 0 Oscar So <oscarsoope...@gmail.com>
New software security device

Hello. Is there any way to create a new Software security device besides the one that is bundled with Mozilla/Firefox? I know it is possible to add new hardware security devices, and then choose among all of them. And I need to do it in the same profile. I am doing some tests and need to select between security devices (this is the important part for my tests). Thank you in advance. Emilio Perez.

12/20/2005 9:08:57 PM 1 Emilio Perez <...@cesatel.net>
using NSPR logging with NSS

Hello, I am running NSS with modified SSL3/TLS library in Mozilla Firefox. I used the NSPR logging functionality (to track the status of the modified TLS handshake) as described in http://www.mozilla.org/projects/nspr/reference/html/prlog.html#25604 Additionally, I tried using the PR_SetLogFile to specify the location of the log file. Is this the best way to do this? Best regards, Peter

12/19/2005 9:41:55 PM 2 "Peter Djalaliev" <peter.djalal...@gmail.com>
pkcs #11 test suite - win32 executable available?

I want to test out the pkcs #11 test suite but am looking for an executable version for win32. I looked over the archives and was only able to find people with problems in compiling on that platform. If anyone succeeded, could they please reply and maybe supply me with a working copy? Or if there is a howto compile for the win32 platform I would appreciate a pointer. With regards, Mads Rasmussen

12/14/2005 11:42:25 AM 0 Mads Rasmussen <m...@lsitec.org.br>
exporting NSS based software

Hi, All! I wonder if anyone knows what needs to be done to export from the US non-open source binaries that use an un-modified NSS library to a "friendly" country (i.e. a country not in the list of usual suspects)? And also I wonder if there is any difference between "just downloading the software from outside the US" and "selling the software to someone outside of the US" in this regard. I know that the best answer on my question would be "call your lawyer" and I am sure I will do it soon ... but now I am looking for a quick advice from someone who might have had similar proble

12/9/2005 6:56:40 AM 2 Aleksey Sanin <alek...@coral8.com>
What is the maximum supported for the modulus in the current version of NSS ?

Hi Guys, I was wondering what is the maximum modulus size supported for RSA or DSA keys in NSS ? For example, we experienced various errors from Thunderbird client (1.0.6,1.0.7 and various other versions) when trying to connect in TLS to an ESMTP server with CA keys with 2048 bits modulus. The error is the following : "could not establish an encrypted connection because certificate presented by <IP> is invalid or corrupted Error Code -8182". With random keys with a smaller modulus, it seems to be ok. Thanks a lot for any feedback, Kind regards,

12/5/2005 5:03:42 PM 1 "adulau" <adu...@gmail.com>
Compilation error of NSS

Hello, The rules.mk file in mozilla/security/coreconf/ does not work on my Windows XP system. I use the MSVC 6.0 compiler and the cygwin path (/cygdrive/.../) is inserted absolutely in the compiler command line. So cl fails. I have changed the fail to this: $(OBJDIR)/$(PROG_PREFIX)%$(OBJ_SUFFIX): %.c @$(MAKE_OBJDIR) ifdef USE_NT_C_SYNTAX $(CC) -Fo$@ -c $(CFLAGS) $< # $(CC) -Fo$@ -c $(CFLAGS) $(call abspath,$<) else ifdef NEED_ABSOLUTE_PATH $(CC) -o $@ -c $(CFLAGS) $(call abspath,$<) else $(CC) -o $@ -c $(CFLAGS) $< endif Karsten

12/4/2005 12:25:24 AM 6 Karsten Ohme <k...@users.sourceforge.net>
creating a module

Hi, what are the (minimum) requirements to be able to load a library as a security module. When importing the module I always get the message "Unable to add the module". Thanks, Daniel

12/2/2005 1:09:20 PM 1 Daniel Etzold <detz...@gmx.net>
Recomendation for Crypto method

Hi I'm building a client/server app for playing bridge online. The client we be written in xul - loaded in the browser through http (not chrome). I am looking for a way to encrypt the user's password on the client. These are my requirements: 1. I want to make sure that I don't disclose the user's password. The user may use this password on other sites - so they will be the temptation for a cracker to sniff my servers traffic/access my user db, so they can get these passwords and try using them for more important sites. I want to stop this. 2. I am *not* trying to stop th

11/30/2005 2:13:33 PM 1 "Gary van der Merwe" <gary...@gmail.com>
How can I get htpps pages working in my app that uses mozilla?

Hello. I have an application which uses mozilla 1.7.12 for displaying web pages. And it doesn't work with https protocol. PSM is turned on the only thing that happens is gpf First there is a call to PK11_GetInternalSlot(); which calls SECMOD_GetInternalModule and it returns 0; As I understand I need to make proper initialization of NSS using NSS_Initialize and then use SECMOD_AddNewModule to add a new module. Is that right? But I can't find any samples of this in the net. Can anyone provide the sample how to get https(nss) working in a custom application using mozilla? Thanks.

11/30/2005 11:21:49 AM 0 "Eugene Maltsev" <euge...@aldec.com.pl>
certificate trust settings gui

I don't know if this has been covered here before. I did a quick search through bugzilla and didn't find anything so here goes. If this isn't an existing issue I'll be happy to file a feature request bug. I was thinking about how the certificate trust settings gui works and if you select all the trust settings for a root CA you do not have to select any options at all for any subordinate CAs. If you open the trust dialog for a subordinate CA whose root CA is fully trusted then usually all the check boxes are left blank. What would be nice to see is a grayed out check box f

11/28/2005 2:43:16 PM 2 David Stutzman <david.konrad.stutzman*at*us.army.mil>
Generation of public key on token

Hi, I have a PKCS11 (v 2.1) library ,.. Using this library via Mozilla I am trying to import a certificate on to the smart card. The process fails because this library does not support generation of RSA public keys on the token.. On looking at the failure point I see that much before the call to slbXsiPkiGenerateKeyPair() there is a check on the PublicKey Template to determine whether it is a Token object or not. If it is, then the check reports an error: "Can't generate RSA public keys on the token!" I am a rookie with PKCS stuff, can someone please explain to me how to go a

11/24/2005 12:07:56 PM 0 "Vivek" <viveque.ku...@gmail.com>
data format of private key on token

Hi, when importing a certificate onto a token Mozilla is doing the following steps: 1. create a secret key K 2. unwrap a buffer of 640 bytes with K and create a private key P 3. delete k 4. store the certificate Now I want to sign a message. My question: what is the data format of P? Is it defined in any PKCS standard? Thanks, Daniel

11/22/2005 8:41:18 PM 1 Daniel Etzold <detz...@gmx.de>
adding a function to CK_FUNCTION_LIST

Hi, We have this PKCS#11 (2.1) implementation of the crypto module for smart cards... Besides the 68 functions, can I add another custom function for the application to call? I have been successfully been able to add the function and use the library from our applications, but when I try to load the module using the Mozilla browser, it reports an error saying "Unable to load module"... If I remove the function from the list everything works fine and the module gets loaded by the browser... Is this a wrong way to add a function to the crypto module or do I need to anything else

11/21/2005 12:35:21 PM 0 "Vivek" <viveque.ku...@gmail.com>
Re: CASH MONEY TO YOUR DOOR!!!

START YOUR OWN E-MAIL BUSINESS TODAY and TAKE ADVANTAGE OF THE FOLLOWING: 1.ALL CUSTOMERS PAY YOU IN CASH!!! 2. TOP PART-TIME OWNERS HAVE EARNED $5,000+ IN ONE MONTH! 3. TOP FULL-TIME OWNERS HAVE EARNED $10,000+ IN ONE MONTH! 4. YOU WILL SELL A PRODUCT WHICH COSTS NOTHING TO PRODUCE! 5. YOUR MAIN OVERHEAD IS YOUR TIME! 6. YOUR START UP COSTS ARE LESS THAN $25 7. YOU HAVE MORE THAN 40 MILLION POTENTIAL CUSTOMERS For additional information please E-mail me at saita@dodo.com.au ===================================================== New Software that finds leads for YOU for F

11/20/2005 4:11:18 PM 0 "Tia" <sa...@dodo.com.au>
JSS UnsatisfiedLinkError: already loaded in another classloader

Hi! I'm using JSS with a web signing applet. When refreshing the web page containing the applet or launching it in another window, cryptoManager initialization raises this error: java.lang.UnsatisfiedLinkError: Native Library jss3.dll already loaded in another classloader The only way to go back to a normal behaviour is to restart the browser. All windows should be closed. Is there a way to bypass this error without limiting applet user's actions? thx! PS: This error does not appear when using other applets with JNI modules.

11/14/2005 11:08:42 AM 0 mmbouallagui <mmboualla...@free.fr>

Pages: 2











Newest Articles

[Hendrix] recent tags and recently bookmarked disappeared when I reinstalled ff36
8 hour 57 mins ago

[Hendrix] www.KORBANEK.pl TARGI ROLNICZE AGROTECH KIELCE
9 hour 0 mins ago

[Hendrix] fix quick
9 hour 17 mins ago

[Hendrix] what does ativan do sae
9 hour 26 mins ago

[Hendrix] "Tools/Options/Manage Add-ons/Plugins" default settings
10 hour 11 mins ago