Google Groups Home
Help | Sign in
Trunk: Please watch out for regressions with secure sites
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  4 messages - Collapse all
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Kai Engert  
View profile
 More options Apr 5 2006, 5:18 pm
Newsgroups: mozilla.dev.tech.crypto, mozilla.dev.general, mozilla.dev.security
Followup-To: mozilla.dev.tech.crypto
From: Kai Engert <kengert-nospam-remove182ij28...@redhat.com>
Date: Wed, 05 Apr 2006 23:18:13 +0200
Local: Wed, Apr 5 2006 5:18 pm
Subject: Trunk: Please watch out for regressions with secure sites
Yesterday we checked in a larger change to the trunk that affects secure
connections (SSL/TLS) in all Mozilla applications.

The new code is active whenever you access a site using a protocol like
https:// or imap+ssl or smtp+tls, etc.

The purpose of the change is to make OCSP (certificate validation) work
through proxies (see bug 111384).

When testing nightly trunk builds of Firefox, Thunderbird or SeaMonkey,
please report any regressions in bugzilla.mozilla.org to the
"Core/Security PSM" component.

Should the change have introduced regressions to SSL/TLS, you should run
into them, regardless whether you actually use the OCSP feature.

However, if you'd like to test further, feel free to enable the "Use
OCSP to validate certificates that specify an OCSP service URL" feature.
Even if you're behind a firewall that requires the use of a proxy, it
should work with latest nightly trunk builds.

To enable go to:
Firefox: Edit/Prefs/Advanced/Security/Verification
Thunderbird: Edit/Prefs/Privacy/Security/Verification
SeaMonkey: Edit/Prefs/Privacy&Security/Validation

Thanks for your help!
Kai


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
steve.england@gmail.com  
View profile
 More options Apr 8 2006, 9:55 am
Newsgroups: mozilla.dev.tech.crypto
From: "steve.engl...@gmail.com" <steve.engl...@gmail.com>
Date: 8 Apr 2006 06:55:58 -0700
Local: Sat, Apr 8 2006 9:55 am
Subject: Re: Trunk: Please watch out for regressions with secure sites
Is the error message ("Dearpark and secureads.ft.com can not
communicate securily because they have no common encryption
algorithms?") generated from
http://news.ft.com/cms/s/257d272e-c665-11da-99fa-0000779e2340.html
anything to do with this?

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Nelson B. Bolyard  
View profile
 More options Apr 8 2006, 1:00 pm
Newsgroups: mozilla.dev.tech.crypto
From: "Nelson B. Bolyard" <nel...@bolyard.com>
Date: Sat, 08 Apr 2006 10:00:21 -0700
Local: Sat, Apr 8 2006 1:00 pm
Subject: Re: Trunk: Please watch out for regressions with secure sites

steve.engl...@gmail.com wrote:
> Is the error message ("Dearpark and secureads.ft.com can not
> communicate securily because they have no common encryption
> algorithms?") generated from
> http://news.ft.com/cms/s/257d272e-c665-11da-99fa-0000779e2340.html
> anything to do with this?

No, https://secureads.ft.com/ is an OLD "export" version of the Netscape
Enterprise Server, version 3.6, which only was capable of the old "40-bit"
cipher suites.  Those 40-bit cipher suites are now disabled by default
in deerpark.  AFAIK, that has nothing to do with Kai's recent work.

Thanks for reporting that site.
--
Nelson B


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Wan-Teh Chang  
View profile
 More options Apr 10 2006, 2:06 pm
Newsgroups: mozilla.dev.tech.crypto
From: Wan-Teh Chang <wtch...@redhat.com>
Date: Mon, 10 Apr 2006 11:06:27 -0700
Local: Mon, Apr 10 2006 2:06 pm
Subject: Re: Trunk: Please watch out for regressions with secure sites

Nelson B. Bolyard wrote:
> steve.engl...@gmail.com wrote:
>> Is the error message ("Dearpark and secureads.ft.com can not
>> communicate securily because they have no common encryption
>> algorithms?") generated from
>> http://news.ft.com/cms/s/257d272e-c665-11da-99fa-0000779e2340.html
>> anything to do with this?

> No, https://secureads.ft.com/ is an OLD "export" version of the Netscape
> Enterprise Server, version 3.6, which only was capable of the old "40-bit"
> cipher suites.  Those 40-bit cipher suites are now disabled by default
> in deerpark.  AFAIK, that has nothing to do with Kai's recent work.

> Thanks for reporting that site.

Yes, this is a known issue with that site:
https://bugzilla.mozilla.org/show_bug.cgi?id=332667

Kai Engert has sent a message to the webmaster of that
site.

Wan-Teh


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2008 Google