OSCP protocol vs CRLs

2010-07-13 Thread Ingela Andin
Hi! I would like to know what is the most common way to handle certificat revokation? Is it OSCP protocol or CRLs? Firefox seems to handle both to some extent, but the default seems to be only use OSCP if the certificate extensions specifies a server. My CRL database is empty, but has a manual im

Re: DH-cipher suites and export cipher suites.

2010-05-19 Thread Ingela Andin
Hi! 2010/5/19 Dr. Stephen Henson : > On Wed, May 19, 2010, Ingela Andin wrote: > >> >> >From OpenSSL documentation: >> "The non-ephemeral DH modes are currently unimplemented in OpenSSL >> because there is no support for DH certificates." >> >&g

DH-cipher suites and export cipher suites.

2010-05-19 Thread Ingela Andin
Hello! I use openSSL to test our own Erlang SSL/TLS implementation that also uses openssl crypto facilities. This all works out very good. I have two questions that are more on a principal level than a use of openssl questions, but I do not think they really fit in very good on any of the lists, s