Re: Signing xpi files

Myk Melez <[email protected]>
Newsgroups gmane.comp.mozilla.devel.xpinstall,gmane.comp.mozilla.crypto
Organization Another Netscape Collabra Server User
Message-ID <[email protected]>
I received a VeriSign signing certificate a few months ago to use for 
signing a remote XUL/JavaScript application.  I experienced the same 
problem you did and with the help of Bill Burns, a security specialist 
at my company, tracked it down to a missing intermediate certificate, 
which Bill then obtained and provided to me.  I've cc:ed him on this 
email.  Bill, what should someone do in this situation to obtain the 
missing intermediate certificate?

-myk


Mike Smithwick wrote:

>I have spent quite some time trying to figure out this signing biz,
>but it seems like the signtool docs are still stuck in Netscape 4 land
>and so are nearly useless.
>
>We were given a "p12" file from our CA. I assume that is by definition
>the certificate. The docs mention exporting a p12 file, but never
>importing one, yet the Mozilla cert manager only permits importing a
>file. So I tried that, and our cert appeared in the list. From the
>docs it appeared as if Signtool then uses the two db files to get the
>info it needs: cert7.db and key3.db which I moved over to the
>directory that has my projects. (Pointing signtool to the original
>directory with the db files caused it to crash, probably the directory
>name was too long and overflowed some buffer).
>
>Now I type in "signtool -l", and it both shows our certificate and the
>line "Error++ Unable to find issuer in certificate". I assume that
>means it cannot find a legal Verisign cert, but when I do a -L I
>clearly see that certificate as listed.
>
>I can create a temporary internal certificate and it works fine.
>
>what gives?
>  
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.