Re: On the future of <keygen> and application/x-x509-*-cert MIME handling
Hubert Kario <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On Thursday 30 July 2015 12:57:57 Ian G wrote: > On 30/07/2015 11:53, Hubert Kario wrote: > > lack of easy, cross-application certificate deployment is the _reason_ for > > low rates of deployment of client certificates, but where they are > > deployed, they are _critical_ > > If there is one thing that definitively improves security for users it > is client certs. If there is one thing that screws client certs for > everyone, it's non-investment by vendors. If there's one thing that the > vendors couldn't figure out how to monetise and franchise, it's client > certs. > > Connect the dots... and that's why we're working on stuff like http://p11-glue.freedesktop.org/ and https://fedoraproject.org/wiki/Changes/CryptoPolicy to make use of proper crypto manageable, but this takes time -- Regards, Hubert Kario Quality Engineer, QE BaseOS Security team Web: www.cz.redhat.com Red Hat Czech s.r.o., Purkyňova 99/71, 612 45, Brno, Czech Republic _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security
signature.asc
(application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAABCgAGBQJVu1krAAoJEJKo0bgB0vX1Dg0QAJP11qes2Bsilhi5eqR4FxOO meRdBr24g3omLAHEJwAHtd4wvSNKfbopTAkbLH+ZqihchWGJtJjljHZ7xZkT2o2E fzE0BwGrdD4oKG5RW0JD401yyjIEJhEwkzWnMfAL38hpLbChPSr8Ml4axaARztXq A+krFjff86q/MT2jMKmAPNshn7OXCpyWduNoXLXnQia2k6oYvfXtXBDYk9eFIgIb 9Doz6gPUuv3ZSctldt+8qiOTBgXWpDHRjMoIV2dZrcmIZ+fKdI5QUnwbbXHNYgRw BQYpxAGAds3nkGZ0XmgmF0WhX5nKo7GPiazsXJxczIiiKjTUYR/WRTa6oFrUfDwc MhoZjrSLwQN+GCbziogHbFNyqUPTYznUUPijIQe8SNF8L/+U0ygGKF9dDfndITKY rzfYfNvIa7lVoChvpwf1xKQExFJT4lIyuITTYQvcPj8w+lbnoTbPEi+uRuiIkvzu mfe6dWWy9Y5WURLD2nmXjELE6DSLOvFxb2ZkKNCTmbfVrdnlQXcXOdeVAusEJfL8 qZJzIOvDXqBoWOla/S5uCGnYJqmJqpzQtktaFj+Fwqut7XiY7nD4mM0i0C8vWFFZ NYJdWROONW0L+MH+DoO7IckwLjqgbIeMgvJDMxa9WweBqijshNNozA8CJN3CzzHS vE8s6J4DU2y38q4p4vLQ =NCs9 -----END PGP SIGNATURE-----