RE: Réf. : RE: Netscape interoperabil ity

"Pawling, John" <[email protected]> Tue, 3 Jul 2001 13:44:34 -0400
Newsgroups gmane.ietf.sfl
Message-ID <[email protected]>
Eric,

That is quite possible.  RFC 2459 (Internet X.509 PKI Certificate and CRL
Profile) states: 
     
   CAs conforming to this profile MUST always encode certificate
   validity dates through the year 2049 as UTCTime; certificate validity
   dates in 2050 or later MUST be encoded as GeneralizedTime.

By the way, Bob Colestock was able to successfully import your PKCS #12 file
(including GeneralizedTime) into MS Outlook.

===========================================
John Pawling, [email protected]
Getronics Government Solutions, LLC
===========================================


-----Original Message-----
From: [email protected] [mailto:[email protected]]
Sent: Tuesday, July 03, 2001 1:39 PM
To: Pawling, John
Cc: [email protected]
Subject: Réf. : RE: Netscape interoperability



Mr. Pawling,

Is it possible that Netscape did not recognize GeneralizedTime ????

My certificate in the PFX file that i have sent to you was generated with
GeneralizedTime.  I have try to generate the same crtificate with UTCTime
and Netscape was able to import my certificates and private key in his data
base.

Thanks.

**************************************************************************
Eric Boudreault
------------------------------------------------
Programmeur
------------------------------------------------
Motus Technologies
390, St-Vallier Est
Bureau 100
Québec, Qc
G1K 3P6
Tél.: 521-2100  ext.#242
Fax.: 521-2101
courriel: [email protected]
**************************************************************************




 

                    "Pawling, John"

                    <John.Pawling@Getroni        Pour :
"'[email protected]'" <[email protected]>,                
                    csGov.com>                   [email protected]

                                                 cc :

                    29/06/01 10:09               Objet :      RE: Netscape
interoperability                                
 

 





Eric,

Bob Colestock was able to successfully import your PKCS #12 file into MS
Outlook.  We will test it with Netscape.  There are differences in the way
that Microsoft and Netscape implemented PKCS #12 (especially in earlier
releases).  We hope to have more info for you later today.

===========================================
John Pawling, [email protected]
Getronics Government Solutions, LLC
===========================================


-----Original Message-----
From: [email protected] [mailto:[email protected]]
Sent: Thursday, June 28, 2001 5:16 PM
To: [email protected]
Subject: Netscape interoperability



Hi,

I am in the interoperability tests with Netscape and i have problems to
import my certificates.  They are all in a PKCS-12 file generated by my
library.  The problem is that the browser always pop this message with
Netscape 6.01:  "The certificate and private key already exist on the
security device.".  With older versions (4.x) it crash every time.

Can you help me with that ????

There is the file that i have problems with :  (the password is "eric")

(See attached file: Test_Netscape_1.p12)



Thanks.

**************************************************************************
Eric Boudreault
------------------------------------------------
Programmeur
------------------------------------------------
Motus Technologies
390, St-Vallier Est
Bureau 100
Québec, Qc
G1K 3P6
Tél.: 521-2100  ext.#242
Fax.: 521-2101
courriel: [email protected]
**************************************************************************