Tuesday, August 29, 2017

Re: ECDH

On Tue, Aug 29, 2017 at 9:36 PM, Patrick Dohman <patrick_dohman@centurylink.net> wrote:

> I've read that SHA1 can be brute forced however why Mozilla Firefox forces a ECDH is misunderstood if attempting to negotiate for example RSA

Because they copied M$IE. This is no longer the case with the latest version of FF.

>In my experience sea monkey can authenticate correctly against an apple key-chain however Firefox returns cipher suite errors
>
>Regards Patrick

We do not trust browsers keychain management. We use their own keychain with care, and avoid linking it with system keychain.

> On Aug 29, 2017, at 2:25 PM, Rupert Gallagher wrote:@protonmail.com>
> @protonmail.com>
>https://www.ssllabs.com/ssltest/viewClient.html?name=Firefox&version=53&platform=Win%207&key=142@protonmail.com>

@centurylink.net> @protonmail.com>

No comments:

Post a Comment