ongoing security & privacy help content updates per b=85925, a=asa, r=oeschger

This commit is contained in:
cotter%netscape.com 2001-08-27 07:18:39 +00:00
Родитель d0d952b223
Коммит 1ed52537c0
5 изменённых файлов: 25 добавлений и 7 удалений

Просмотреть файл

@ -23,6 +23,7 @@
<p><a href="cert_dialog_help.html#Certificate_Backup">Certificate Backup</a>
<p><a href="#User_Identification_Request">User Identification Request</a></p>
<p><a href="#New_Certificate_Authority">New Certificate Authority</a></p>
<p><a href="#old_next_update_crl">Browser Won't Accept CRL</a></p>
<p><a href="#Web_Site_Certificates">Web Site Certificates</a></p>
</td>
</tr>
@ -165,6 +166,21 @@
<LI><B>Trust this CA to identify software developers.</B> Selecting this option means that you trust the CA to issue certificates that identify the origin of Java applets and JavaScript scripts requesting special access to your computer, such as the ability to change files. Since such access privileges can be misused, for example to destroy data stored on your hard disk, be very careful about selecting this option unless you are certain that you trust the CA for this purpose.
</ul>
<p>&nbsp;</p>
<a NAME="old_next_update_crl"></a>
<h2>Browser Won't Accept CRL</h2>
<p>A certificate revocation list (CRL) is list of revoked certificates. The browser uses the CRLs it has available to check the validity of certificates issued by the corresponding <a href="glossary.html#certificate_authority_(CA)">certificate authorities (CAs)</a>. If a certificate is listed as revoked, the browser won't accept it as evidence of identity.
<p>A CA typically publishes an updated CRL at regular intervals. Every CRL includes a date, specified in the Next Update field, by which the CA will publish the next update of that CRL. If the date in the Next Update field is earlier than the current date, you should obtain the most recent version of the CRL.
<p>Although the absence of the most recent CRL does not by itself invalidate a certificate, the browser can't accept a server certificate unless the corresponding CRL is the most recent available. In some situations, you may want to delete CRLs with Next Update dates earlier than the present. Speak to your system administrator for guidance on CRL management.
<p>For more information on CRLs and instructions for viewing or deleting them, see <a href="using_certs_help.html#Managing_CRLs">Managing CRLs</a>.
<p>&nbsp;</p>
<a NAME="Web_Site_Certificates"></a>
<h2>Web Site Certificates</h2>
@ -209,7 +225,9 @@
</ul>
<p>Selecting "Remember this certifidate permanently" solves the problem for this web site certificate, but you'll see the same alert for any other web site whose certificate was issued by the same CA. To ensure that the Certificate Manager will trust all certificates issued by a given CA, you must edit the trust settings for the the corresponding CA certificate. To do so, follow these steps:
<p>Selecting "Remember this certifidate permanently" solves the problem for this web site certificate, but you'll see the same alert for any other web site whose certificate was issued by the same CA.
<p>To ensure that the Certificate Manager will trust all certificates issued by a given CA, you must edit the trust settings for the the corresponding CA certificate. To do so, follow these steps:
<ol>
<li>Open the Edit menu and choose Preferences.
@ -220,7 +238,7 @@
<li>Click the Edit button and select the appropriate trust settings.
</ol>
<p>For help deciding which trust settings you should select, click the Help button in the Edit dialog box or see <a href="certs_help.html#Edit_CA_Certificate_Settings">Edit CA Certificate Settings.
<p>For help deciding which trust settings you should select, click the Help button in the Edit dialog box or see <a href="certs_help.html#Edit_CA_Certificate_Settings">Edit CA Certificate Settings</a>.
<p>&nbsp;</p>
@ -272,7 +290,7 @@
<hr>
<p><i>8/20/2001</i></p>
<p><i>8/21/2001</i></p>
<p>Copyright &copy; 1994-2001 Netscape Communications Corporation.</p>
</body>

Просмотреть файл

@ -373,7 +373,7 @@
<a name="Managing_CRLs"><h2>Managing CRLs</h2></a>
<p>A certificate revocation list (CRL) is list of revoked certificates. A <a href="glossary.html#certificate_authority_(CA)">Certificate authority (CA)</a> might revoke a certificate, for example, if it has been compromised in some way&#151;much the way a credit card company might revoke your credit card if you report that it's been stolen.
<p>A certificate revocation list (CRL) is list of revoked certificates. A <a href="glossary.html#certificate_authority_(CA)">certificate authority (CA)</a> might revoke a certificate, for example, if it has been compromised in some way&#151;much the way a credit card company might revoke your credit card if you report that it's been stolen.
<h3>Downloading and Updating CRLs</h3>
<p> You can download the latest CRL from a CA to your browser. To download a CRL, you typically go to a URL (specified by the CA or by your system administrator) and click a link.

Просмотреть файл

@ -373,7 +373,7 @@
<a name="Managing_CRLs"><h2>Managing CRLs</h2></a>
<p>A certificate revocation list (CRL) is list of revoked certificates. A <a href="glossary.html#certificate_authority_(CA)">Certificate authority (CA)</a> might revoke a certificate, for example, if it has been compromised in some way&#151;much the way a credit card company might revoke your credit card if you report that it's been stolen.
<p>A certificate revocation list (CRL) is list of revoked certificates. A <a href="glossary.html#certificate_authority_(CA)">certificate authority (CA)</a> might revoke a certificate, for example, if it has been compromised in some way&#151;much the way a credit card company might revoke your credit card if you report that it's been stolen.
<h3>Downloading and Updating CRLs</h3>
<p> You can download the latest CRL from a CA to your browser. To download a CRL, you typically go to a URL (specified by the CA or by your system administrator) and click a link.

Просмотреть файл

@ -453,7 +453,7 @@ A domain cookie is sent back to any site that's in the same domain as the site t
<p>In addition, a new profile will not include any customizations you may have made to your bookmarks, address books, mail filters, and so on while using your old profile.
<p>It is possible to copy some files (such as bookmarks.html, which contains all your bookmarks) from your old profile directory to your new profile directory by hand, but this can be complicated and may not work for all your customizations.
<p>It is possible to copy some files (such as bookmarks.html, which contains all your bookmarks) from your old profile directory to your new profile directory by hand, but this may not work for all your customizations.

Просмотреть файл

@ -453,7 +453,7 @@ A domain cookie is sent back to any site that's in the same domain as the site t
<p>In addition, a new profile will not include any customizations you may have made to your bookmarks, address books, mail filters, and so on while using your old profile.
<p>It is possible to copy some files (such as bookmarks.html, which contains all your bookmarks) from your old profile directory to your new profile directory by hand, but this can be complicated and may not work for all your customizations.
<p>It is possible to copy some files (such as bookmarks.html, which contains all your bookmarks) from your old profile directory to your new profile directory by hand, but this may not work for all your customizations.