Online Security with "best attempts" set for certificate verification

As many others, I've had some security issues with both webkit browsers and the iTunes store after upgrading to 10.4.8 and running the late-November security update. Basically it was impossible to access https sites as well as the iTunes store without changing my certificate verification settings in Keychain.
After switching Keychain preferences for certificates to "best attempt" for both OCSP and CRL, things are working fine again. But now my concern is about security. Basically, how insecure are such settings? Is Apple working at all on a fix for this or should I basically wait to upgrade to Leopard before expecting a solution?
Thanks in advance.

Hi Shadya10,
Those are some pretty big questions! I'm not saying that your company can't become a CA because obviously there are companies that have, but this is almost something that happens at the state level if your not already intimate with PKI. Just from the tenor of your questions I'd suggest you contract with a reputable, existing CA to provide your PKI infrastructure. I could explain key management and how revocation checking works, but really if you're asking in an Adobe forum this is way more than you want to be dealing with.
If you're really interested you need to start with reading RFC 5280.
Steve

Similar Messages

  • What is the best Compressor setting for best quality video playback on an iBook g4?

    I know the iBook and G4's in general are very outdated today, but I need to ask anyways. I have some video projects in 720p and 1080p in which I have down converted to 480p and also exported to MPEG-2 for DVD (personal wedding videos and videos made for my clients using Final Cut Studio). Anything encoded at most resolutions using h264 won't play on my iBook. Even 480p.
    I have about 20 hours of mixed video content that I need it in a format that is suitable for an iPhone 4 and an iBook 12" with a 1.2GHz G4, 1.25GB RAM and I added a 250 WD 5400 IDE hard disk (running 10.5.8 and 10.4.11 for Classic Mode). I know the iBook doesn't seem like the best tool for modern video playback, but I need to figure out which setting will play best with iPhone 4 and iBook so I don't need to make 2 local copies of each video for each device.
    The iBook plays best with the original DVD output MPEG-2 file and playing back in QT Pro or VLC... but I already have 180 GB's of MPEG-2 files now and my little HD is almost full. I don't have enough room to convert all the iPhone 4 counterparts. If I use Compressor 3.5.3, what is the optimal setting for iBook and iPhone .m4v or .mp4 files that can play on both devices? So far 720x400-480 widescreen videos @ 29fps works great on my iPhone, Apple TV 2, and other computers but seems to murder my poor iBook if encoded with high profile (and still choppy on simple profiles). 640x480 (adding black matte bars to my videos) plays fine in MPEG-2 but drops frames or goes to black screen if I convert it to mp4 (and looks bad on the iPhone 4 because of the matte). But if I convert on any of the simple profiles, it looks terrible on my iPhone 4 and a blocky on the iBook.
    This is the problem leading me to having 2 copies of each video and eating my hard disk space. What is the best video setting for both playback on the iBook and iPhone 4? Can the iBook playback H264 at all in decent resolutionsat all? I don't really want to have a 480p .m4v collection for the iPhone 4 and a MPEG-2 RAW collection just to play the same videos on the iBook.
    Any suggestions are greatly appreciated! Thanks!

    Update: The iBook can play any 480p video and higher if I encode them with DivX and in AVI format. But of course this is not compatible with my iPhone 4. At least I can shrink my library now and get away from the full MPEG-2s. I don't get why I can't use Apple's h264 though. There has to be a setting I am missing. The sample Apple h264 videos from the days of Tiger worked flawlessly on my iBook when it was new so the CPU must be capable of decoding it. I really can't understand this.
    Also, since I made my videos in English for my family, I had to create soft subtitles for my wife's Chinese family, and I can't get players like QT with perian or MPlayerX to sync them properly to an AVI encoded with DivX, they only sync well with the iPhone 4 m4v/mp4 formatted files I made. This is a real pickle.
    So now I may need three or four copies of each video, LOL. I need to hardcode the subtitles if I want to use AVI to playback on older machines, and keep the mp4 file for the iDevices too, while keeping higher quality h264 videos for my American relatives...
    If h264 is compatible with my iBook, what is the proper encoding settings? Must I dramatically lower the settings or frame rate? I can settle on 2 copies of each video that way. One iBook/G4/eMac compatible video that syncs correctly with my srt soft subs, and another version that works well with my iPhone 4 and iPad.
    All in all, I will end up with more than 3 or 4 version of each video. On my late G5 dual core I have the full 720-1080p uncompressed master files. On my i5 iMac I have the h264 compressed versions for distribution, and lower versions for my iDevices. Now I need to keep either full MPEG-2 files for the iBook to play, or convert to older formats like DivX AVI for our family's legacy machines. I am running out of hard disk space quick now, LOL.
    Is there an easier way?

  • What is the best export setting for video on blogger

    What is the best export setting for video from premeire to blogger.com or blogspot.com

    I have not been able to find the technical limits/specs for the site Blogger or blogspot.com. That is why I made the post here thinking some Adobe users may have experimented already and come up with good export settings for AVI DV video to a format optimized for Blogger.

  • MOVED: Best BIOS setting for MSI K8N Plat + AMD 3000+ Venice + Geil Value RAM

    This topic has been moved to AMD64 nVidia Based board.
    Best BIOS setting for MSI K8N Plat + AMD 3000+ Venice + Geil Value RAM

    If you want SSE3 support and you do not overclock, Bios 1.4 is the only one officially available (1.41beta is not official).
    Try to upgrade to 1.4 and see it for yourself, do the upgrade with floppy in DOS so that you can save your old Bios.
    I would rather wait till mid June when a less troublesome new bios is suppose to be availabe for NEO4 MBs.

  • Best export setting for HD Video

    I am currently woriking with Final Cut Express HD and I am new to the whole HD experience. I would like to know what is the best exporting setting for FCE to be copied on DVD and viewed. I am currently working on a wedding project with a JVC Pro HD camera GY-HD110 720p. Any help will be appreciated. Thank You.

    This is a question better asked in the FCE forum located at the link below:
    http://discussions.apple.com/forum.jspa?forumID=936

  • What is best network setting for jetpack mifi 5510l

    I live in a rural area with poor signal.  No 4G and limited 3G.  We got an antenna that boosts phones from nothing or 1X one bar to 3G and 2-3 bars inside the house.  What is the best network setting for jetpack?  It doesn't seem to work as well. 
    Automatic and 4g don't work.  I don't know what CDMA Auto or EDVO stand for. 
    Any suggestions for improving strength would be appreciated.  I know I won't get a great connection but a steady connection sure would be great.

    > What is the best network setting for jetpack?
    Not sure what you mean.  The jetpack will automatically configure itself to whatever signal it currently has access to.  Shouldn't have to configure any network settings.
    > I don't know what CDMA Auto or EDVO stand for.
    Those are the old 3G networks.
    > Any suggestions for improving strength would be appreciated.
    Perform what is known as a Site Survey and evaluate your current environment:
    http://3gstore.com/page/13_will_an_antenna_help_me.html
    After you generate some numbers then look up what they mean in the Interpret the Results tab.  You mentioned that you already purchased an antenna so there may not be anything else you can do as the local towers in your area are not good enough to reach inside your home.

  • What is the best compressor setting for dvds

    What is the best compressor setting for dvds that is not for HD dvd players? I used "DVD Best quality 90 min" and changed the GOP setting to 7.5 and my dvd looks terrible. the text is blurry and the colors are bad.

    correction the bit rate is 7.5

  • Time consumption for certificate verification

    Hello everyone,
    I tried to track the time consumption for certificate verification. I generated the certificate by myself using X509V1CertificateGenerator in org.bouncycastle.asn1.x509. The signature algorithm is "SHA1withRSA". I generated two different certificates using different public exponent and tracked the time for certificate verification respectively. The first time, the public exponent I used to generate a certificate is 3; the second time, the public exponent I used to generate a certificate is 65537.
    In theory, the operation for signature verification is C=M^e(mod n), in another word, the time consumption should depend on the length of e. More specifically, Time complexity of C=M^e(mod n) should be linear with the length of exponent e, under the same n.
    The method I used for tracking the time is:
    //record the time before verification
    long time1 = (new Date()).getTime();
    //certificate verification
    aCert.verify(publickey)/*Here, 'aCert' is a certificate to be verified. 'publickey' is a public key which I retrieved from an already trusted certificate, and in this case, the first time, e=3, the second time, e=65537.*/
    //record the time after verification
    long time2 = (new Date()).getTime();
    //the time consumption is:
    long period = time2 - time1;But, after I execute using different public exponent 3 and 65537, the time consumption is almost the same, not as it supposed to be.(in theory, due to the different length of 3 and 65537 in binary form(one is 2-bit, the other is 17-bit), the time consumtion should be 17/2 times different). Actualy, in my case, the time for verification using e=3 is 551 ms; and the time for e=65537 is 531 ms.
    I am just wondering, how to explain this bizarre thing?
    Any help is every welcome! Thanks a lot.

    You can check the source code of the oddModPow() method in java/math/BigInteger.java (check src.zip). There are some optimizations in it, so try to verify if they can make the running time of the case "exponent = 3" nearly equal to the case "exponent = 65537". In the first case, 3 = 11 in binary (two bits 1); in the second case, 65537 = 10000000000000001 in binary (two bits 1 as well). Maybe it can be a hint for you.

  • Export Media from DV Pal to AVI: Best recommended setting for Output file?

    I have a project in CS4, on Windows, in DV format (original videos were M2t).
    What is the optimal setting for export (and possibly for the sequence settings too) for the best quality and then smallest size?
    If my input is M2T files - is the best settings to work in Premiere is DV 1 for Pal?
    I always use Progressive Interlace - is that required or is the default of Lower field OK as well (I am not sure exactly what is the impact of using just one field, but from previous versions of Premiere Progressive always improved the video image)?
    Is the frame rate of Pal as 25 FPS must be adhered in the sequence setting and export to avoid re-rendering?
    As for the Export side:
    Is using the DV Pal is best for quality without going uncompressed?
    Is starting with 16GB of DV as m2T and ending with 20GB of DV reasonable?
    Is the method of exporting to DV and then compressing it using a 3rd party is the best way going about the creation of the movie and then compressing it for distribution?
    What is the the recommended tool for compressing - and with which format?
    The end result is meant to be consumed as an AVI on people's desktop. Not on mobiles or YouTube or DVD.
    On BitTorrent I see many files that are in HD but have an amazingly small size of less 1 GB - what do these guys use to achieve such small sizes yet amazing quality?
    What is the best tool and codec to achieve a compression based on a file size?
    Is DivX better than XVid? And is "Multipass nth pass" is the way to configure the DivX for best results?
    I really feel we lack any guidance on these aspects and a huge of time is wasted every time I get to this stage when it should all be pretty standrad for me.
    I know I am asking a number of question but if someone is able to jot down the basics of the tool, codec and settings to achieve best quality (regardless of the time it takes to get to it) - I'd be very grateful!
    Merry Xmas and a Happy New year to all,
    Eroka00

    I find your post somewhat confusing.
    These m2t are they converted?
    Run a file that you are using in Prmeiere through Media Info and post a screendump.
    http://mediainfo.sourceforge.net/nl
    What is the endproduct going to be? YouTube, DVD, media player or .....

  • HT4110 What is the best battery setting for the MacBook Pro 13 Retina display?

    I want to know the best setting for the battery for the MacBook Pro 13 Retina display.

    To add just a little
    Keep it plugged in when near a socket so you keep the charging cycles down on your LiPo (lithium polymer) cells / battery, but not plugged in all the time. When not being used for several hours, turn it off.
    And best "tip" is if its near a socket,...plug it in as long as you can (especially at home) since cycle count on the battery are the "miles that wear out the tires (battery)", however again, not plugged in all or most of the time.
    http://www.apple.com/batteries/notebooks.html
    "Apple does not recommend leaving your portable plugged in all the time."
    General rule to remember of Lithium batteries is:
    Never drain them LOW  & dont always/often store them HIGH
    While cycle count is commonly seen to be the “miles” on your Lithium Ion pack cell in your Macbook, which they are, this distinction is not a fine line at all, and it is a big misconception to “count charge cycles”
    *A person who has, for example, 300 charge cycles on their battery and is recharging at say 50-60% remaining of a 100% charge has better battery usage and care than another person who has 300 charge cycles at say 15% remaining on a 100% charge. 
    DoD (depth of discharge) is far more important on the wear and tear on your Macbook battery than any mere charge cycle count.  *There is no set “mile” or wear from a charge cycle in general OR in specific.    As such, contrary to popular conception, counting cycles is not conclusive whatsoever, rather the amount of deep DoD on an averaged scale of its use and charging conditions.
                              (as a very rough analogy would be 20,000 hard miles put on a car vs. 80,000 good miles being something similar)
    *Contrary to some myths out there, there is protection circuitry in your Macbook and therefore you cannot overcharge it when plugged in and already fully charged
    *However if you don’t plan on using it for a few hours, turn it OFF (plugged in or otherwise) ..*You don’t want your Macbook both always plugged in AND in sleep mode       (When portable devices are charging and in the on or sleep position, the current that is drawn through the device is called the parasitic load and will alter the dynamics of charge cycle. Battery manufacturers advise against parasitic loading because it induces mini-cycles.)
    Keeping batteries connected to a charger ensures that periodic "top-ups" do very minor but continuous damage to individual cells, hence Apples recommendation above:   “Apple does not recommend leaving your portable plugged in all the time”, …this is because “Li-ion degrades fastest at high state-of-charge”.
                        This is also the same reason new Apple notebooks are packaged with 50% charges and not 100%.
    LiPo (lithium polymer, same as in your Macbook) batteries do not need conditioning. However...
    A lot of battery experts call the use of Lithium cells the "80% Rule" ...meaning use 80% of the charge or so, then recharge them for longer overall life.
    Never let your Macbook go into shutdown and safe mode from loss of power, you can corrupt files that way, and the batteries do not like it.
    The only quantified abuse seen to Lithium cells are instances when often the cells are repeatedly drained very low…. key word being "often"
    Contrary to what some might say, Lithium batteries have an "ideal" break in period. First ten cycles or so, don't discharge down past 40% of the battery's capacity. Same way you don’t take a new car out and speed and rev the engine hard first 100 or so miles.
    Proper treatment is still important. Just because LiPo batteries don’t need conditioning in general, does NOT mean they dont have an ideal use / recharge environment. Anything can be abused even if it doesn’t need conditioning.
    From Apple on batteries:
    http://support.apple.com/kb/HT1446
    http://www.apple.com/batteries/
    Storing your MacBook
    If you are going to store your MacBook away for an extended period of time, keep it in a cool location (room temperature roughly 22° C or about 72° F). Make certain you have at least a 50% charge on the internal battery of your Macbook if you plan on storing it away for a few months; recharge your battery to 50% or so every six months roughly if being stored away. If you live in a humid environment, keep your Macbook stored in its zippered case to prevent infiltration of humidity on the internals of your Macbook which could lead to corrosion.
    Considerations:
    Your battery is subject to chemical aging even if not in use. A Lithium battery is aging as soon as its made, regardless.
    In a perfect (although impractical) situation, your lithium battery is best idealized swinging back and forth between 20 and 85% SOC (state of charge) roughly.
    Further still how you discharge the battery is far more important than how it is either charged or stored short term, and more important long term that cycle counts.
    Ultimately counting charge cycles is of little importance.  Abuse in discharging (foremost), charging, and storing the battery and how it affects battery chemistry is important and not the ‘odometer’ reading, or cycle counts on the battery. 
    Everything boils down to battery chemistry long term, and not an arbitrary number, or cycle count.
    Keep your macbook plugged in when near a socket since in the near end of long-term life, this is beneficial to the battery.
    Peace

  • Best Capture Setting for MiniDV

    Does anyone have any suggestions on the best capture setting in FCP 6 for MiniDV tape (NTSC not PAL). Can I capture it with the Pro Res setting or should I capture it in another setting and then edit with the sequence setting set to Pro Res?

    Capture and edit the material in its native format. DV-NTSC has it's own special Easy Preset. Select it and have at it.
    You gain nothing except huge file sizes when converting DV into ProRes.
    x

  • What is the best proejct setting for editing h.264 video?

    I have captured hours of VHS footage via an Elgato Video Capture device for Mac.   Captured video is in H.264 format.
    Trying to edit the video in Adobe Premiere Elements 10, but it is being very fussy.   Takes a long time to import media.  Once in and a few cuts are made, timeline drags and freezes repeatedly.   This was with a setting for HDV 720p 30.  
    Is my problem with the project setting?  I hope so.  But I also hope I can figure out what the proper setting should be.   Any thoughts?
    Footage is decades old.  Not the best quality, of course.  I do want the final project to look as good as possible and be in Widescreen for uploading to Youtube.

    Here are the propertites of the captured video:
    Format                           : MPEG-4
    Codec ID                         : M4V
    File size                        : 1.37 GiB
    Duration                         : 2h 1mn
    Overall bit rate                 : 1 613 Kbps
    Movie name                       :
    Recorded date                    : 2013-08-22
    Encoded date                     : UTC 2013-08-22 13:15:21
    Tagged date                      : UTC 2013-09-01 07:00:53
    Writing library                  : Apple QuickTime
    Cover                            : Yes
    stik                             : 0
    tvnn                             : S-Video Input
    iTunMOVI                         : <?xml version="1.0" encoding="UTF-8"?> / <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> / <plist version="1.0"> / <dict> /     <key>asset-info</key> /     <dict> /         <key>file-size</key> /         <integer>1467486295</integer> /         <key>flavor</key> /         <string>4:640x480</string> /         <key>high-definition</key> /         <false/> /         <key>screen-format</key> /         <string>standard</string> /         <key>soundtrack</key> /         <string>LC</string> /     </dict> /     <key>cast</key> /     <array/> /     <key>codirectors</key> /     <array/> /     <key>copy-warning</key> /     <string></string> /     <key>directors</key> /     <array/> /     <key>producers</key> /     <array/> /     <key>screenwriters</key> /     <array/> /     <key>studio</key> /     <string></string> / </dict> / </plist>
    Video
    ID                               : 1
    Format                           : AVC
    Format/Info                      : Advanced Video Codec
    Format profile                   : [email protected]
    Format settings, CABAC           : No
    Format settings, ReFrames        : 3 frames
    Codec ID                         : avc1
    Codec ID/Info                    : Advanced Video Coding
    Duration                         : 2h 1mn
    Bit rate mode                    : Variable
    Bit rate                         : 1 499 Kbps
    Width                            : 640 pixels
    Height                           : 480 pixels
    Display aspect ratio             : 4:3
    Frame rate mode                  : Constant
    Frame rate                       : 29.970 fps
    Color space                      : YUV
    Chroma subsampling               : 4:2:0
    Bit depth                        : 8 bits
    Scan type                        : Progressive
    Bits/(Pixel*Frame)               : 0.163
    Stream size                      : 1.27 GiB (93%)
    Language                         : English
    Encoded date                     : UTC 2013-08-22 13:15:21
    Tagged date                      : UTC 2013-08-22 13:15:21
    Audio
    ID                               : 2
    Format                           : AAC
    Format/Info                      : Advanced Audio Codec
    Format profile                   : LC
    Codec ID                         : 40
    Duration                         : 2h 1mn
    Bit rate mode                    : Constant
    Bit rate                         : 110 Kbps
    Nominal bit rate                 : 128 Kbps
    Channel(s)                       : 2 channels
    Channel positions                : Front: L R
    Sampling rate                    : 48.0 KHz
    Compression mode                 : Lossy
    Stream size                      : 95.6 MiB (7%)
    Language                         : English
    Encoded date                     : UTC 2013-08-22 13:15:21
    Tagged date                      : UTC 2013-08-22 13:15:21

  • Best EQ setting for new Earpods?

    What is the best EQ settings for the new Earpods?

    I have my EQ set to jazz, and the results are remarkably better than anything previously made by Apple!!  I think they've done a great job with these new EarPods. I also find them to be much more comfortable.

  • Is there a way to automatically change tabs with different times set for each tab?

    I found a few add-ons that will automatically change tabs based on a configurable time. But all the tabs use the same time setting. What I need is the ability to have tabs displayed for different amounts of time. Ex, Tab 1 for 30 seconds, Tab 2 for 10 seconds, Tab 3 and 4 for 5 seconds. Ideally, I will have the ability to modify these settings as the amount of tabs and the content will change a couple times a week.
    Currently I'm using Tab Slideshow with each tab displayed for 15 seconds. But it sounds like Tab Rotate and Auto Toggle Tabs essentially do the same. If there is already a solution that would be great but if not is there someone available for hire to help modify one of the existing add-ons? Thank you in advance for your time.
    John

    Currently Firefox don't have any options like that.
    You can ask the Addon developers
    *http://addons.mozilla.org/

  • Iterate DB using DBcursor- get with DB_DBT_USERMEM flag set for DBT

    Have BDB running in TDS mode. Want to iterate over a complete database using a DBcursor from start to end. Set the DB_DBT_USERMEM flag on the DBT structure with data pointing to a fixed sized user allocated memory block to hold the contents of a single record read. Currently cursor-get fails with DB_BUFFER_SMALL. I assume that this is because cursor->get retrieves more than one record.
    Is it possible to iterate over the DB using the said cursor while allocating user-memory for only one (1) database record? Each call to cursor->get with DB_NEXT / DB_PREV / DB_FIRST /DB_LAST etc would update the single record entry.

    Hi Kedar,
    No, DBcursor->get() retrieves multiple key/data items if you're using the DB_MULTIPLE or DB_MULTIPLE_KEY flags. See "Bulk Retrieval":
    [http://www.oracle.com/technology/documentation/berkeley-db/db/programmer_reference/am_misc_bulk.html#am_misc_bulk_get]
    You only want to retrieve a single record per call, hence are not using the aforementioned flags. In this case the DB_BUFFER_SMALL error indicates that the length of the requested/retrieved item is larger than that specified for the DBT via its "ulen" field.
    [http://www.oracle.com/technology/documentation/berkeley-db/db/api_reference/C/dbt.html#dbt_DB_DBT_USERMEM]
    If you want to iterate over all the records in the database (including duplicates, if the database is configured to support them) you should use the DB_NEXT flag.
    Note than when the DB_BUFFER_SMALL error is returned the "size" field of the DBT is set to the the length needed for the requested item; you can inspect that value to decide how to size your supplied buffer (or you may know in advance the size of the data items in the database).
    Here is an excerpt from the example code in "Retrieving records with a cursor" with the necessary adjustments for the data DBT:
    [http://www.oracle.com/technology/documentation/berkeley-db/db/programmer_reference/am_cursor.html#am_curget]
         DB *dbp;
         DBC *dbcp;
         DBT key, data;
         int close_db, close_dbc, ret;
         /* Acquire a cursor for the database. */
         if ((ret = dbp->cursor(dbp, NULL, &dbcp, 0)) != 0) {
              dbp->err(dbp, ret, "DB->cursor");
              goto err;
         close_dbc = 1;
         /* Initialize the key/data return pair. */
         memset(&key, 0, sizeof(key));
         memset(&data, 0, sizeof(data));
         /* Retrieve data item in user suplied buffer. */
    #define BUFFER_LENGTH 1024
         if ((data.data = malloc(BUFFER_LENGTH)) == NULL)
              return (errno);
         data.ulen = BUFFER_LENGTH;
         data.flags = DB_DBT_USERMEM;
         /* You can supply your own buffer for the key as well. */
         /* Iterate through the database. */
         while ((ret = dbcp->c_get(dbcp, &key, &data, DB_NEXT)) == 0)
              /* Operate on the retrieved items. */
         if (ret != DB_NOTFOUND) {
              dbp->err(dbp, ret, "DBcursor->get");
              goto err;
    err:
         // ...Regards,
    Andrei

Maybe you are looking for