Network Security Services
Go to file
Bob Relyea c9c633332d Resolves: rhbz#2008320
Rebase to NSS 3.71: (changes since NSS 3.67)

    Network Security Services (NSS) 3.71 was released on 30 September 2021.

    The HG tag is NSS_3_71_RTM. This version of NSS requires NSPR 4.32 or newer.

    NSS 3.71 source distributions are available on ftp.mozilla.org for secure HTTPS download: <https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_71_RTM/src/>

    Changes:
    - Bug 1717716 - Set nssckbi version number to 2.52.
    - Bug 1667000 - Respect server requirements of tlsfuzzer/test-tls13-signature-algorithms.py
    - Bug 1373716 - Import of PKCS#12 files with Camellia encryption is not supported
    - Bug 1717707 - Add HARICA Client ECC Root CA 2021.
    - Bug 1717707 - Add HARICA Client RSA Root CA 2021.
    - Bug 1717707 - Add HARICA TLS ECC Root CA 2021.
    - Bug 1717707 - Add HARICA TLS RSA Root CA 2021.
    - Bug 1728394 - Add TunTrust Root CA certificate to NSS.
    -------------------------------------

    Network Security Services (NSS) 3.70 was released on 4 September 2021.

    The HG tag is NSS_3_70_RTM. This version of NSS requires NSPR 4.32 or newer.

    NSS 3.70 source distributions are available on ftp.mozilla.org for secure HTTPS download: <https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_70_RTM/src/>

    Changes:
       - Documentation: release notes for NSS 3.70.
       - Documentation: release notes for NSS 3.69.1.
       - Bug 1726022 - Update test case to verify fix.
       - Bug 1714579 - Explicitly disable downgrade check in TlsConnectStreamTls13.EchOuterWith12Max
       - Bug 1714579 - Explicitly disable downgrade check in TlsConnectTest.DisableFalseStartOnFallback
       - Formatting for lib/util
       - Bug 1681975 - Avoid using a lookup table in nssb64d.
       - Bug 1724629 - Use HW accelerated SHA2 on AArch64 Big Endian.
       - Bug 1714579 - Change default value of enableHelloDowngradeCheck to true.
       - Formatting for gtests/pk11_gtest/pk11_hpke_unittest.cc
       - Bug 1726022 - Cache additional PBE entries.
       - Bug 1709750 - Read HPKE vectors from official JSON.
       - Documentation: update for NSS 3.69 release.

    Network Security Services (NSS) 3.69 was released on 5 August 2021.

    The HG tag is NSS_3_69_RTM. NSS 3.69 requires NSPR 4.32 or newer.

    NSS 3.69 source distributions are available on ftp.mozilla.org for secure HTTPS download: <https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_69_RTM/src/>

    Bugs fixed:
       - Bug 1722613 - Disable DTLS 1.0 and 1.1 by default
       - Bug 1720226 - integrity checks in key4.db not happening on private components with AES_CBC
       - Bug 1720235 - SSL handling of signature algorithms ignores environmental invalid algorithms.
       - Bug 1721476 - sqlite 3.34 changed it's open semantics, causing nss failures.
       - Bug 1720230 - Gtest update changed the gtest reports, losing gtest details in all.sh reports.
       - Bug 1720228 - NSS incorrectly accepting 1536 bit DH primes in FIPS mode
       - Bug 1720232 - SQLite calls could timeout in starvation situations.
       - Bug 1720225 - Coverity/cpp scanner errors found in nss 3.67
       - Bug 1709817 - Import the NSS documentation from MDN in nss/doc.
       - Bug 1720227 - NSS using a tempdir to measure sql performance not active

    Network Security Services (NSS) 3.68 ESR was released on 8 July 2021.

    The HG tag is NSS_3_68_RTM. NSS 3.68 requires NSPR 4.32 or newer.

    NSS 3.68 source distributions are available on ftp.mozilla.org for secure HTTPS download: <https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_68_RTM/src/>

    Bugs fixed:
       -  Bug 1713562 - Fix test leak.
       -  Bug 1717452 - NSS 3.68 should depend on NSPR 4.32.
       -  Bug 1693206 - Implement PKCS8 export of ECDSA keys.
       -  Bug 1712883 - DTLS 1.3 draft-43.
       -  Bug 1655493 - Support SHA2 HW acceleration using Intel SHA Extension.
       -  Bug 1713562 - Validate ECH public names.
       -  Bug 1717610 - Add function to get seconds from epoch from pkix::Time.
2021-10-06 12:09:11 -07:00
tests RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
.gitignore Resolves: rhbz#2008320 2021-10-06 12:09:11 -07:00
STAGE2-nss RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
cert8.db.xml RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
cert9.db.xml RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
gating.yaml Related: rhbz#1972928 2021-08-20 10:57:03 -07:00
iquote.patch RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
key3.db.xml RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
key4.db.xml RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
nspr-config-pc.patch Merged update from upstream sources 2020-10-30 02:57:17 +01:00
nspr-config.xml Merged update from upstream sources 2020-10-30 02:57:17 +01:00
nspr-gcc-atomics.patch Merged update from upstream sources 2020-10-30 02:57:17 +01:00
nss-3.44-kbkdf-coverity.patch Resolves: rhbz#1972928 2021-06-21 10:17:18 -07:00
nss-3.53.1-measure-fix.patch Resolves: rhbz#1972928 2021-06-21 10:17:18 -07:00
nss-3.53.1-revert_rhel8_unsafe_policy_change.patch Merged update from upstream sources 2020-12-12 23:43:09 +00:00
nss-3.66-fix-gtest-parsing.patch Resolves: rhbz#1972928 2021-06-21 10:17:18 -07:00
nss-3.66-no-small-primes.patch Resolves: rhbz#1972928 2021-06-21 10:17:18 -07:00
nss-3.67-fix-coverity-issues.patch Resolves: rhbz#1972928 2021-06-21 10:17:18 -07:00
nss-3.67-fix-private-key-mac.patch Resolves: rhbz#1978038 2021-07-01 15:12:42 -07:00
nss-3.67-fix-ssl-alerts.patch Resolves: rhbz#1933778 2021-07-07 12:06:28 -07:00
nss-3.71-fips-module-name.patch Resolves: rhbz#2008320 2021-10-06 12:09:11 -07:00
nss-3.71-ipv6-fix.patch Resolves: rhbz#2008320 2021-10-06 12:09:11 -07:00
nss-config.in RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
nss-config.xml RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
nss-disable-md5.patch Related: rhbz1926367 2021-04-16 18:13:49 -07:00
nss-dso-ldflags.patch Resolves: rhbz#1926367 2021-04-16 14:12:00 -07:00
nss-fedora-btrf-sql-hack.patch Merged update from upstream sources 2020-12-12 23:43:09 +00:00
nss-no-dbm-man-page.patch Resolves: rhbz#1972928 2021-06-21 10:17:18 -07:00
nss-p11-kit.config RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
nss-signtool-format.patch Resolves: rhbz#1972928 2021-06-21 10:17:18 -07:00
nss-softokn-config.in RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
nss-softokn-dracut-module-setup.sh RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
nss-softokn-dracut.conf RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
nss-softokn.pc.in RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
nss-turn-off-expired-ocsp-cert.patch Merged update from upstream sources 2021-01-22 05:44:38 +00:00
nss-util-config.in RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
nss-util.pc.in RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
nss.pc.in RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
nss.spec Resolves: rhbz#2008320 2021-10-06 12:09:11 -07:00
pkcs11.txt.xml RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
secmod.db.xml RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
setup-nsssysinit.sh RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
setup-nsssysinit.xml RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00
sources Resolves: rhbz#2008320 2021-10-06 12:09:11 -07:00
system-pkcs11.txt RHEL 9.0.0 Alpha bootstrap 2020-10-15 21:19:07 +02:00