Commit Graph

  • d4dfa4d671 Accepting request 991359 from mozilla:Factory Richard Brown 2022-08-01 19:28:11 +00:00
  • e805adc554 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/mozilla-nss?expand=0&rev=391 Wolfgang Rosenauer 2022-07-26 20:46:45 +00:00
  • 36fe40e3e2 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/mozilla-nss?expand=0&rev=390 Wolfgang Rosenauer 2022-07-26 20:46:30 +00:00
  • e6797bdfe9 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/mozilla-nss?expand=0&rev=389 Wolfgang Rosenauer 2022-07-26 20:39:35 +00:00
  • 521f0d9c83 - update to NSS 3.80 * bmo#1774720 - Fix SEC_ERROR_ALGORITHM_MISMATCH entry in SECerrs.h. * bmo#1617956 - Add support for asynchronous client auth hooks. * bmo#1497537 - nss-policy-check: make unknown keyword check optional. * bmo#1765383 - GatherBuffer: Reduced plaintext buffer allocations by allocating it on initialization. Replaced redundant code with assert. Debug builds: Added buffer freeing/allocation for each record. * bmo#1773022 - Mark 3.79 as an ESR release. * bmo#1764206 - Bump nssckbi version number for June. * bmo#1759815 - Remove Hellenic Academic 2011 Root. * bmo#1770267 - Add E-Tugra Roots. * bmo#1768970 - Add Certainly Roots. * bmo#1764392 - Add DigitCert Roots. * bmo#1759794 - Protect SFTKSlot needLogin with slotLock. * bmo#1366464 - Compare signature and signatureAlgorithm fields in legacy certificate verifier. * bmo#1771497 - Uninitialized value in cert_VerifyCertChainOld. * bmo#1771495 - Unchecked return code in sec_DecodeSigAlg. * bmo#1771498 - Uninitialized value in cert_ComputeCertType. * bmo#1760998 - Avoid data race on primary password change. * bmo#1769063 - Replace ppc64 dcbzl intrinisic. * bmo#1771036 - Allow LDFLAGS override in makefile builds. - FIPS patch updates - removed obsolete patches * nss-fips-tests-skip.patch * nss-fips-tls-allow-md5-prf.patch Wolfgang Rosenauer 2022-07-26 19:23:39 +00:00
  • 18a34af8c5 Accepting request 985447 from mozilla:Factory Dominique Leuenberger 2022-06-29 14:00:24 +00:00
  • 8442248c89 - sync with current SLE * latest FIPS changes incl. testsuite fixes (enabled now) nss-fips-180-3-csp-clearing.patch nss-fips-tests-enable-fips.patch nss-fips-tests-skip.patch nss-fips-pbkdf-kat-compliance.patch Wolfgang Rosenauer 2022-06-28 06:46:22 +00:00
  • 397638d222 Accepting request 980155 from mozilla:Factory Dominique Leuenberger 2022-06-01 15:34:21 +00:00
  • 8ce8182c65 - update to NSS 3.78.1 * bmo#1767590 - Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple Wolfgang Rosenauer 2022-05-31 19:26:50 +00:00
  • e00bc7731b Accepting request 974916 from mozilla:Factory Dominique Leuenberger 2022-05-06 16:58:50 +00:00
  • 66ec2a7e6f - update to NSS 3.77 * Bug 1762244 - resolve mpitests build failure on Windows. * bmo#1761779 - Fix link to TLS page on wireshark wiki * bmo#1754890 - Add two D-TRUST 2020 root certificates. * bmo#1751298 - Add Telia Root CA v2 root certificate. * bmo#1751305 - Remove expired explicitly distrusted certificates from certdata.txt. * bmo#1005084 - support specific RSA-PSS parameters in mozilla::pkix * bmo#1753535 - Remove obsolete stateEnd check in SEC_ASN1DecoderUpdate. * bmo#1756271 - Remove token member from NSSSlot struct. * bmo#1602379 - Provide secure variants of mpp_pprime and mpp_make_prime. * bmo#1757279 - Support UTF-8 library path in the module spec string. * bmo#1396616 - Update nssUTF8_Length to RFC 3629 and fix buffer overrun. * bmo#1760827 - Add a CI Target for gcc-11. * bmo#1760828 - Change to makefiles for gcc-4.8. * bmo#1741688 - Update googletest to 1.11.0 * bmo#1759525 - Add SetTls13GreaseEchSize to experimental API. * bmo#1755264 - TLS 1.3 Illegal legacy_version handling/alerts. * bmo#1755904 - Fix calculation of ECH HRR Transcript. * bmo#1758741 - Allow ld path to be set as environment variable. * bmo#1760653 - Ensure we don't read uninitialized memory in ssl gtests. * bmo#1758478 - Fix DataBuffer Move Assignment. * bmo#1552254 - internal_error alert on Certificate Request with sha1+ecdsa in TLS 1.3 * bmo#1755092 - rework signature verification in mozilla::pkix Wolfgang Rosenauer 2022-05-04 12:54:27 +00:00
  • 35ec2e0808 Accepting request 968290 from mozilla:Factory Dominique Leuenberger 2022-04-13 19:03:51 +00:00
  • a55c72c60d Accepting request 968285 from home:gmbr3:Active Wolfgang Rosenauer 2022-04-10 19:12:35 +00:00
  • 779193bc56 Accepting request 967153 from mozilla:Factory Dominique Leuenberger 2022-04-07 22:26:48 +00:00
  • da5d18a546 - update to NSS 3.76.1 NSS 3.76.1 * bmo#1756271 - Remove token member from NSSSlot struct. NSS 3.76 * bmo#1755555 - Hold tokensLock through nssToken_GetSlot calls in nssTrustDomain_GetActiveSlots. * bmo#1370866 - Check return value of PK11Slot_GetNSSToken. * bmo#1747957 - Use Wycheproof JSON for RSASSA-PSS * bmo#1679803 - Add SHA256 fingerprint comments to old certdata.txt entries. * bmo#1753505 - Avoid truncating files in nss-release-helper.py. * bmo#1751157 - Throw illegal_parameter alert for illegal extensions in handshake message. Wolfgang Rosenauer 2022-04-02 18:00:25 +00:00
  • c9b2b09040 Accepting request 965234 from mozilla:Factory Dominique Leuenberger 2022-03-29 16:14:13 +00:00
  • 7f79f8bf08 Accepting request 964904 from home:gmbr3:Active Wolfgang Rosenauer 2022-03-27 19:24:54 +00:00
  • 2985e585ae Accepting request 960367 from mozilla:Factory Dominique Leuenberger 2022-03-11 20:40:49 +00:00
  • c3a6e0b1c1 - update to NSS 3.75 * bmo#1749030 - This patch adds gcc-9 and gcc-10 to the CI. * bmo#1749794 - Make DottedOIDToCode.py compatible with python3. * bmo#1749475 - Avoid undefined shift in SSL_CERT_IS while fuzzing. * bmo#1748386 - Remove redundant key type check. * bmo#1749869 - Update ABI expectations to match ECH changes. * bmo#1748386 - Enable CKM_CHACHA20. * bmo#1747327 - check return on NSS_NoDB_Init and NSS_Shutdown. * bmo#1747310 - real move assignment operator. * bmo#1748245 - Run ECDSA test vectors from bltest as part of the CI tests. * bmo#1743302 - Add ECDSA test vectors to the bltest command line tool. * bmo#1747772 - Allow to build using clang's integrated assembler. * bmo#1321398 - Allow to override python for the build. * bmo#1747317 - test HKDF output rather than input. * bmo#1747316 - Use ASSERT macros to end failed tests early. * bmo#1747310 - move assignment operator for DataBuffer. * bmo#1712879 - Add test cases for ECH compression and unexpected extensions in SH. * bmo#1725938 - Update tests for ECH-13. * bmo#1725938 - Tidy up error handling. * bmo#1728281 - Add tests for ECH HRR Changes. * bmo#1728281 - Server only sends GREASE HRR extension if enabled by preference. * bmo#1725938 - Update generation of the Associated Data for ECH-13. * bmo#1712879 - When ECH is accepted, reject extensions which were only advertised in the Outer Client Hello. * bmo#1712879 - Allow for compressed, non-contiguous, extensions. * bmo#1712879 - Scramble the PSK extension in CHOuter. * bmo#1712647 - Split custom extension handling for ECH. * bmo#1728281 - Add ECH-13 HRR Handling. Wolfgang Rosenauer 2022-03-09 07:41:18 +00:00
  • 2e6634defe Accepting request 948399 from mozilla:Factory Dominique Leuenberger 2022-01-26 20:26:38 +00:00
  • 3adcfa1059 - update to NSS 3.74 * bmo#966856 - mozilla::pkix: support SHA-2 hashes in CertIDs in OCSP responses * bmo#1553612 - Ensure clients offer consistent ciphersuites after HRR * bmo#1721426 - NSS does not properly restrict server keys based on policy * bmo#1733003 - Set nssckbi version number to 2.54 * bmo#1735407 - Replace Google Trust Services LLC (GTS) R4 root certificate * bmo#1735407 - Replace Google Trust Services LLC (GTS) R3 root certificate * bmo#1735407 - Replace Google Trust Services LLC (GTS) R2 root certificate * bmo#1735407 - Replace Google Trust Services LLC (GTS) R1 root certificate * bmo#1735407 - Replace GlobalSign ECC Root CA R4 * bmo#1733560 - Remove Expired Root Certificates - DST Root CA X3 * bmo#1740807 - Remove Expiring Cybertrust Global Root and GlobalSign root certificates * bmo#1741930 - Add renewed Autoridad de Certificacion Firmaprofesional CIF A62634068 root certificate * bmo#1740095 - Add iTrusChina ECC root certificate * bmo#1740095 - Add iTrusChina RSA root certificate * bmo#1738805 - Add ISRG Root X2 root certificate * bmo#1733012 - Add Chunghwa Telecom's HiPKI Root CA - G1 root certificate * bmo#1738028 - Avoid a clang 13 unused variable warning in opt build * bmo#1735028 - Check for missing signedData field * bmo#1737470 - Ensure DER encoded signatures are within size limits - enable key logging option (boo#1195040) Wolfgang Rosenauer 2022-01-24 08:20:50 +00:00
  • 3d5ca710a9 Accepting request 943071 from mozilla:Factory Dominique Leuenberger 2021-12-30 14:55:37 +00:00
  • 8b25050daa Accepting request 943053 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2021-12-29 15:49:46 +00:00
  • 26af6a5d0a Accepting request 935043 from mozilla:Factory Dominique Leuenberger 2021-12-06 22:59:18 +00:00
  • 6d2b744a69 MFSA 2021-51 (bsc#1193170) Wolfgang Rosenauer 2021-12-01 18:36:14 +00:00
  • c2c03087b1 - update to NSS 3.73 * bmo#1735028 - check for missing signedData field. * bmo#1737470 - Ensure DER encoded signatures are within size limits. * bmo#1729550 - NSS needs FiPS 140-3 version indicators. * bmo#1692132 - pkix_CacheCert_Lookup doesn't return cached certs * bmo#1738600 - sunset Coverity from NSS MFSA 2021-51 * CVE-2021-43527 (bmo#1737470) Memory corruption via DER-encoded DSA and RSA-PSS signatures Wolfgang Rosenauer 2021-12-01 17:50:06 +00:00
  • 23f663c23f Accepting request 928802 from mozilla:Factory Dominique Leuenberger 2021-11-08 16:24:02 +00:00
  • 0a23e7af46 - update to NSS 3.71 * bmo#1717716 - Set nssckbi version number to 2.52. * bmo#1667000 - Respect server requirements of tlsfuzzer/test-tls13-signature-algorithms.py * bmo#1373716 - Import of PKCS#12 files with Camellia encryption is not supported * bmo#1717707 - Add HARICA Client ECC Root CA 2021. * bmo#1717707 - Add HARICA Client RSA Root CA 2021. * bmo#1717707 - Add HARICA TLS ECC Root CA 2021. * bmo#1717707 - Add HARICA TLS RSA Root CA 2021. * bmo#1728394 - Add TunTrust Root CA certificate to NSS. - required for Firefox 94 Wolfgang Rosenauer 2021-11-02 13:45:59 +00:00
  • 31c7d379a3 Accepting request 923247 from mozilla:Factory Richard Brown 2021-10-08 20:04:54 +00:00
  • 2f5b9340fb OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/mozilla-nss?expand=0&rev=368 Wolfgang Rosenauer 2021-10-05 13:51:47 +00:00
  • b88778e620 - update to NSS 3.70 * bmo#1726022 - Update test case to verify fix. * bmo#1714579 - Explicitly disable downgrade check in TlsConnectStreamTls13.EchOuterWith12Max * bmo#1714579 - Explicitly disable downgrade check in TlsConnectTest.DisableFalseStartOnFallback * bmo#1681975 - Avoid using a lookup table in nssb64d. * bmo#1724629 - Use HW accelerated SHA2 on AArch64 Big Endian. * bmo#1714579 - Change default value of enableHelloDowngradeCheck to true. * bmo#1726022 - Cache additional PBE entries. * bmo#1709750 - Read HPKE vectors from official JSON. - required for Firefox 93 Wolfgang Rosenauer 2021-10-05 13:51:16 +00:00
  • 5a83f92434 Accepting request 916736 from mozilla:Factory Dominique Leuenberger 2021-09-07 19:13:41 +00:00
  • 4d1c1437e6 - Update to NSS 3.69.1 * bmo#1722613 (Backout) - Disable DTLS 1.0 and 1.1 by default * bmo#1720226 (Backout) - integrity checks in key4.db not happening on private components with AES_CBC NSS 3.69 * bmo#1722613 - Disable DTLS 1.0 and 1.1 by default (backed out again) * bmo#1720226 - integrity checks in key4.db not happening on private components with AES_CBC (backed out again) * bmo#1720235 - SSL handling of signature algorithms ignores environmental invalid algorithms. * bmo#1721476 - sqlite 3.34 changed it's open semantics, causing nss failures. (removed obsolete nss-btrfs-sqlite.patch) * bmo#1720230 - Gtest update changed the gtest reports, losing gtest details in all.sh reports. * bmo#1720228 - NSS incorrectly accepting 1536 bit DH primes in FIPS mode * bmo#1720232 - SQLite calls could timeout in starvation situations. * bmo#1720225 - Coverity/cpp scanner errors found in nss 3.67 * bmo#1709817 - Import the NSS documentation from MDN in nss/doc. * bmo#1720227 - NSS using a tempdir to measure sql performance not active - add nss-fips-stricter-dh.patch - updated existing patches with latest SLE Wolfgang Rosenauer 2021-09-03 11:26:43 +00:00
  • 9c0330962e Accepting request 913334 from mozilla:Factory Dominique Leuenberger 2021-08-24 08:54:04 +00:00
  • 0e62680001 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/mozilla-nss?expand=0&rev=365 Wolfgang Rosenauer 2021-08-20 06:56:19 +00:00
  • 230a70c6b1 - Update nss-fips-constructor-self-tests.patch to fix crashes reported by upstream. This was likely affecting WebRTC calls. Wolfgang Rosenauer 2021-08-18 17:08:41 +00:00
  • e0a827349c Accepting request 910950 from mozilla:Factory Richard Brown 2021-08-16 08:08:42 +00:00
  • 90a37e3936 - added nss-fips-fix-missing-nspr.patch (via SLE sync) Wolfgang Rosenauer 2021-08-09 12:40:49 +00:00
  • f1644f1832 - update to NSS 3.68 * bmo#1713562 - Fix test leak. * bmo#1717452 - NSS 3.68 should depend on NSPR 4.32. * bmo#1693206 - Implement PKCS8 export of ECDSA keys. * bmo#1712883 - DTLS 1.3 draft-43. * bmo#1655493 - Support SHA2 HW acceleration using Intel SHA Extension. * bmo#1713562 - Validate ECH public names. * bmo#1717610 - Add function to get seconds from epoch from pkix::Time. - required by Firefox 91.0 Wolfgang Rosenauer 2021-08-09 12:31:34 +00:00
  • feed344e74 Accepting request 906331 from mozilla:Factory Dominique Leuenberger 2021-07-17 21:36:23 +00:00
  • 009bd2b01c - update to NSS 3.66 * no releasenotes available yet https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.66_release_notes - update to NSS 3.65 * bmo#1709654 - Update for NetBSD configuration. * bmo#1709750 - Disable HPKE test when fuzzing. * bmo#1566124 - Optimize AES-GCM for ppc64le. * bmo#1699021 - Add AES-256-GCM to HPKE. * bmo#1698419 - ECH -10 updates. * bmo#1692930 - Update HPKE to final version. * bmo#1707130 - NSS should use modern algorithms in PKCS#12 files by default. * bmo#1703936 - New coverity/cpp scanner errors. * bmo#1697303 - NSS needs to update it's csp clearing to FIPS 180-3 standards. * bmo#1702663 - Need to support RSA PSS with Hashing PKCS #11 Mechanisms. * bmo#1705119 - Deadlock when using GCM and non-thread safe tokens. - refreshed patches - Firefox 90.0 requires NSS 3.66 Wolfgang Rosenauer 2021-07-14 16:20:34 +00:00
  • f3c19e461e Accepting request 895810 from mozilla:Factory Dominique Leuenberger 2021-06-01 08:33:04 +00:00
  • 2607747af9 Accepting request 895809 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2021-05-27 17:36:07 +00:00
  • 926a532f98 Accepting request 886901 from mozilla:Factory Dominique Leuenberger 2021-04-23 15:49:45 +00:00
  • eba5fa49ec - update to NSS 3.63.1 * no upstream release notes for 3.63.1 (yet) Fixed in 3.63 * bmo#1697380 - Make a clang-format run on top of helpful contributions. * bmo#1683520 - ECCKiila P384, change syntax of nested structs initialization to prevent build isses with GCC 4.8. * bmo#1683520 - [lib/freebl/ecl] P-384: allow zero scalars in dual scalar multiplication. * bmo#1683520 - ECCKiila P521, change syntax of nested structs initialization to prevent build isses with GCC 4.8. * bmo#1683520 - [lib/freebl/ecl] P-521: allow zero scalars in dual scalar multiplication. * bmo#1696800 - HACL* update March 2021 - c95ab70fcb2bc21025d8845281bc4bc8987ca683. * bmo#1694214 - tstclnt can't enable middlebox compat mode. * bmo#1694392 - NSS does not work with PKCS #11 modules not supporting profiles. * bmo#1685880 - Minor fix to prevent unused variable on early return. * bmo#1685880 - Fix for the gcc compiler version 7 to support setenv with nss build. * bmo#1693217 - Increase nssckbi.h version number for March 2021 batch of root CA changes, CA list version 2.48. * bmo#1692094 - Set email distrust after to 21-03-01 for Camerfirma's 'Chambers of Commerce' and 'Global Chambersign' roots. * bmo#1618407 - Symantec root certs - Set CKA_NSS_EMAIL_DISTRUST_AFTER. * bmo#1693173 - Add GlobalSign R45, E45, R46, and E46 root certs to NSS. * bmo#1683738 - Add AC RAIZ FNMT-RCM SERVIDORES SEGUROS root cert to NSS. * bmo#1686854 - Remove GeoTrust PCA-G2 and VeriSign Universal root certs from NSS. * bmo#1687822 - Turn off Websites trust bit for the “Staat der Nederlanden Root CA - G3” root cert in NSS. Wolfgang Rosenauer 2021-04-18 07:40:17 +00:00
  • 2fff3f55e1 Accepting request 880741 from mozilla:Factory Richard Brown 2021-04-06 15:29:00 +00:00
  • 2e8ea1e384 - update to NSS 3.62 * bmo#1688374 - Fix parallel build NSS-3.61 with make * bmo#1682044 - pkix_Build_GatherCerts() + pkix_CacheCert_Add() can corrupt "cachedCertTable" * bmo#1690583 - Fix CH padding extension size calculation * bmo#1690421 - Adjust 3.62 ABI report formatting for new libabigail * bmo#1690421 - Install packaged libabigail in docker-builds image * bmo#1689228 - Minor ECH -09 fixes for interop testing, fuzzing * bmo#1674819 - Fixup a51fae403328, enum type may be signed * bmo#1681585 - Add ECH support to selfserv * bmo#1681585 - Update ECH to Draft-09 * bmo#1678398 - Add Export/Import functions for HPKE context * bmo#1678398 - Update HPKE to draft-07 - required for Firefox 87 Wolfgang Rosenauer 2021-03-17 08:44:35 +00:00
  • 36801a3be6 Accepting request 875778 from mozilla:Factory Richard Brown 2021-03-02 11:28:14 +00:00
  • bac7e766cb Accepting request 875772 from home:hellcp:branches:security:idm Wolfgang Rosenauer 2021-02-28 12:47:39 +00:00
  • 5de44ac988 - Mozilla Thunderbird 78.8.0 * various bugfixes MFSA 2021-09 (bsc#1182614) * CVE-2021-23969 (bmo#1542194) Content Security Policy violation report could have contained the destination of a redirect * CVE-2021-23968 (bmo#1687342) Content Security Policy violation report could have contained the destination of a redirect * CVE-2021-23973 (bmo#1690976) MediaError message property could have leaked information about cross-origin resources * CVE-2021-23978 (bmo#786797, bmo#1682928, bmo#1687391, bmo#1687597) Memory safety bugs fixed in Firefox 86 and Firefox ESR 78.8 Wolfgang Rosenauer 2021-02-24 08:07:17 +00:00
  • 3cea36e7ac Accepting request 867003 from mozilla:Factory Dominique Leuenberger 2021-01-29 13:55:23 +00:00
  • 56558e6d23 - update to NSS 3.60.1 Notable changes in NSS 3.60: * TLS 1.3 Encrypted Client Hello (draft-ietf-tls-esni-08) support has been added, replacing the previous ESNI (draft-ietf-tls-esni-01) implementation. See bmo#1654332 for more information. * December 2020 batch of Root CA changes, builtins library updated to version 2.46. See bmo#1678189, bmo#1678166, and bmo#1670769 for more information. - removed obsolete ppc-old-abi-v3.patch Wolfgang Rosenauer 2021-01-26 21:30:37 +00:00
  • 4c45e1b696 Accepting request 859942 from mozilla:Factory Dominique Leuenberger 2021-01-04 18:07:17 +00:00
  • 691fd0a9fa - update to NSS 3.59.1 * bmo#1679290 - Fix potential deadlock with certain third-party PKCS11 modules Wolfgang Rosenauer 2020-12-31 12:04:59 +00:00
  • dee7c844b0 Accepting request 852633 from mozilla:Factory Dominique Leuenberger 2020-12-24 18:39:56 +00:00
  • 87892cd552 Accepting request 851799 from mozilla:Factory Dominique Leuenberger 2020-12-02 12:57:27 +00:00
  • 95bb1123a7 - update to NSS 3.59 Notable changes * Exported two existing functions from libnss: CERT_AddCertToListHeadWithData and CERT_AddCertToListTailWithData Bugfixes * bmo#1607449 - Lock cert->nssCertificate to prevent a potential data race * bmo#1672823 - Add Wycheproof test cases for HMAC, HKDF, and DSA * bmo#1663661 - Guard against NULL token in nssSlot_IsTokenPresent * bmo#1670835 - Support enabling and disabling signatures via Crypto Policy * bmo#1672291 - Resolve libpkix OCSP failures on SHA1 self-signed root certs when SHA1 signatures are disabled. * bmo#1644209 - Fix broken SelectedCipherSuiteReplacer filter to solve some test intermittents * bmo#1672703 - Tolerate the first CCS in TLS 1.3 to fix a regression in our CVE-2020-25648 fix that broke purple-discord (boo#1179382) * bmo#1666891 - Support key wrap/unwrap with RSA-OAEP * bmo#1667989 - Fix gyp linking on Solaris * bmo#1668123 - Export CERT_AddCertToListHeadWithData and CERT_AddCertToListTailWithData from libnss * bmo#1634584 - Set CKA_NSS_SERVER_DISTRUST_AFTER for Trustis FPS Root CA * bmo#1663091 - Remove unnecessary assertions in the streaming ASN.1 decoder that affected decoding certain PKCS8 private keys when using NSS debug builds * bmo#670839 - Use ARM crypto extension for AES, SHA1 and SHA2 on MacOS. Wolfgang Rosenauer 2020-12-01 13:33:23 +00:00
  • 694386f519 Accepting request 849662 from home:lnussel:usrmove Wolfgang Rosenauer 2020-11-30 10:24:31 +00:00
  • b54447fa2a Accepting request 849114 from mozilla:Factory Dominique Leuenberger 2020-11-21 11:39:52 +00:00
  • de30840f35 - update to NSS 3.58 Bugs fixed: * bmo#1641480 (CVE-2020-25648) Tighten CCS handling for middlebox compatibility mode. * bmo#1631890 - Add support for Hybrid Public Key Encryption (draft-irtf-cfrg-hpke) support for TLS Encrypted Client Hello (draft-ietf-tls-esni). * bmo#1657255 - Add CI tests that disable SHA1/SHA2 ARM crypto extensions. * bmo#1668328 - Handle spaces in the Python path name when using gyp on Windows. * bmo#1667153 - Add PK11_ImportDataKey for data object import. * bmo#1665715 - Pass the embedded SCT list extension (if present) to TrustDomain::CheckRevocation instead of the notBefore value. Wolfgang Rosenauer 2020-11-17 13:50:18 +00:00
  • 93b007137a Accepting request 841322 from mozilla:Factory Dominique Leuenberger 2020-10-14 13:38:13 +00:00
  • da00e5afd0 Accepting request 841320 from home:dimstar:Factory Wolfgang Rosenauer 2020-10-12 15:35:14 +00:00
  • d5a2413344 Accepting request 840031 from mozilla:Factory Dominique Leuenberger 2020-10-10 17:00:34 +00:00
  • d97dd3a9da OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/mozilla-nss?expand=0&rev=338 Wolfgang Rosenauer 2020-10-07 09:55:48 +00:00
  • f6aa3fb9fb - update to NSS 3.57 * The following CA certificates were Added: bmo#1663049 - CN=Trustwave Global Certification Authority SHA-256 Fingerprint: 97552015F5DDFC3C8788C006944555408894450084F100867086BC1A2BB58DC8 bmo#1663049 - CN=Trustwave Global ECC P256 Certification Authority SHA-256 Fingerprint: 945BBC825EA554F489D1FD51A73DDF2EA624AC7019A05205225C22A78CCFA8B4 bmo#1663049 - CN=Trustwave Global ECC P384 Certification Authority SHA-256 Fingerprint: 55903859C8C0C3EBB8759ECE4E2557225FF5758BBD38EBD48276601E1BD58097 * The following CA certificates were Removed: bmo#1651211 - CN=EE Certification Centre Root CA SHA-256 Fingerprint: 3E84BA4342908516E77573C0992F0979CA084E4685681FF195CCBA8A229B8A76 bmo#1656077 - O=Government Root Certification Authority; C=TW SHA-256 Fingerprint: 7600295EEFE85B9E1FD624DB76062AAAAE59818A54D2774CD4C0B2C01131E1B3 * Trust settings for the following CA certificates were Modified: bmo#1653092 - CN=OISTE WISeKey Global Root GA CA Websites (server authentication) trust bit removed. * https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes - requires NSPR 4.29 - removed obsolete nss-freebl-fix-aarch64.patch (bmo#1659256) - introduced _constraints due to high memory requirements especially for LTO on Tumbleweed Wolfgang Rosenauer 2020-10-07 08:15:55 +00:00
  • 0321aaf402 Accepting request 837281 from mozilla:Factory Dominique Leuenberger 2020-09-29 16:58:59 +00:00
  • e43a7b9e4b Accepting request 837280 from home:Guillaume_G:branches:mozilla:Factory Wolfgang Rosenauer 2020-09-25 06:58:55 +00:00
  • 626f71eef2 Accepting request 835234 from mozilla:Factory Dominique Leuenberger 2020-09-24 14:11:54 +00:00
  • 50269fd3cd Accepting request 835218 from home:hpjansson:nss-tw Wolfgang Rosenauer 2020-09-17 14:55:31 +00:00
  • cd3540b0de - update to NSS 3.56 Notable changes * bmo#1650702 - Support SHA-1 HW acceleration on ARMv8 * bmo#1656981 - Use MPI comba and mulq optimizations on x86-64 MacOS. * bmo#1654142 - Add CPU feature detection for Intel SHA extension. * bmo#1648822 - Add stricter validation of DH keys in FIPS mode. * bmo#1656986 - Properly detect arm64 during GYP build architecture detection. * bmo#1652729 - Add build flag to disable RC2 and relocate to lib/freebl/deprecated. * bmo#1656429 - Correct RTT estimate used in 0-RTT anti-replay. * bmo#1588941 - Send empty certificate message when scheme selection fails. * bmo#1652032 - Fix failure to build in Windows arm64 makefile cross-compilation. * bmo#1625791 - Fix deadlock issue in nssSlot_IsTokenPresent. * bmo#1653975 - Fix 3.53 regression by setting "all" as the default makefile target. * bmo#1659792 - Fix broken libpkix tests with unexpired PayPal cert. * bmo#1659814 - Fix interop.sh failures with newer tls-interop commit and dependencies. * bmo#1656519 - NSPR dependency updated to 4.28 - do not hard require mozilla-nss-certs-32bit via baselibs (boo#1176206) Wolfgang Rosenauer 2020-09-08 20:23:09 +00:00
  • b6c47560ab Accepting request 829609 from mozilla:Factory Dominique Leuenberger 2020-09-02 23:08:00 +00:00
  • 6364ad3ae6 - update to NSS 3.55 Notable changes * P384 and P521 elliptic curve implementations are replaced with verifiable implementations from Fiat-Crypto [0] and ECCKiila [1]. * PK11_FindCertInSlot is added. With this function, a given slot can be queried with a DER-Encoded certificate, providing performance and usability improvements over other mechanisms. (bmo#1649633) * DTLS 1.3 implementation is updated to draft-38. (bmo#1647752) Relevant Bugfixes * bmo#1631583 (CVE-2020-6829, CVE-2020-12400) - Replace P384 and P521 with new, verifiable implementations from Fiat-Crypto and ECCKiila. * bmo#1649487 - Move overzealous assertion in VFY_EndWithSignature. * bmo#1631573 (CVE-2020-12401) - Remove unnecessary scalar padding. * bmo#1636771 (CVE-2020-12403) - Explicitly disable multi-part ChaCha20 (which was not functioning correctly) and more strictly enforce tag length. * bmo#1649648 - Don't memcpy zero bytes (sanitizer fix). * bmo#1649316 - Don't memcpy zero bytes (sanitizer fix). * bmo#1649322 - Don't memcpy zero bytes (sanitizer fix). * bmo#1653202 - Fix initialization bug in blapitest when compiled with NSS_DISABLE_DEPRECATED_SEED. * bmo#1646594 - Fix AVX2 detection in makefile builds. * bmo#1649633 - Add PK11_FindCertInSlot to search a given slot for a DER-encoded certificate. * bmo#1651520 - Fix slotLock race in NSC_GetTokenInfo. * bmo#1647752 - Update DTLS 1.3 implementation to draft-38. * bmo#1649190 - Run cipher, sdr, and ocsp tests under standard test cycle in CI. * bmo#1649226 - Add Wycheproof ECDSA tests. * bmo#1637222 - Consistently enforce IV requirements for DES and 3DES. * bmo#1067214 - Enforce minimum PKCS#1 v1.5 padding length in Wolfgang Rosenauer 2020-08-22 07:01:08 +00:00
  • 1ce163d005 Accepting request 823327 from mozilla:Factory Dominique Leuenberger 2020-07-30 07:57:44 +00:00
  • 8581fb64fb - update to NSS 3.54 Notable changes * Support for TLS 1.3 external pre-shared keys (bmo#1603042). * Use ARM Cryptography Extension for SHA256, when available (bmo#1528113) * The following CA certificates were Added: bmo#1645186 - certSIGN Root CA G2. bmo#1645174 - e-Szigno Root CA 2017. bmo#1641716 - Microsoft ECC Root Certificate Authority 2017. bmo#1641716 - Microsoft RSA Root Certificate Authority 2017. * The following CA certificates were Removed: bmo#1645199 - AddTrust Class 1 CA Root. bmo#1645199 - AddTrust External CA Root. bmo#1641718 - LuxTrust Global Root 2. bmo#1639987 - Staat der Nederlanden Root CA - G2. bmo#1618402 - Symantec Class 2 Public Primary Certification Authority - G4. bmo#1618402 - Symantec Class 1 Public Primary Certification Authority - G4. bmo#1618402 - VeriSign Class 3 Public Primary Certification Authority - G3. * A number of certificates had their Email trust bit disabled. See bmo#1618402 for a complete list. Bugs fixed * bmo#1528113 - Use ARM Cryptography Extension for SHA256. * bmo#1603042 - Add TLS 1.3 external PSK support. * bmo#1642802 - Add uint128 support for HACL* curve25519 on Windows. * bmo#1645186 - Add "certSIGN Root CA G2" root certificate. * bmo#1645174 - Add Microsec's "e-Szigno Root CA 2017" root certificate. * bmo#1641716 - Add Microsoft's non-EV root certificates. * bmo1621151 - Disable email trust bit for "O=Government Root Certification Authority; C=TW" root. * bmo#1645199 - Remove AddTrust root certificates. Wolfgang Rosenauer 2020-07-23 16:12:42 +00:00
  • 62b6732e56 Accepting request 817441 from mozilla:Factory Dominique Leuenberger 2020-06-30 19:52:57 +00:00
  • 194c062b5d - add FIPS mode patches from SLE stream nss-fips-aes-keywrap-post.patch nss-fips-approved-crypto-non-ec.patch nss-fips-cavs-dsa-fixes.patch nss-fips-cavs-general.patch nss-fips-cavs-kas-ecc.patch nss-fips-cavs-kas-ffc.patch nss-fips-cavs-keywrap.patch nss-fips-cavs-rsa-fixes.patch nss-fips-combined-hash-sign-dsa-ecdsa.patch nss-fips-constructor-self-tests.patch nss-fips-detect-fips-mode-fixes.patch nss-fips-dsa-kat.patch nss-fips-gcm-ctr.patch nss-fips-pairwise-consistency-check.patch nss-fips-rsa-keygen-strictness.patch nss-fips-tls-allow-md5-prf.patch nss-fips-use-getrandom.patch nss-fips-use-strong-random-pool.patch nss-fips-zeroization.patch nss-fix-dh-pkcs-derive-inverted-logic.patch Wolfgang Rosenauer 2020-06-27 21:18:50 +00:00
  • c4ac198bc6 Accepting request 816170 from home:michel_mno:branches:mozilla:Factory Wolfgang Rosenauer 2020-06-23 05:37:44 +00:00
  • 1c02c4f2d6 Accepting request 810949 from mozilla:Factory Dominique Leuenberger 2020-06-05 18:02:24 +00:00
  • 51c5e75fe8 Accepting request 810947 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2020-06-02 20:01:34 +00:00
  • 29468ba107 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/mozilla-nss?expand=0&rev=322 Wolfgang Rosenauer 2020-06-02 10:48:22 +00:00
  • c9da1099a1 - removed obsolete nss-kremlin-ppc64le.patch Wolfgang Rosenauer 2020-05-26 13:56:16 +00:00
  • 6553d00ceb * CVE-2020-12399 - Force a fixed length for DSA exponentiation (bmo#1631576) Wolfgang Rosenauer 2020-05-26 09:14:39 +00:00
  • e33a5800ee - update to NSS 3.52.1 * required for Firefox 77.0 Notable changes * Update NSS to support PKCS#11 v3.0 (bmo#1603628) * Support new PKCS #11 v3.0 Message Interface for AES-GCM and ChaChaPoly (bmo#1623374) * Integrate AVX2 ChaCha20, Poly1305, and ChaCha20Poly1305 from HACL* (bmo#1612493) - Add patch nss-kremlin-ppc64le.patch to fix ppc and s390x builds Wolfgang Rosenauer 2020-05-26 09:12:44 +00:00
  • a00e1cb470 Accepting request 799040 from mozilla:Factory Dominique Leuenberger 2020-05-02 20:14:59 +00:00
  • f615b8c01b Accepting request 798944 from home:marxin:branches:mozilla:Factory Wolfgang Rosenauer 2020-04-29 21:43:25 +00:00
  • ea7949cb9d Accepting request 793077 from mozilla:Factory Dominique Leuenberger 2020-04-15 17:52:12 +00:00
  • 6ea59419f5 Accepting request 793073 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2020-04-11 10:30:25 +00:00
  • 0c74453c3f Accepting request 790238 from mozilla:Factory Dominique Leuenberger 2020-04-04 10:05:24 +00:00
  • 507c7ec45b Accepting request 790234 from home:michel_mno:branches:mozilla:Factory Wolfgang Rosenauer 2020-03-31 15:31:21 +00:00
  • 5c3b101fcb Accepting request 790066 from home:MSirringhaus:branches:mozilla:Factory Wolfgang Rosenauer 2020-03-31 14:28:37 +00:00
  • ab72679b5e - update to NSS 3.51 * Updated DTLS 1.3 implementation to Draft-34. (bmo#1608892) * Correct swapped PKCS11 values of CKM_AES_CMAC and CKM_AES_CMAC_GENERAL (bmo#1611209) * Complete integration of Wycheproof ECDH test cases (bmo#1612259) * Check if PPC __has_include(<sys/auxv.h>) (bmo#1614183) * Fix a compilation error for ‘getFIPSEnv’ "defined but not used" (bmo#1614786) * Send DTLS version numbers in DTLS 1.3 supported_versions extension to avoid an incompatibility. (bmo#1615208) * SECU_ReadDERFromFile calls strstr on a string that isn't guaranteed to be null-terminated (bmo#1538980) * Correct a warning for comparison of integers of different signs: 'int' and 'unsigned long' in security/nss/lib/freebl/ecl/ecp_25519.c:88 (bmo#1561337) * Add test for mp_int clamping (bmo#1609751) * Don't attempt to read the fips_enabled flag on the machine unless NSS was built with FIPS enabled (bmo#1582169) * Fix a null pointer dereference in BLAKE2B_Update (bmo#1431940) * Fix compiler warning in secsign.c (bmo#1617387) * Fix a OpenBSD/arm64 compilation error: unused variable 'getauxval' (bmo#1618400) * Fix a crash on unaligned CMACContext.aes.keySchedule when using AES-NI intrinsics (bmo#1610687) Wolfgang Rosenauer 2020-03-30 13:40:12 +00:00
  • 9b381f8d16 Accepting request 783555 from mozilla:Factory Dominique Leuenberger 2020-03-14 08:54:00 +00:00
  • 1816e8360d OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/mozilla-nss?expand=0&rev=309 Wolfgang Rosenauer 2020-03-03 21:25:27 +00:00
  • 14bbc2e047 - update to NSS 3.50 * Verified primitives from HACL* were updated, bringing performance improvements for several platforms. Note that Intel processors with SSE4 but without AVX are currently unable to use the improved ChaCha20/Poly1305 due to a build issue; such platforms will fall-back to less optimized algorithms. See bmo#1609569 for details * Updated DTLS 1.3 implementation to Draft-30. See bmo#1599514 for details. * Added NIST SP800-108 KBKDF - PKCS#11 implementation. See bmo#1599603 for details. * Several bugfixes and minor changes Wolfgang Rosenauer 2020-03-03 21:21:24 +00:00
  • deaa59ba87 Accepting request 780186 from mozilla:Factory Dominique Leuenberger 2020-02-29 20:20:04 +00:00
  • b1721753f1 Accepting request 779969 from home:fstrba:branches:mozilla:Factory Wolfgang Rosenauer 2020-02-28 09:07:15 +00:00
  • 478511aedc Accepting request 779080 from home:Guillaume_G:branches:openSUSE:Factory:ARM Wolfgang Rosenauer 2020-02-25 13:41:19 +00:00
  • 75fb6f4946 Accepting request 772451 from mozilla:Factory Oliver Kurz 2020-02-14 15:27:50 +00:00
  • 2e89924539 - update to NSS 3.49.2 Fixed bugs: * Fix compilation problems with NEON-specific code in freebl (bmo#1608327) * Fix a taskcluster issue with Python 2 / Python 3 (bmo#1608895) Wolfgang Rosenauer 2020-02-08 16:32:51 +00:00
  • 93fc73f5eb Accepting request 761944 from mozilla:Factory Dominique Leuenberger 2020-01-11 13:37:50 +00:00