b6c47560ab
- update to NSS 3.55 Notable changes * P384 and P521 elliptic curve implementations are replaced with verifiable implementations from Fiat-Crypto [0] and ECCKiila [1]. * PK11_FindCertInSlot is added. With this function, a given slot can be queried with a DER-Encoded certificate, providing performance and usability improvements over other mechanisms. (bmo#1649633) * DTLS 1.3 implementation is updated to draft-38. (bmo#1647752) Relevant Bugfixes * bmo#1631583 (CVE-2020-6829, CVE-2020-12400) - Replace P384 and P521 with new, verifiable implementations from Fiat-Crypto and ECCKiila. * bmo#1649487 - Move overzealous assertion in VFY_EndWithSignature. * bmo#1631573 (CVE-2020-12401) - Remove unnecessary scalar padding. * bmo#1636771 (CVE-2020-12403) - Explicitly disable multi-part ChaCha20 (which was not functioning correctly) and more strictly enforce tag length. * bmo#1649648 - Don't memcpy zero bytes (sanitizer fix). * bmo#1649316 - Don't memcpy zero bytes (sanitizer fix). * bmo#1649322 - Don't memcpy zero bytes (sanitizer fix). * bmo#1653202 - Fix initialization bug in blapitest when compiled with NSS_DISABLE_DEPRECATED_SEED. * bmo#1646594 - Fix AVX2 detection in makefile builds. * bmo#1649633 - Add PK11_FindCertInSlot to search a given slot for a DER-encoded certificate. * bmo#1651520 - Fix slotLock race in NSC_GetTokenInfo. * bmo#1647752 - Update DTLS 1.3 implementation to draft-38. * bmo#1649190 - Run cipher, sdr, and ocsp tests under standard test cycle in CI. * bmo#1649226 - Add Wycheproof ECDSA tests. * bmo#1637222 - Consistently enforce IV requirements for DES and 3DES. * bmo#1067214 - Enforce minimum PKCS#1 v1.5 padding length in OBS-URL: https://build.opensuse.org/request/show/829609 OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/mozilla-nss?expand=0&rev=161 |
||
---|---|---|
.gitattributes | ||
.gitignore | ||
add-relro-linker-option.patch | ||
baselibs.conf | ||
bmo-1400603.patch | ||
cert9.db | ||
key4.db | ||
malloc.patch | ||
mozilla-nss-rpmlintrc | ||
mozilla-nss.changes | ||
mozilla-nss.spec | ||
nss-3.55.tar.gz | ||
nss-config.in | ||
nss-fips-aes-keywrap-post.patch | ||
nss-fips-approved-crypto-non-ec.patch | ||
nss-fips-cavs-dsa-fixes.patch | ||
nss-fips-cavs-general.patch | ||
nss-fips-cavs-kas-ecc.patch | ||
nss-fips-cavs-kas-ffc.patch | ||
nss-fips-cavs-keywrap.patch | ||
nss-fips-cavs-rsa-fixes.patch | ||
nss-fips-combined-hash-sign-dsa-ecdsa.patch | ||
nss-fips-constructor-self-tests.patch | ||
nss-fips-detect-fips-mode-fixes.patch | ||
nss-fips-dsa-kat.patch | ||
nss-fips-gcm-ctr.patch | ||
nss-fips-pairwise-consistency-check.patch | ||
nss-fips-rsa-keygen-strictness.patch | ||
nss-fips-tls-allow-md5-prf.patch | ||
nss-fips-use-getrandom.patch | ||
nss-fips-use-strong-random-pool.patch | ||
nss-fips-zeroization.patch | ||
nss-fix-dh-pkcs-derive-inverted-logic.patch | ||
nss-no-rpath.patch | ||
nss-opt.patch | ||
nss-sqlitename.patch | ||
nss.pc.in | ||
pkcs11.txt | ||
ppc-old-abi-v3.patch | ||
setup-nsssysinit.sh | ||
system-nspr.patch |