mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-24 17:37:30 +09:00
[NSS] ported mozilla upstream changes:
- Bug 1552254 internal_error alert on Certificate Request with sha1+ecdsa in TLS 1.3 (be6a9782) - Bug 1753535 - Remove obsolete stateEnd check in SEC_ASN1DecoderUpdate. r=rrelyea (800111fa) - Bug 1756271 - Remove token member from NSSSlot struct. r=rrelyea (55052f78) - Bug 1396616 - Update nssUTF8_Length to RFC 3629 and fix buffer overrun. r=nss-reviewers,jschanck (2f2c8564) - Bug 1755264 - TLS 1.3 Illegal legacy_version handling/alerts. r=djackson (7d931c59) - Bug 1751305 - Remove expired explicitly distrusted certificates from certdata.txt. r=KathleenWilson (b722e523) - Bug 1751298 - Add Telia Root CA v2 root certificate. r=KathleenWilson (1fcbbd7e) - Bug 1754890 - Add two D-TRUST 2020 root certificates. r=KathleenWilson (f63fb86d)
This commit is contained in:
parent
f155978c51
commit
3336114a36
37 changed files with 1556 additions and 671 deletions
|
|
@ -1100,6 +1100,10 @@ struct sslSocketStr {
|
|||
|
||||
/* Anti-replay for TLS 1.3 0-RTT. */
|
||||
SSLAntiReplayContext *antiReplay;
|
||||
|
||||
/* peer data passed in during getClientAuthData */
|
||||
const SSLSignatureScheme *peerSignatureSchemes;
|
||||
unsigned int peerSignatureSchemeCount;
|
||||
};
|
||||
|
||||
struct sslSelfEncryptKeysStr {
|
||||
|
|
@ -1723,6 +1727,8 @@ PRBool ssl3_CipherSuiteAllowedForVersionRange(ssl3CipherSuite cipherSuite,
|
|||
|
||||
SECStatus ssl3_SelectServerCert(sslSocket *ss);
|
||||
SECStatus ssl_PrivateKeySupportsRsaPss(SECKEYPrivateKey *privKey,
|
||||
CERTCertificate *cert,
|
||||
void *pwArg,
|
||||
PRBool *supportsRsaPss);
|
||||
SECStatus ssl_PickSignatureScheme(sslSocket *ss,
|
||||
CERTCertificate *cert,
|
||||
|
|
@ -1730,7 +1736,14 @@ SECStatus ssl_PickSignatureScheme(sslSocket *ss,
|
|||
SECKEYPrivateKey *privKey,
|
||||
const SSLSignatureScheme *peerSchemes,
|
||||
unsigned int peerSchemeCount,
|
||||
PRBool requireSha1);
|
||||
PRBool requireSha1,
|
||||
SSLSignatureScheme *schemPtr);
|
||||
SECStatus ssl_PickClientSignatureScheme(sslSocket *ss,
|
||||
CERTCertificate *clientCertificate,
|
||||
SECKEYPrivateKey *privKey,
|
||||
const SSLSignatureScheme *schemes,
|
||||
unsigned int numSchemes,
|
||||
SSLSignatureScheme *schemePtr);
|
||||
SECOidTag ssl3_HashTypeToOID(SSLHashType hashType);
|
||||
SSLHashType ssl_SignatureSchemeToHashType(SSLSignatureScheme scheme);
|
||||
SSLAuthType ssl_SignatureSchemeToAuthType(SSLSignatureScheme scheme);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue