mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-10-10 01:07:31 +09:00
nss: update to 3.44.1, with vc2013 fix and gyp fix
This commit is contained in:
parent
a2ef5fcde7
commit
d4b834111b
553 changed files with 1515569 additions and 1130 deletions
|
|
@ -19,10 +19,10 @@
|
|||
* The format of the version string should be
|
||||
* "<major version>.<minor version>[.<patch level>[.<build number>]][ <Beta>]"
|
||||
*/
|
||||
#define NSSUTIL_VERSION "3.43"
|
||||
#define NSSUTIL_VERSION "3.44.1"
|
||||
#define NSSUTIL_VMAJOR 3
|
||||
#define NSSUTIL_VMINOR 43
|
||||
#define NSSUTIL_VPATCH 0
|
||||
#define NSSUTIL_VMINOR 44
|
||||
#define NSSUTIL_VPATCH 1
|
||||
#define NSSUTIL_VBUILD 0
|
||||
#define NSSUTIL_BETA PR_FALSE
|
||||
|
||||
|
|
|
|||
|
|
@ -230,6 +230,16 @@
|
|||
#define CKM_NSS_PKCS12_PBE_SHA384_HMAC_KEY_GEN (CKM_NSS + 31)
|
||||
#define CKM_NSS_PKCS12_PBE_SHA512_HMAC_KEY_GEN (CKM_NSS + 32)
|
||||
|
||||
#define CKM_NSS_CHACHA20_CTR (CKM_NSS + 33)
|
||||
|
||||
/* IKE mechanism (to be proposed to PKCS #11 */
|
||||
#define CKM_NSS_IKE_PRF_PLUS_DERIVE (CKM_NSS + 34)
|
||||
#define CKM_NSS_IKE_PRF_DERIVE (CKM_NSS + 35)
|
||||
#define CKM_NSS_IKE1_PRF_DERIVE (CKM_NSS + 36)
|
||||
#define CKM_NSS_IKE1_APP_B_PRF_DERIVE (CKM_NSS + 37)
|
||||
|
||||
#define CKM_NSS_PUB_FROM_PRIV (CKM_NSS + 40)
|
||||
|
||||
/*
|
||||
* HISTORICAL:
|
||||
* Do not attempt to use these. They are only used by NETSCAPE's internal
|
||||
|
|
@ -341,6 +351,72 @@ typedef struct CK_NSS_HKDFParams {
|
|||
CK_ULONG ulInfoLen;
|
||||
} CK_NSS_HKDFParams;
|
||||
|
||||
/*
|
||||
* CK_NSS_IKE_PRF_PLUS_PARAMS is a structure that provides the parameters to
|
||||
* the CKM_NSS_IKE_PRF_PLUS_DERIVE mechanism.
|
||||
* The fields of the structure have the following meanings:
|
||||
* prfMechanism underlying MAC mechanism used to generate the prf.
|
||||
* bHasSeedKey hSeed key is present.
|
||||
* hSeedKey optional seed from key
|
||||
* pSeedData optional seed from data.
|
||||
* ulSeedDataLen length of optional seed data.
|
||||
* If no seed data is present this value is NULL.
|
||||
*/
|
||||
typedef struct CK_NSS_IKE_PRF_PLUS_DERIVE_PARAMS {
|
||||
CK_MECHANISM_TYPE prfMechanism;
|
||||
CK_BBOOL bHasSeedKey;
|
||||
CK_OBJECT_HANDLE hSeedKey;
|
||||
CK_BYTE_PTR pSeedData;
|
||||
CK_ULONG ulSeedDataLen;
|
||||
} CK_NSS_IKE_PRF_PLUS_DERIVE_PARAMS;
|
||||
|
||||
/* CK_NSS_IKE_PRF_DERIVE_PARAMS is a structure that provides the parameters to
|
||||
* the CKM_NSS_IKE_PRF_DERIVE mechanism.
|
||||
*
|
||||
* The fields of the structure have the following meanings:
|
||||
* prfMechanism underlying MAC mechanism used to generate the prf.
|
||||
* bRekey hNewKey is present.
|
||||
* pNi Ni value
|
||||
* ulNiLen length of Ni
|
||||
* pNr Nr value
|
||||
* ulNrLen length of Nr
|
||||
* hNewKey New key value to drive the rekey.
|
||||
*/
|
||||
typedef struct CK_NSS_IKE_PRF_DERIVE_PARAMS {
|
||||
CK_MECHANISM_TYPE prfMechanism;
|
||||
CK_BBOOL bDataAsKey;
|
||||
CK_BBOOL bRekey;
|
||||
CK_BYTE_PTR pNi;
|
||||
CK_ULONG ulNiLen;
|
||||
CK_BYTE_PTR pNr;
|
||||
CK_ULONG ulNrLen;
|
||||
CK_OBJECT_HANDLE hNewKey;
|
||||
} CK_NSS_IKE_PRF_DERIVE_PARAMS;
|
||||
|
||||
/* CK_NSS_IKE1_PRF_DERIVE_PARAMS is a structure that provides the parameters
|
||||
* to the CKM_NSS_IKE_PRF_DERIVE mechanism.
|
||||
*
|
||||
* The fields of the structure have the following meanings:
|
||||
* prfMechanism underlying MAC mechanism used to generate the prf.
|
||||
* bRekey hNewKey is present.
|
||||
* pCKYi CKYi value
|
||||
* ulCKYiLen length of CKYi
|
||||
* pCKYr CKYr value
|
||||
* ulCKYrLen length of CKYr
|
||||
* hNewKey New key value to drive the rekey.
|
||||
*/
|
||||
typedef struct CK_NSS_IKE1_PRF_DERIVE_PARAMS {
|
||||
CK_MECHANISM_TYPE prfMechanism;
|
||||
CK_BBOOL bHasPrevKey;
|
||||
CK_OBJECT_HANDLE hKeygxy;
|
||||
CK_OBJECT_HANDLE hPrevKey;
|
||||
CK_BYTE_PTR pCKYi;
|
||||
CK_ULONG ulCKYiLen;
|
||||
CK_BYTE_PTR pCKYr;
|
||||
CK_ULONG ulCKYrLen;
|
||||
CK_BYTE keyNumber;
|
||||
} CK_NSS_IKE1_PRF_DERIVE_PARAMS;
|
||||
|
||||
/*
|
||||
* Parameter for the TLS extended master secret key derivation mechanisms:
|
||||
*
|
||||
|
|
|
|||
|
|
@ -882,6 +882,8 @@ typedef CK_ULONG CK_MECHANISM_TYPE;
|
|||
#define CKM_AES_GCM 0x00001087
|
||||
#define CKM_AES_CCM 0x00001088
|
||||
#define CKM_AES_CTS 0x00001089
|
||||
#define CKM_AES_XCBC_MAC 0x0000108C
|
||||
#define CKM_AES_XCBC_MAC_96 0x0000108D
|
||||
|
||||
/* BlowFish and TwoFish are new for v2.20 */
|
||||
#define CKM_BLOWFISH_KEY_GEN 0x00001090
|
||||
|
|
|
|||
|
|
@ -757,6 +757,13 @@ DecodeItem(void* dest,
|
|||
}
|
||||
|
||||
case SEC_ASN1_BIT_STRING: {
|
||||
/* Can't be 8 or more spare bits, or any spare bits
|
||||
* if there are no octets. */
|
||||
if (temp.data[0] >= 8 || (temp.data[0] > 0 && temp.len == 1)) {
|
||||
PORT_SetError(SEC_ERROR_BAD_DER);
|
||||
rv = SECFailure;
|
||||
break;
|
||||
}
|
||||
/* change the length in the SECItem to be the number
|
||||
of bits */
|
||||
temp.len = (temp.len - 1) * 8 - (temp.data[0] & 0x7);
|
||||
|
|
|
|||
|
|
@ -455,6 +455,11 @@ CONST_OID pkixExtendedKeyUsageServerAuth[] = { PKIX_KEY_USAGE, 1 };
|
|||
CONST_OID pkixExtendedKeyUsageClientAuth[] = { PKIX_KEY_USAGE, 2 };
|
||||
CONST_OID pkixExtendedKeyUsageCodeSign[] = { PKIX_KEY_USAGE, 3 };
|
||||
CONST_OID pkixExtendedKeyUsageEMailProtect[] = { PKIX_KEY_USAGE, 4 };
|
||||
/* IPsecEnd, IPsecTunnel, and IPsecUser are deprecated, but still in use
|
||||
* (see RFC4945) */
|
||||
CONST_OID pkixExtendedKeyUsageIPsecEnd[] = { PKIX_KEY_USAGE, 5 };
|
||||
CONST_OID pkixExtendedKeyUsageIPsecTunnel[] = { PKIX_KEY_USAGE, 6 };
|
||||
CONST_OID pkixExtendedKeyUsageIPsecUser[] = { PKIX_KEY_USAGE, 7 };
|
||||
CONST_OID pkixExtendedKeyUsageTimeStamp[] = { PKIX_KEY_USAGE, 8 };
|
||||
CONST_OID pkixOCSPResponderExtendedKeyUsage[] = { PKIX_KEY_USAGE, 9 };
|
||||
/* 17 replaces 5 + 6 + 7 (declared obsolete in RFC 4945) */
|
||||
|
|
@ -1778,6 +1783,18 @@ const static SECOidData oids[SEC_OID_TOTAL] = {
|
|||
SEC_OID_IPSEC_IKE_INTERMEDIATE,
|
||||
"IPsec IKE Intermediate",
|
||||
CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
|
||||
OD(pkixExtendedKeyUsageIPsecEnd,
|
||||
SEC_OID_EXT_KEY_USAGE_IPSEC_END,
|
||||
"IPsec Tunnel",
|
||||
CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
|
||||
OD(pkixExtendedKeyUsageIPsecTunnel,
|
||||
SEC_OID_EXT_KEY_USAGE_IPSEC_TUNNEL,
|
||||
"IPsec Tunnel",
|
||||
CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
|
||||
OD(pkixExtendedKeyUsageIPsecUser,
|
||||
SEC_OID_EXT_KEY_USAGE_IPSEC_USER,
|
||||
"IPsec User",
|
||||
CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
|
||||
};
|
||||
|
||||
/* PRIVATE EXTENDED SECOID Table
|
||||
|
|
|
|||
|
|
@ -498,6 +498,9 @@ typedef enum {
|
|||
SEC_OID_EXT_KEY_USAGE_IPSEC_IKE = 358,
|
||||
SEC_OID_IPSEC_IKE_END = 359,
|
||||
SEC_OID_IPSEC_IKE_INTERMEDIATE = 360,
|
||||
SEC_OID_EXT_KEY_USAGE_IPSEC_END = 361,
|
||||
SEC_OID_EXT_KEY_USAGE_IPSEC_TUNNEL = 362,
|
||||
SEC_OID_EXT_KEY_USAGE_IPSEC_USER = 363,
|
||||
|
||||
SEC_OID_TOTAL
|
||||
} SECOidTag;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue