Commit graph

102 commits

Author SHA1 Message Date
wuggy
29bfa4fc7f IT LAUNCHES ON OS X 2026-04-05 02:08:42 +01:00
Moonchild
96a9380208 [NSS] Update NSS 2026-03-06 04:32:10 +00:00
roytam1
e5ea29554a Merge remote-tracking branch 'origin/tracking' into custom 2025-08-21 16:07:53 +08:00
Moonchild
fe21538da4 [NSS] Avoid leak in pkcs12 decoder. 2025-08-21 16:07:31 +08:00
roytam1
f5307ea861 nss: update certdata and bump ckbi version to 2.80
- Bug 1974511 - Add SwissSign 2022 Roots to NSS r=jschanck
- Bug 1972391 - Add TrustAsia Dedicated Roots to NSS r=jschanck
- Bug 1961848 - Remove expired Baltimore CyberTrust Root r=jschanck
- Bug 1978677 - remove expired explicitly distrusted DigiNotar lookalike root r=nss-reviewers,jschanck
2025-08-21 15:54:50 +08:00
roytam1
bde8fbbb5f nss: merge changes from upstream UXP 2025-06-28 06:31:32 +08:00
roytam1
cd1840493f nss: update certdata and bump ckbi version to 2.78 2025-06-28 00:41:36 +08:00
roytam1
e72f8a3a81 Merge remote-tracking branch 'origin/tracking' into custom 2025-05-14 14:36:05 +08:00
Brian Smith
e8b3077d4f No Issue - Fixes for building with LLVM 19 included with FreeBSD 13.5. Fix a conflict with libc++ 19 and the old Mozilla (re)alloc macros. LLVM 18+ does not allow std::char_traits<unsigned char> so avoid it. https://bugzilla.mozilla.org/show_bug.cgi?id=1849070 Partial NSS upgrade to replace ByteString with a class. https://bugzilla.mozilla.org/show_bug.cgi?id=1851092 2025-05-14 14:20:07 +08:00
roytam1
5384bb6d14 nss: update builtin certstore and bump ckbi version 2025-04-30 23:07:58 +08:00
roytam1
6792dc4b66 Merge remote-tracking branch 'origin/tracking' into custom 2025-04-30 23:06:47 +08:00
Moonchild
be9a6ed2ac [NSS] Improve locking in nssPKIObject_GetInstances. 2025-04-30 23:03:04 +08:00
roytam1
0a18b05efd nss: update nssckbi to 2.74 2025-02-13 21:22:34 +08:00
roytam1
f7298813f9 Merge remote-tracking branch 'origin/tracking' into custom 2025-02-06 09:30:57 +08:00
Moonchild
dcb76fe0f7 [NSS] Ensure zero-initialization of collectArgs.cert 2025-02-06 09:25:33 +08:00
Moonchild
ecb18ddf57 [NSS] Simplify error handling in get_token_objects_for_cache. 2025-02-06 09:25:01 +08:00
roytam1
e26468c8a2 nss: update nssckbi to 2.72 2024-11-29 21:04:06 +08:00
roytam1
c6517989ab Merge remote-tracking branch 'origin/tracking' into custom 2024-11-29 21:00:51 +08:00
Kai Engert
e825209039 [NSS] Bug 1899402 - Correctly destroy bulkkey in error scenario. r=jschanck
Differential Revision: https://phabricator.services.mozilla.com/D223837

--HG--
extra : rebase_source : d06a6bb8d51bb844c814c5ee682a1b24de3e2e69
2024-11-29 20:55:45 +08:00
roytam1
b794ec0afd nss: update nssckbi to 2.68 2024-06-09 07:15:57 +08:00
roytam1
ab39f724a8 nss: update nssckbi to 2.66 2024-05-26 06:58:33 +08:00
roytam1
35252384aa Merge remote-tracking branch 'origin/tracking' into custom 2024-01-25 12:22:19 +08:00
John Schanck
266b96a53a [NSS] add a defensive check for large ssl_DefSend return values. 2024-01-25 12:13:04 +08:00
roytam1
24413daff9 [NSS] revert "sync with https://github.com/roytam1/NSS/tree/NSS_3_48_UXP_BRANCH", this should fix a crash when browsing 2023-11-17 14:29:07 +08:00
roytam1
4e45ee69e0 [NSS] sync with https://github.com/roytam1/NSS/tree/NSS_3_48_UXP_BRANCH, notably:
- Bug 1665715 - (1/2) revert e8f2720c8254 (bug 1593141) because it's no longer necessary r=jcj (a9bca998)
- Bug 1665715 - (2/2) pass encoded signed certificate timestamp extension (if present) in CheckRevocation r=jcj (429f9ef9)
2023-11-17 11:01:12 +08:00
roytam1
96524cc3c5 nss: update nssckbi to 2.64 2023-11-16 10:15:29 +08:00
roytam1
e7c19e1155 nss: update nssckbi to 2.62 2023-08-24 10:08:25 +08:00
roytam1
16926c542d Merge remote-tracking branch 'origin/tracking' into custom 2023-02-20 12:02:40 +08:00
Moonchild
cdda874cff [NSS] Update NSS to pick up fixes. 2023-02-20 12:01:55 +08:00
roytam1
58af5d4b99 imported changes from mozilla NSS:
- Bug 1794495 - Remove Network Solutions Certificate Authority. r=KathleenWilson (64a28c8d60)
- Bug 1794507 - Remove SwissSign Platinum CA - G2 from NSS. r=KathleenWilson (f2c2308403)
- Bug 1797559 - Remove EC-ACC root cert from NSS. r=KathleenWilson (4f1985c8dd)
- Bug 1799038 - Remove Staat der Nederlanden EV Root CA from NSS. r=KathleenWilson (9151be4c45)
- Bug 1794506 - Set nssckbi version number to 2.60. r=nss-reviewers,bbeurdouche (39fc42e136)
- Bug 1803453 - Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates. r=KathleenWilson (a871902c05)
2022-12-07 13:24:50 +08:00
roytam1
29846d1e4d update NSS builtin certstore to Sep 2022 version from mozilla upstream. 2022-09-19 15:11:02 +08:00
roytam1
1822f2031e Merge remote-tracking branch 'origin/tracking' into custom 2022-07-30 08:49:22 +08:00
Moonchild
10fdf0e1c5 [NSS] Fix uninitialized value in cert_ComputeCertType. 2022-07-30 08:43:45 +08:00
Moonchild
a77cf423c2 [NSS] Avoid potential data race on primary password change. 2022-07-30 08:43:44 +08:00
Moonchild
b9084ea29d [NSS] protect SFTKSlot needLogin with slotLock. 2022-07-30 08:43:44 +08:00
roytam1
206c9dcbbf Merge remote-tracking branch 'origin/tracking' into custom 2022-07-05 17:28:42 +08:00
Moonchild
2706ef696d Update NSS 2022-07-05 17:21:07 +08:00
roytam1
43cfc69b25 imported changes from mozilla NSS:
- Bug 1759794 - protect SFTKSlot needLogin with slotLock. r=rrelyea (1bbd8d8c)
- Bug 1771497 - Uninitialized value in cert_VerifyCertChainOld. r=nss-reviewers,djackson (23be110c)
- Bug 1771495 - unchecked return code in sec_DecodeSigAlg. r=nss-reviewers,djackson (d4fb4b83)
- Bug 1771498 - Uninitialized value in cert_ComputeCertType. r=djackson (b28bc4cd)
- Bug 1764392 - Add DigitCert Roots r=nss-reviewers,jschanck (0863d9ec)
- Bug 1768970 - Add Certainly Roots. r=nss-reviewers,jschanck (6307e75b)
- Bug 1770267 - Add E-Tugra Roots. r=nss-reviewers,jschanck (9555008f)
- Bug 1759815 - Remove Hellenic Academic 2011 Root. r=nss-reviewers,jschanck (9c2cbf14)
- Bug 1764206 - Bump nssckbi version number for June. r=nss-reviewers,jschanck (b3acf3d9)
2022-06-17 11:00:44 +08:00
roytam1
5618d02caf import from nss upstream: Bug 1767590 - Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple r=#nss-reviewers,kaie (118b893f8e) 2022-06-02 10:10:47 +08:00
roytam1
eb6e4fbafe zlib: also pick up 4346a16853 2022-04-10 23:05:55 +08:00
roytam1
21d56c9c93 nss: update in-tree zlib to 1.2.11 with CVE-2018-25032 fix 2022-04-01 23:56:16 +08:00
roytam1
3336114a36 [NSS] ported mozilla upstream changes:
- Bug 1552254 internal_error alert on Certificate Request with sha1+ecdsa in TLS 1.3 (be6a9782)
- Bug 1753535 - Remove obsolete stateEnd check in SEC_ASN1DecoderUpdate. r=rrelyea (800111fa)
- Bug 1756271 - Remove token member from NSSSlot struct. r=rrelyea (55052f78)
- Bug 1396616 - Update nssUTF8_Length to RFC 3629 and fix buffer overrun. r=nss-reviewers,jschanck (2f2c8564)
- Bug 1755264 - TLS 1.3 Illegal legacy_version handling/alerts. r=djackson (7d931c59)
- Bug 1751305 - Remove expired explicitly distrusted certificates from certdata.txt. r=KathleenWilson (b722e523)
- Bug 1751298 - Add Telia Root CA v2 root certificate. r=KathleenWilson (1fcbbd7e)
- Bug 1754890 - Add two D-TRUST 2020 root certificates. r=KathleenWilson (f63fb86d)
2022-03-25 23:38:11 +08:00
roytam1
c403014cbe imported changes from mozilla NSS:
- Bug 1755555 - Hold tokensLock through nssToken_GetSlot calls in nssTrustDomain_GetActiveSlots. r=rrelyea (a36477f0)
- Bug 1370866 - Check return value of PK11Slot_GetNSSToken. r=djackson (d7e8c2df)
- Bug 1751157 - Throw illegal_parameter alert for illegal extensions in handshake message. r=djackson (8fd5ca0c)
2022-02-25 13:02:18 +08:00
roytam1
e3fb994063 Bug 1735028 - check for missing signedData field r=keeler 2022-01-19 10:25:05 +08:00
roytam1
5b0d1f871a imported changes from mozilla NSS:
- Bug 1737470 - Ensure DER encoded signatures are within size limits. r=jschanck,mt,bbeurdouche,rrelyea
- Bug 1735028 - check for missing signedData field r=keeler
and bump patch version.
2021-12-27 10:42:03 +08:00
roytam1
fceddf74e6 update NSS builtin certstore to Dec 2021 version from mozilla upstream. 2021-12-20 09:20:26 +08:00
roytam1
a140666918 imported changes from mozilla NSS:
- Bug 966856 - mozilla::pkix: support SHA-2 hashes in CertIDs in OCSP responses r=jschanck,djackson (78d2f4a3)
2021-12-17 16:54:54 +08:00
roytam1
423d61a6f8 import changes from mozilla nss repo:
- Bug 1662515 - Fix incorrect alert after successful decryption r=djackson
- Bug 1721476 sqlite 3.34 changed it's open semantics, causing nss failures.
- Bug 1728394 - Add TunTrust Root CA certificate to NSS. r=KathleenWilson
- Bug 1717707 - Add HARICA TLS RSA Root CA 2021. r=KathleenWilson
- Bug 1717707 - Add HARICA TLS ECC Root CA 2021. r=KathleenWilson
- Bug 1717707 - Add HARICA Client RSA Root CA 2021. r=KathleenWilson
- Bug 1717707 - Add HARICA Client ECC Root CA 2021. r=KathleenWilson
2021-09-10 11:57:20 +08:00
roytam1
6026e19d20 update NSS builtin certstore to May 2021 version from mozilla upstream. 2021-05-31 10:23:28 +08:00
roytam1
c082741e8a import changes from mozilla nss repo:
- Bug 1682863 - Revert nssSlot_IsTokenPresent to 3.58 after ongoing Fx hangs with slow PKCS11 devices. r=bbeurdouche
- Bug 1680400 - Fix memory leak in PK11_UnwrapPrivKey. r=bbeurdouche
2020-12-30 08:33:37 +08:00