roytam1
e7c19e1155
nss: update nssckbi to 2.62
2023-08-24 10:08:25 +08:00
roytam1
16926c542d
Merge remote-tracking branch 'origin/tracking' into custom
2023-02-20 12:02:40 +08:00
Moonchild
cdda874cff
[NSS] Update NSS to pick up fixes.
2023-02-20 12:01:55 +08:00
roytam1
58af5d4b99
imported changes from mozilla NSS:
...
- Bug 1794495 - Remove Network Solutions Certificate Authority. r=KathleenWilson (64a28c8d60)
- Bug 1794507 - Remove SwissSign Platinum CA - G2 from NSS. r=KathleenWilson (f2c2308403)
- Bug 1797559 - Remove EC-ACC root cert from NSS. r=KathleenWilson (4f1985c8dd)
- Bug 1799038 - Remove Staat der Nederlanden EV Root CA from NSS. r=KathleenWilson (9151be4c45)
- Bug 1794506 - Set nssckbi version number to 2.60. r=nss-reviewers,bbeurdouche (39fc42e136)
- Bug 1803453 - Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates. r=KathleenWilson (a871902c05)
2022-12-07 13:24:50 +08:00
roytam1
29846d1e4d
update NSS builtin certstore to Sep 2022 version from mozilla upstream.
2022-09-19 15:11:02 +08:00
roytam1
1822f2031e
Merge remote-tracking branch 'origin/tracking' into custom
2022-07-30 08:49:22 +08:00
Moonchild
10fdf0e1c5
[NSS] Fix uninitialized value in cert_ComputeCertType.
2022-07-30 08:43:45 +08:00
Moonchild
a77cf423c2
[NSS] Avoid potential data race on primary password change.
2022-07-30 08:43:44 +08:00
Moonchild
b9084ea29d
[NSS] protect SFTKSlot needLogin with slotLock.
2022-07-30 08:43:44 +08:00
roytam1
206c9dcbbf
Merge remote-tracking branch 'origin/tracking' into custom
2022-07-05 17:28:42 +08:00
Moonchild
2706ef696d
Update NSS
2022-07-05 17:21:07 +08:00
roytam1
43cfc69b25
imported changes from mozilla NSS:
...
- Bug 1759794 - protect SFTKSlot needLogin with slotLock. r=rrelyea (1bbd8d8c)
- Bug 1771497 - Uninitialized value in cert_VerifyCertChainOld. r=nss-reviewers,djackson (23be110c)
- Bug 1771495 - unchecked return code in sec_DecodeSigAlg. r=nss-reviewers,djackson (d4fb4b83)
- Bug 1771498 - Uninitialized value in cert_ComputeCertType. r=djackson (b28bc4cd)
- Bug 1764392 - Add DigitCert Roots r=nss-reviewers,jschanck (0863d9ec)
- Bug 1768970 - Add Certainly Roots. r=nss-reviewers,jschanck (6307e75b)
- Bug 1770267 - Add E-Tugra Roots. r=nss-reviewers,jschanck (9555008f)
- Bug 1759815 - Remove Hellenic Academic 2011 Root. r=nss-reviewers,jschanck (9c2cbf14)
- Bug 1764206 - Bump nssckbi version number for June. r=nss-reviewers,jschanck (b3acf3d9)
2022-06-17 11:00:44 +08:00
roytam1
5618d02caf
import from nss upstream: Bug 1767590 - Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple r=#nss-reviewers,kaie (118b893f8e)
2022-06-02 10:10:47 +08:00
roytam1
eb6e4fbafe
zlib: also pick up 4346a16853
2022-04-10 23:05:55 +08:00
roytam1
21d56c9c93
nss: update in-tree zlib to 1.2.11 with CVE-2018-25032 fix
2022-04-01 23:56:16 +08:00
roytam1
3336114a36
[NSS] ported mozilla upstream changes:
...
- Bug 1552254 internal_error alert on Certificate Request with sha1+ecdsa in TLS 1.3 (be6a9782)
- Bug 1753535 - Remove obsolete stateEnd check in SEC_ASN1DecoderUpdate. r=rrelyea (800111fa)
- Bug 1756271 - Remove token member from NSSSlot struct. r=rrelyea (55052f78)
- Bug 1396616 - Update nssUTF8_Length to RFC 3629 and fix buffer overrun. r=nss-reviewers,jschanck (2f2c8564)
- Bug 1755264 - TLS 1.3 Illegal legacy_version handling/alerts. r=djackson (7d931c59)
- Bug 1751305 - Remove expired explicitly distrusted certificates from certdata.txt. r=KathleenWilson (b722e523)
- Bug 1751298 - Add Telia Root CA v2 root certificate. r=KathleenWilson (1fcbbd7e)
- Bug 1754890 - Add two D-TRUST 2020 root certificates. r=KathleenWilson (f63fb86d)
2022-03-25 23:38:11 +08:00
roytam1
c403014cbe
imported changes from mozilla NSS:
...
- Bug 1755555 - Hold tokensLock through nssToken_GetSlot calls in nssTrustDomain_GetActiveSlots. r=rrelyea (a36477f0)
- Bug 1370866 - Check return value of PK11Slot_GetNSSToken. r=djackson (d7e8c2df)
- Bug 1751157 - Throw illegal_parameter alert for illegal extensions in handshake message. r=djackson (8fd5ca0c)
2022-02-25 13:02:18 +08:00
roytam1
e3fb994063
Bug 1735028 - check for missing signedData field r=keeler
2022-01-19 10:25:05 +08:00
roytam1
5b0d1f871a
imported changes from mozilla NSS:
...
- Bug 1737470 - Ensure DER encoded signatures are within size limits. r=jschanck,mt,bbeurdouche,rrelyea
- Bug 1735028 - check for missing signedData field r=keeler
and bump patch version.
2021-12-27 10:42:03 +08:00
roytam1
fceddf74e6
update NSS builtin certstore to Dec 2021 version from mozilla upstream.
2021-12-20 09:20:26 +08:00
roytam1
a140666918
imported changes from mozilla NSS:
...
- Bug 966856 - mozilla::pkix: support SHA-2 hashes in CertIDs in OCSP responses r=jschanck,djackson (78d2f4a3)
2021-12-17 16:54:54 +08:00
roytam1
423d61a6f8
import changes from mozilla nss repo:
...
- Bug 1662515 - Fix incorrect alert after successful decryption r=djackson
- Bug 1721476 sqlite 3.34 changed it's open semantics, causing nss failures.
- Bug 1728394 - Add TunTrust Root CA certificate to NSS. r=KathleenWilson
- Bug 1717707 - Add HARICA TLS RSA Root CA 2021. r=KathleenWilson
- Bug 1717707 - Add HARICA TLS ECC Root CA 2021. r=KathleenWilson
- Bug 1717707 - Add HARICA Client RSA Root CA 2021. r=KathleenWilson
- Bug 1717707 - Add HARICA Client ECC Root CA 2021. r=KathleenWilson
2021-09-10 11:57:20 +08:00
roytam1
6026e19d20
update NSS builtin certstore to May 2021 version from mozilla upstream.
2021-05-31 10:23:28 +08:00
roytam1
c082741e8a
import changes from mozilla nss repo:
...
- Bug 1682863 - Revert nssSlot_IsTokenPresent to 3.58 after ongoing Fx hangs with slow PKCS11 devices. r=bbeurdouche
- Bug 1680400 - Fix memory leak in PK11_UnwrapPrivKey. r=bbeurdouche
2020-12-30 08:33:37 +08:00
roytam1
ecf2071a46
import changes from mozilla nss repo:
...
- Bug 1641480, TLS 1.3: tighten CCS handling in compatibility mode, r=mt
- Bug 1672703, always tolerate the first CCS in TLS 1.3, r=mt
- Bug 1663661 - Guard against NULL token in nssSlot_IsTokenPresent. r=jcj
- Bug 1607449 - Lock cert->nssCertificate to prevent data race. r=jcj,keeler
- Bug 1679290 - Don't hold slot lock when taking session lock r=bbeurdouche
2020-12-02 10:52:47 +08:00
roytam1
ee3eabdb1e
sync NSS builtin cert store up to mozilla nss hg rev f8c49b33:
...
- Bug 1670769 - Remove 10 GeoTrust, thawte, and VeriSign root certs from NSS. r=kjacobs,KathleenWilson
- Bug 1678166 - Add NAVER Global Root Certification Authority root cert to NSS. r=bbeurdouche,KathleenWilson
- Bug 1678189 - December 2020 batch of root changes, NSS_BUILTINS_LIBRARY_VERSION 2.46. r=bbeurdouche
2020-12-02 10:04:43 +08:00
roytam1
ee11f1749b
Merge remote-tracking branch 'origin/master' into custom
2020-12-02 09:58:28 +08:00
Moonchild
d8fdbcd88c
[NSS] Version and build bump
2020-12-02 09:57:49 +08:00
Moonchild
b71804f4a3
[NSS] Update root certificates.
2020-12-02 09:57:48 +08:00
roytam1
75e16e5121
partly import changes from tenfourfox:
...
- #627 : M1631583 M1631597 M1636771 M1637222 M1649316 M1651520 (2373458b5)
- #627 : M1631573 (0abd0fc5d)
2020-10-09 21:23:26 +08:00
roytam1
56aaf6a15a
Merge remote-tracking branch 'origin/master' into custom
2020-09-25 22:18:48 +08:00
Moonchild
8c395520d9
Issue #1656 - Part 1: Nuke most vim config lines in the tree.
...
Since these are just interpreted comments, there's 0 impact on actual code.
This removes all lines that match /* vim: set(.*)tw=80: */ with S&R -- there are
a few others scattered around which will be removed manually in a second part.
2020-09-25 22:04:12 +08:00
roytam1
06a2891ef7
import certdata changes from NSS upstream:
...
- Bug 1651211 - Remove EE Certification Centre Root CA root cert. r=KathleenWilson,jcj
- Bug 1653092 - Disable server trust bit for OISTE WISeKey Global Root GA CA root cert. r=KathleenWilson,jcj
- Bug 1656077 - Remove Taiwan Government Root Certification Authority root cert. r=KathleenWilson,jcj
- Bug 1663049 - Add SecureTrust's Trustwave Global root certificates to NSS. r=KathleenWilson,jcj
- Bug 1663049 - September 2020 batch of root changes, NSS_BUILTINS_LIBRARY_VERSION 2.44. r=jcj
2020-09-19 07:05:30 +08:00
roytam1
1455a4fcbd
import change from tenfourfox:
...
- fix overzealous assertion (M1531906) (af9a8236e)
2020-09-19 07:05:02 +08:00
Roy Tam
8015bb7004
update NSS as-of pm27 rev 7606140ee
2020-09-04 22:55:34 +08:00
Roy Tam
eeb44de4a1
Merge remote-tracking branch 'origin/master' into custom
2020-09-04 22:34:20 +08:00
Moonchild
38470e4fe9
[NSS] Version and build bump
2020-09-04 22:30:57 +08:00
J.C. Jones
0e23c7cc48
[NSS] Prevent slotLock race in NSC_GetTokenInfo
...
Basically, NSC_GetTokenInfo doesn't lock slot->slotLock before accessing slot
after obtaining it, even though slotLock is defined as its lock.
2020-09-04 22:30:55 +08:00
Roy Tam
3d5ac98e9d
Merge remote-tracking branch 'origin/master' into custom
2020-07-10 22:22:14 +08:00
Moonchild
9890572c8e
[NSS] Version and build bump
2020-07-10 22:18:56 +08:00
Sohaib ul Hassan
62467c473d
[NSS] Implement constant-time GCD and modular inversion
...
The implementation is based on the work by Bernstein and Yang
(https://eprint.iacr.org/2019/266 )
"Fast constant-time gcd computation and modular inversion".
It fixes the old mp_gcd and s_mp_invmod_odd_m functions. The patch also fixes
mpl_significant_bits s_mp_div_2d and s_mp_mul_2d by having less control flow to
reduce side-channel leaks.
Co-authored by : Billy Bob Brumley
2020-07-10 22:18:52 +08:00
Roy Tam
5c4cee240f
Merge remote-tracking branch 'origin/master' into custom
2020-06-06 07:27:53 +08:00
Moonchild
ca3ce88bd1
[NSS] Bump NSS version
2020-06-06 07:21:18 +08:00
Moonchild
4789fee7cf
[NSS] Force a fixed length for DSA exponentiation
2020-06-06 07:21:15 +08:00
Roy Tam
678ad26488
Merge remote-tracking branch 'origin/master' into custom
2020-01-24 09:39:16 +08:00
Kai Engert
a8daf97de0
Issue #1338 - Follow-up: Also cache the most recent PBKDF1 hash
...
This rewrites the caching mechanism to apply to both PBKDF1 and PBKDF2
2020-01-24 09:36:33 +08:00
wolfbeast
abb2afe2a7
Issue #1338 - Bump NSS version
...
Our NSS version is closer to the currently-released .1, so bump version
to that.
Note: we still have some additional patches to the in-tree version in
place so this isn't a 100% match to the RTM one.
2020-01-24 09:28:39 +08:00
Roy Tam
969d239b65
Merge remote-tracking branch 'origin/master' into custom
2020-01-17 09:24:31 +08:00
Kai Engert
3d75257e8d
Issue #1338 : Follow-up: Cache the most recent PBKDF2 password hash,
...
to speed up repeated SDR operations.
Landed on NSS-3.48 for Bug 1606992
2020-01-17 09:15:04 +08:00
Daiki Ueno
75fdf9c3b0
Issue #1338 - Followup: certdb: propagate trust information if trust
...
module is loaded afterwards,
Summary: When the builtin trust module is loaded after some temp certs
being created, these temp certs are usually not accompanied by trust
information. This causes a problem in UXP as it loads the module from a
separate thread while accessing the network cache which populates temp
certs.
This change makes it properly roll up the trust information, if a temp
cert doesn't have trust information.
2020-01-11 06:47:38 +08:00