Network Security Services

Edit Package mozilla-nss

Network Security Services (NSS) is a set of libraries designed to
support cross-platform development of security-enabled server
applications. Applications built with NSS can support SSL v2 and v3,
TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3
certificates, and other security standards.

Refresh
Refresh
Source Files
Filename Size Changed
add-relro-linker-option.patch 0000000433 433 Bytes
baselibs.conf 0000000426 426 Bytes
bmo-1400603.patch 0000012934 12.6 KB
cert9.db 0000009216 9 KB
key4.db 0000011264 11 KB
malloc.patch 0000000300 300 Bytes
mozilla-nss-rpmlintrc 0000000187 187 Bytes
mozilla-nss.changes 0000125136 122 KB
mozilla-nss.spec 0000015095 14.7 KB
nss-3.55.tar.gz 0081759883 78 MB
nss-config.in 0000002408 2.35 KB
nss-fips-aes-keywrap-post.patch 0000005243 5.12 KB
nss-fips-approved-crypto-non-ec.patch 0000012487 12.2 KB
nss-fips-cavs-dsa-fixes.patch 0000007870 7.69 KB
nss-fips-cavs-general.patch 0000008456 8.26 KB
nss-fips-cavs-kas-ecc.patch 0000011953 11.7 KB
nss-fips-cavs-kas-ffc.patch 0000008718 8.51 KB
nss-fips-cavs-keywrap.patch 0000007043 6.88 KB
nss-fips-cavs-rsa-fixes.patch 0000001045 1.02 KB
nss-fips-combined-hash-sign-dsa-ecdsa.patch 0000014361 14 KB
nss-fips-constructor-self-tests.patch 0000046348 45.3 KB
nss-fips-detect-fips-mode-fixes.patch 0000002480 2.42 KB
nss-fips-dsa-kat.patch 0000010049 9.81 KB
nss-fips-gcm-ctr.patch 0000001977 1.93 KB
nss-fips-pairwise-consistency-check.patch 0000001110 1.08 KB
nss-fips-rsa-keygen-strictness.patch 0000008558 8.36 KB
nss-fips-tls-allow-md5-prf.patch 0000007641 7.46 KB
nss-fips-use-getrandom.patch 0000003069 3 KB
nss-fips-use-strong-random-pool.patch 0000001599 1.56 KB
nss-fips-zeroization.patch 0000006516 6.36 KB
nss-fix-dh-pkcs-derive-inverted-logic.patch 0000000796 796 Bytes
nss-no-rpath.patch 0000001040 1.02 KB
nss-opt.patch 0000000739 739 Bytes
nss-sqlitename.patch 0000000893 893 Bytes
nss.pc.in 0000000250 250 Bytes
pkcs11.txt 0000000450 450 Bytes
ppc-old-abi-v3.patch 0000001152 1.13 KB
setup-nsssysinit.sh 0000001255 1.23 KB
system-nspr.patch 0000000430 430 Bytes
Revision 161 (latest revision is 218)
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 829609 from Wolfgang Rosenauer's avatar Wolfgang Rosenauer (wrosenauer) (revision 161)
- update to NSS 3.55
  Notable changes
  * P384 and P521 elliptic curve implementations are replaced with
    verifiable implementations from Fiat-Crypto [0] and ECCKiila [1].
  * PK11_FindCertInSlot is added. With this function, a given slot
    can be queried with a DER-Encoded certificate, providing performance
    and usability improvements over other mechanisms. (bmo#1649633)
  * DTLS 1.3 implementation is updated to draft-38. (bmo#1647752)
  Relevant Bugfixes
  * bmo#1631583 (CVE-2020-6829, CVE-2020-12400) - Replace P384 and
    P521 with new, verifiable implementations from Fiat-Crypto and ECCKiila.
  * bmo#1649487 - Move overzealous assertion in VFY_EndWithSignature.
  * bmo#1631573 (CVE-2020-12401) - Remove unnecessary scalar padding.
  * bmo#1636771 (CVE-2020-12403) - Explicitly disable multi-part
    ChaCha20 (which was not functioning correctly) and more strictly
    enforce tag length.
  * bmo#1649648 - Don't memcpy zero bytes (sanitizer fix).
  * bmo#1649316 - Don't memcpy zero bytes (sanitizer fix).
  * bmo#1649322 - Don't memcpy zero bytes (sanitizer fix).
  * bmo#1653202 - Fix initialization bug in blapitest when compiled
    with NSS_DISABLE_DEPRECATED_SEED.
  * bmo#1646594 - Fix AVX2 detection in makefile builds.
  * bmo#1649633 - Add PK11_FindCertInSlot to search a given slot
    for a DER-encoded certificate.
  * bmo#1651520 - Fix slotLock race in NSC_GetTokenInfo.
  * bmo#1647752 - Update DTLS 1.3 implementation to draft-38.
  * bmo#1649190 - Run cipher, sdr, and ocsp tests under standard test cycle in CI.
  * bmo#1649226 - Add Wycheproof ECDSA tests.
  * bmo#1637222 - Consistently enforce IV requirements for DES and 3DES.
  * bmo#1067214 - Enforce minimum PKCS#1 v1.5 padding length in
Comments 0
openSUSE Build Service is sponsored by