Overview
Request 567964 accepted
NSS update as prerequisite for Firefox 58 to be released coming week (to TW).
- update to NSS 3.34.1
Changes in 3.34:
Notable changes
* The following CA certificates were Added:
GDCA TrustAUTH R5 ROOT
SSL.com Root Certification Authority RSA
SSL.com Root Certification Authority ECC
SSL.com EV Root Certification Authority RSA R2
SSL.com EV Root Certification Authority ECC
TrustCor RootCert CA-1
TrustCor RootCert CA-2
TrustCor ECA-1
* The following CA certificates were Removed:
Certum CA, O=Unizeto Sp. z o.o.
StartCom Certification Authority
StartCom Certification Authority G2
TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı - Sürüm 3
ACEDICOM Root
Certinomis - Autorité Racine
TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı
PSCProcert
CA 沃通根证书, O=WoSign CA Limited
Certification Authority of WoSign
Certification Authority of WoSign G2
CA WoSign ECC Root
* libfreebl no longer requires SSE2 instructions
New functionality
* When listing an NSS database using certutil -L, but the database
hasn't yet been initialized with any non-empty or empty password,
the text "Database needs user init" will be included in the listing.
* When using certutil to set an inacceptable password in FIPS mode,
a correct explanation of acceptable passwords will be printed.
* SSLKEYLOGFILE is now supported with TLS 1.3, see bmo#1287711 for details.
* SSLChannelInfo has two new fields (bmo#1396525):
SSLNamedGroup originalKeaGroup holds the key exchange group of
the original handshake when the session was resumed.
PRBool resumed is PR_TRUE when the session is resumed and PR_FALSE
otherwise.
* RSA-PSS signatures are now supported on certificates. Certificates
with RSA-PSS or RSA-PKCS#1v1.5 keys can be used to create an RSA-PSS
signature on a certificate using the --pss-sign argument to certutil.
Changes in 3.34.1:
* The following CA certificate was Re-Added. It was removed in NSS
3.34, but has been re-added with only the Email trust bit set.
(bmo#1418678):
libfreebl no longer requires SSE2 instructionsCN = Certum CA, O=Unizeto Sp. z o.o.
* Removed entries from certdata.txt for actively distrusted
certificates that have expired (bmo#1409872)
* The version of the CA list was set to 2.20.
- Created by wrosenauer
- In state accepted
Request History
wrosenauer created request
NSS update as prerequisite for Firefox 58 to be released coming week (to TW).
- update to NSS 3.34.1
Changes in 3.34:
Notable changes
* The following CA certificates were Added:
GDCA TrustAUTH R5 ROOT
SSL.com Root Certification Authority RSA
SSL.com Root Certification Authority ECC
SSL.com EV Root Certification Authority RSA R2
SSL.com EV Root Certification Authority ECC
TrustCor RootCert CA-1
TrustCor RootCert CA-2
TrustCor ECA-1
* The following CA certificates were Removed:
Certum CA, O=Unizeto Sp. z o.o.
StartCom Certification Authority
StartCom Certification Authority G2
TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı - Sürüm 3
ACEDICOM Root
Certinomis - Autorité Racine
TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı
PSCProcert
CA 沃通根证书, O=WoSign CA Limited
Certification Authority of WoSign
Certification Authority of WoSign G2
CA WoSign ECC Root
* libfreebl no longer requires SSE2 instructions
New functionality
* When listing an NSS database using certutil -L, but the database
hasn't yet been initialized with any non-empty or empty password,
the text "Database needs user init" will be included in the listing.
* When using certutil to set an inacceptable password in FIPS mode,
a correct explanation of acceptable passwords will be printed.
* SSLKEYLOGFILE is now supported with TLS 1.3, see bmo#1287711 for details.
* SSLChannelInfo has two new fields (bmo#1396525):
SSLNamedGroup originalKeaGroup holds the key exchange group of
the original handshake when the session was resumed.
PRBool resumed is PR_TRUE when the session is resumed and PR_FALSE
otherwise.
* RSA-PSS signatures are now supported on certificates. Certificates
with RSA-PSS or RSA-PKCS#1v1.5 keys can be used to create an RSA-PSS
signature on a certificate using the --pss-sign argument to certutil.
Changes in 3.34.1:
* The following CA certificate was Re-Added. It was removed in NSS
3.34, but has been re-added with only the Email trust bit set.
(bmo#1418678):
libfreebl no longer requires SSE2 instructionsCN = Certum CA, O=Unizeto Sp. z o.o.
* Removed entries from certdata.txt for actively distrusted
certificates that have expired (bmo#1409872)
* The version of the CA list was set to 2.20.
factory-auto added opensuse-review-team as a reviewer
Please review sources
factory-auto added repo-checker as a reviewer
Please review build success
factory-auto accepted review
Check script succeeded
licensedigger accepted review
ok
staging-bot set openSUSE:Factory:Staging:G as a staging project
Being evaluated by staging project "openSUSE:Factory:Staging:G"
staging-bot accepted review
Picked openSUSE:Factory:Staging:G
dimstar accepted review
repo-checker accepted review
cycle and install check passed
dimstar_suse accepted review
ready to accept
dimstar_suse approved review
ready to accept
dimstar_suse accepted request
Accept to openSUSE:Factory