|
|
|
|
Changelog for nss-sysinit-3.28.4-1.el6_9.x86_64.rpm :
* Fri Apr 07 2017 Daiki Ueno - 3.28.4-1- Rebase to 3.28.4 * Fri Mar 24 2017 Daiki Ueno - 3.28.3-3- Fix crash with tstclnt -W- Adjust gtests to run with our old softoken and downstream patches * Wed Mar 15 2017 Daiki Ueno - 3.28.3-2- Avoid cipher suite ordering change, spotted by Hubert Kario * Tue Feb 28 2017 Daiki Ueno - 3.28.3-1- Rebase to 3.28.3- Remove upstreamed moz-1282627-rh-1294606.patch, moz-1312141-rh-1387811.patch, moz-1315936.patch, and moz-1318561.patch- Remove no longer necessary nss-duplicate-ciphers.patch- Disable X25519 and exclude tests using it- Catch failed ASN1 decoding of RSA keys, by Kamil Dudka (#1427481) * Mon Jan 09 2017 Daiki Ueno - 3.27.1-13- Update expired PayPalEE.cert * Tue Dec 13 2016 Daiki Ueno - 3.27.1-12- Disable unsupported test cases in ssl_gtests * Tue Dec 06 2016 Daiki Ueno - 3.27.1-11- Adjust the sslstress.txt filename so that it matches with the disableSSL2tests patch ported from RHEL 7- Exclude SHA384 and CHACHA20_POLY1305 ciphersuites from stress tests- Don\'t add gtests and ssl_gtests to nss_tests, unless gtests are enabled * Fri Dec 02 2016 Daiki Ueno - 3.27.1-10- Add patch to fix SSL CA name leaks, taken from NSS 3.27.2 release- Add patch to fix bash syntax error in tests/ssl.sh- Add patch to remove duplicate ciphersuites entries in sslinfo.c- Add patch to abort selfserv/strsclnt/tstclnt on non-parsable version range- Build with support for SSLKEYLOGFILE * Wed Nov 16 2016 Daiki Ueno - 3.27.1-9- Update fix_multiple_open patch to fix regression in openldap client- Remove pk11_genobj_leak patch, which caused crash with Firefox- Add comment in the policy file to preserve the last empty line- Disable SHA384 ciphersuites when CKM_TLS12_KEY_AND_MAC_DERIVE is not provided by softoken; this superseds check_hash_impl patch * Fri Nov 11 2016 Daiki Ueno - 3.27.1-8- Fix problem in check_hash_impl patch * Wed Nov 09 2016 Daiki Ueno - 3.27.1-7- Add patch to check if hash algorithms are backed by a token- Add patch to disable TLS_ECDHE_{RSA,ECDSA}_WITH_AES_128_CBC_SHA256, which have never enabled in the past * Tue Nov 08 2016 Kai Engert - 3.27.1-6- Add upstream patch to fix a crash. Mozilla #1315936 * Wed Nov 02 2016 Kai Engert - 3.27.1-5- Disable the use of RSA-PSS with SSL/TLS. #1390161 * Mon Oct 31 2016 Kai Engert - 3.27.1-4- Use updated upstream patch for RH bug 1387811 * Thu Oct 27 2016 Kai Engert - 3.27.1-3- Added upstream patches to fix RH bugs 1057388, 1294606, 1387811 * Wed Oct 12 2016 Daiki Ueno - 3.27.1-2- Enable gtests when requested * Tue Oct 11 2016 Daiki Ueno - 3.27.1-1- Rebase to NSS 3.27.1- Remove nss-646045.patch, which is not necessary- Remove p-disable-md5-590364-reversed.patch, which is no-op here, because the patched code is removed later in %setup- Remove disable_hw_gcm.patch, which is no-op here, because the patched code is removed later in %setup. Also remove NSS_DISABLE_HW_GCM setting, which was only required for RHEL 5- Add Bug-1001841-disable-sslv2-libssl.patch and Bug-1001841-disable-sslv2-tests.patch, which completedly disable EXPORT ciphersuites. Ported from RHEL 7- Remove disable-export-suites-tests.patch, which is covered by Bug-1001841-disable-sslv2-tests.patch- Remove nss-ca-2.6-enable-legacy.patch, as we decided to not allow 1024 legacy CA certificates- Remove ssl-server-min-key-sizes.patch, as we decided to support DH key size greater than 1023 bits- Remove nss-init-ss-sec-certs-null.patch, which appears to be no-op, as it clears memory area allocated with PORT_ZAlloc()- Remove nss-disable-sslv2-libssl.patch, nss-disable-sslv2-tests.patch, sslauth-no-v2.patch, and nss-sslstress-txt-ssl3-lower-value-in-range.patch as SSLv2 is already disabled in upstream- Remove fix-nss-test-filtering.patch, which is fixed in upstream- Add nss-check-policy-file.patch from Fedora- Install policy config in /etc/pki/nss-legacy/nss-rhel6.config * Tue Mar 22 2016 Kai Engert - 3.21.0-8- Ensure all ssl.sh tests are executed * Mon Mar 21 2016 Elio Maldonado - 3.21.0-7- Update sslauth patch to run more tests * Wed Mar 16 2016 Elio Maldonado - 3.21.0-6- Fix syntax errors in patch that disables sslv2 tests- Resolves: Bug 1297888 - Rebase RHEL 6.8 to NSS 3.21 for Firefox 45 * Wed Mar 02 2016 Elio Maldonado - 3.21.0-5- Resolves: Bug 1304812 - Disable support for SSLv2 completely. * Wed Feb 24 2016 Elio Maldonado - 3.21.0-4- Add patches for ABI compatibility * Mon Jan 25 2016 Elio Maldonado - 3.21.0-3- Disable extended master-secret due to older version of softoken * Sat Jan 23 2016 Elio Maldonado - 3.21.0-2- Enable two additional ciphers and keep another one disabled- Prevent enabling extended masker key derive * Tue Jan 12 2016 Elio Maldonado - 3.21.0-1- Rebase to NSS-3.21 * Tue Dec 22 2015 Elio Maldonado - 3.19.1-9- Prevent TLS 1.2 Transcript Collision attacks against MD5 in key exchange protocol- Resolves: Bug 1289890 * Thu Nov 19 2015 Elio Maldonado - 3.19.1-7- Package listsuites as part of the unsupported tools set- Resolves: Bug 1283655 * Wed Nov 18 2015 Elio Maldonado - 3.19.1-6- Resolves: Bug 1272504 - Enable TLS 1.2 as the default in nss * Wed Oct 21 2015 Elio Maldonado - 3.19.1-5- Rebuild against updated NSPR * Thu Jun 25 2015 Elio Maldonado - 3.19.1-4- Sync up with the rhel-6.6 branch- Resolves: Bug 1224450 * Sat Jun 13 2015 Kai Engert - 3.19.1-3- Additional NULL initialization. * Fri Jun 12 2015 Kai Engert - 3.19.1-2- Updated the patch to keep old cipher suite order- Resolves: Bug 1224450 * Sat Jun 06 2015 Elio Maldonado - 3.19.1-1- Rebase to nss-3.19.1- Resolves: Bug 1224450 * Wed Apr 29 2015 Kai Engert - 3.18.0-5.3- On RHEL 6.x keep the TLS version defaults unchanged.- Require softokn build 22 to ensure runtime compatibility.- Relax the requirement from pkcs11-devel to nss-softokn-freebl-devel to allow same or newer.- Update to CKBI 2.4 from NSS 3.18.1 (the only change in NSS 3.18.1) * Sat Apr 18 2015 Elio Maldonado - 3.18.0-5- Update and reeneable nss-646045.patch on account of the rebase- Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL7.1] * Mon Apr 13 2015 Elio Maldonado - 3.18.0-4- Fix shell syntax error in nss/tests/all.sh- Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6] * Sat Apr 11 2015 Elio Maldonado - 3.18.0-3- Restore a patch that had been mistakenly disabled- Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6] * Fri Apr 10 2015 Elio Maldonado - 3.18.0-2- Replace expired PayPal test certificate that breaks the build- Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6] * Mon Apr 06 2015 Elio Maldonado - 3.18.0-1- Resolves: Bug 1200900 - Rebase nss to 3.18 for Firefox 38 ESR [RHEL-6.6]- Resolves: Bug 1131311 - rhel65 ns-slapd crash, segfault error 4 in libnss3.so in PK11_DoesMechanism at pk11slot.c:1824- Temporarily disable some tests until expired PayPalEE.cert is renewed * Fri Mar 13 2015 Elio Maldonado - 3.16.2.3-4- Keep the same cipher suite order as we had in NSS_3_15_3_RTM- Resolves: Bug 1123092 - openldap-2.4.23-34.el6_5.1.i686 fails after updating nss to nss-3.16.1-4.el6_5.i686 * Wed Nov 26 2014 Elio Maldonado - 3.16.2.3-3- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3- Remove unused indentation pseudo patch- require nss util 3.16.2.3- Restore patch for certutil man page- supply missing options descriptions to the man page * Thu Nov 13 2014 Elio Maldonado - 3.16.2.3-1- Resolves: Bug 1158160 - Upgrade to NSS 3.16.2.3 for Firefox 31.3 * Wed Sep 24 2014 Elio Maldonado - 3.16.1-14- Resolves: Bug 1145432 - CVE-2014-1568 * Wed Aug 20 2014 Elio Maldonado - 3.16.1-13- Fix pem deadlock caused by previous version of a fix for a race condition- Fixes: Bug 1090681 * Fri Aug 15 2014 Elio Maldonado - 3.16.1-12- Add references to bugs filed upstream- Related: Bug 1090681, Bug 1104300 * Mon Aug 11 2014 Elio Maldonado - 3.16.1-11- Resolves: Bug 1090681 - RHDS 9.1 389-ds-base-1.2.11.15-31 crash in PK11_DoesMechanism * Tue Jul 29 2014 Elio Maldonado - 3.16.1-10- Replace expired PayPal test certificate that breaks the build- Related: Bug 1099619 * Mon Jul 21 2014 Elio Maldonado - 3.16.1-9- Fix defects found by coverity- Resolves: Bug 1104300 * Mon Jun 30 2014 Elio Maldonado - 3.16.1-8- Backport nss-3.12.6 upstream fix required by Firefox 31- Resolves: Bug 1099619 * Wed Jun 18 2014 Elio Maldonado - 3.16.1-7- Update nspr-version to 4.10.6 * Tue Jun 17 2014 Elio Maldonado - 3.16.1-6- Update pem sources to the same ones used on rhel-7- Remove no longer needed patches on account of this update- Resolves: Bug 1002205 * Tue Jun 10 2014 Elio Maldonado - 3.16.1-5- Move removal of directories to the end of the %prep section- Resolves: Bug 689919 - build without any softoken or util sources in the tree * Fri Jun 06 2014 Elio Maldonado - 3.16.1-4- Remove unused patches rendered obsolete * Fri Jun 06 2014 Elio Maldonado - 3.16.1-3- Fix pem module trashing of private keys on failed login- Resolves: Bug 1002205 - PEM module trashes private keys if login fails * Thu May 29 2014 Elio Maldonado - 3.16.1-2- Restore use of indentation patch until another bug is resolved- Resolves: Bug 606022 - nss security tools lack man pages * Wed May 28 2014 Elio Maldonado - 3.16.1-1- Update to nss-3.16.1- Resolves: Bug 1099619 - Rebase nss in RHEL 6.6 to NSS 3.16.1 * Mon Apr 21 2014 Elio Maldonado - 3.15.3-11- Resolves: Bug 689919 - build without any softoken or util sources in the tree- Add define-uint32.patch to deal with using older version of nss-softokn- Fix suboptimal test failure detection shell code in the %check section * Thu Apr 10 2014 Elio Maldonado - 3.15.3-10- Prevent users from disabling the internal crypto module- Resolves: Bug 1059176 - nss segfaults with opencryptoki module * Wed Mar 26 2014 Elio Maldonado - 3.15.3-9- Improve support for ECDSA algorithm via pluggable ECC- Document the purpose of the iquote.patch- Resolves: Bug 1057224 - Pluggable ECC in NSS not enabled on RHEL 6 and above * Wed Mar 26 2014 Elio Maldonado - 3.15.3-8- Install man pages for the nss security tools- Resolves: Bug 606022 - nss security tools lack man pages * Wed Feb 12 2014 Elio Maldonado - 3.15.3-7- Fix the numbering and naming of the patches- Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL * Wed Jan 22 2014 Elio Maldonado - 3.15.3-6- make derEncodingsMatch work with encrypted keys- rename a patch, dropped the experimental moniker from it- Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL * Fri Jan 03 2014 Elio Maldonado - 3.15.3-5- Resolves: Bug 895339 - [PEM] active FTPS with encrypted client key ends up with SSL_ERROR_TOKEN_INSERTION_REMOVAL * Fri Dec 13 2013 Elio Maldonado - 3.15.3-4- Revoke trust in one mis-issued anssi certificate- Resolves: Bug 1042686 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117) [rhel-6.6] * Sun Dec 01 2013 Elio Maldonado - 3.15.3-3- Disable hw gcm on rhel-5 based build environments where OS lacks support- Rollback changes to build nss without softokn until Bug 689919 is approved- Cipher suite was run as part of the nss-softokn build * Fri Nov 29 2013 Elio Maldonado - 3.15.3-2- Build nss without softoken, freebl, or util sources in the build source tree- Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 * Mon Nov 25 2013 Elio Maldonado - 3.15.3-1- Update to NSS_3_15_3_RTM- Resolves: Bug 1032472 - CVE-2013-5605 CVE-2013-5606 CVE-2013-1741- Resolves: Bug 1031238 - deadlock in trust domain lock and object lock * Tue Oct 15 2013 Elio Maldonado - 3.15.1-15- Using export NSS_DISABLE_HW_GCM=1 to deal with some problemmatic build systems- Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so * Tue Oct 15 2013 Elio Maldonado - 3.15.1-14- Add s390x and ia64 to the %define multilib_arches list used for defining alt_ckbi- Resolves: rhbz#1016044 - nss.s390: primary link for libnssckbi.so must be /usr/lib64/libnssckbi.so * Mon Oct 07 2013 Elio Maldonado - 3.15.1-13- Add zero default value to DISABLETEST check and fix the TEST_FAILURES check and reporting- Resolves: rhbz#990631 - file permissions of pkcs11.txt/secmod.db must be kept when modified by NSS- Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) * Sun Oct 06 2013 Elio Maldonado - 3.15.1-12- Add a zero default value to the DISABLETEST and TEST_FAILURES checks- Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) * Fri Oct 04 2013 Elio Maldonado - 3.15.1-11- Fix the test for zero failures in the %check section- Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) * Fri Sep 27 2013 Elio Maldonado - 3.15.1-10- Restore a mistakenly removed patch- Resolves: rhbz#961659 - SQL backend does not reload certificates * Mon Sep 23 2013 Elio Maldonado - 3.15.1-9- Rebuild for the pem module to link with freel from nss-softokn-3.14.3-6.el6- Related: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0]- Related: rhbz#1010224 - NSS 3.15 breaks SSL in OpenLDAP clients * Thu Sep 19 2013 Elio Maldonado - 3.15.1-8- Don\'t require nss-softokn-fips- Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0] * Thu Sep 19 2013 Kai Engert - 3.15.1-7- Additional syntax fixes in nss-versus-softoken-test.patch- Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) * Wed Sep 18 2013 Elio Maldonado - 3.15.1-6- Fix all.sh test for which application was last build by updating nss-versus-softoken-test.path- Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) * Fri Sep 13 2013 Elio Maldonado - 3.15.1-5- Disable the cipher suite already run as part of the nss-softokn build- Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0] * Fri Sep 13 2013 Elio Maldonado - 3.15.1-4- Require nss-softokn-fips- Resolves: rhbz#993441 - NSS needs to conform to new FIPS standard. [rhel-6.5.0] * Sat Sep 07 2013 Elio Maldonado - 3.15.1-3- Require nspr-4.10.0- Related: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) * Fri Sep 06 2013 Elio Maldonado - 3.15.1-2- Fix relative path in %check section to prevent undetected test failures- Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) * Fri Sep 06 2013 Elio Maldonado - 3.15.1-1- Rebase to NSS_3.15.1_RTM- Resolves: rhbz#1002645 - Rebase RHEL 6 to NSS 3.15.1 (for FF 24.x) - Update patches on account of the shallow tree with the rebase to 3.15.1- Update the pem module sources nss-pem-20130405.tar.bz2 with latest patches applied- Remove patches rendered obsolete by the nss rebase and the updated nss-pem sources- Enable the iquote.patch to access newly introduced types * Tue Aug 13 2013 Elio Maldonado - 3.14.3-37- Do not hold issuer certificate handles in the crl cache- Resolves: rhbz#961659 - SQL backend does not reload certificates * Mon Aug 12 2013 Elio Maldonado - 3.14.3-36- Resolves: rhbz#977341 - nss-tools certutil -H does not list all options * Fri Aug 09 2013 Elio Maldonado - 3.14.3-35- Resolves: rhbz#702083 - dont require unique file basenames * Thu Aug 08 2013 Elio Maldonado - 3.14.3-34- Fix race condition in cert code related to smart cards- Resolves: rhbz#903017 - Firefox hang when CAC/PIV smart card certificates are viewed in the certificate manager * Thu Jun 13 2013 Kai Engert - 3.14.3-33- Configure libnssckbi.so to use the alternatives system in order to prepare for a drop in replacement. Please ensure that older packages that don\'t use the alternatives system for libnssckbi.so have a smaller n-v-r. * Sun May 26 2013 Elio Maldonado - 3.14.3-5- Syncup with uptream changes for aes gcm and ecc suiteb- Enable ecc support for suite b- Apply several upstream AES GCM fixes- Use the pristine nss upstream sources with ecc included- Export NSS_ENABLE_ECC=1 in both the build and the check sections- Make failed requests for unsupoprted ssl pkcs 11 bypass non fatal- Resolves: rhbz#882408 - NSS_NO_PKCS11_BYPASS must preserve ABI- Related: rhbz#918950 - rebase nss to 3.14.3 * Fri Apr 26 2013 Elio Maldonado - 3.14.3-4- Revert to accepting MD5 on digital signatures by default- Resolves: rhbz#918136 - nss 3.14 - MD5 hash algorithm disabled * Wed Mar 27 2013 Elio Maldonado - 3.14.3-3- Ensure pem uses system freebl as with this update freebl brings in new API\'s- Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue * Tue Mar 26 2013 Elio Maldonado - 3.14.3-2- Install sechash.h and secmodt.h which are now provided by nss-devel- Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue- Remove unsafe -r option from commands that remove headers already shipped by nss-util and nss-softoken * Sun Mar 24 2013 Elio Maldonado - 3.14.3-1- Update to NSS_3.14.3_RTM- Resolves: rhbz#918950 - [RFE][RHEL6] Rebase to nss-3.14.3 to fix the lucky-13 issue- Update expired test certificates (fixed in upstream bug 852781)- Sync up pem module\'s rsawrapr.c with softoken\'s upstream changes for nss-3.14.3- Reactivate the aia tests * Thu Jan 10 2013 Elio Maldonado - 3.14.0.0-12- Recreate the distrust patch by backporting the upstream one- Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate * Wed Jan 09 2013 Elio Maldonado - 3.14.0.0-11- Resolves: rhpbz#890914 - Dis-trust TURKTRUST mis-issued *.google.com certificate * Wed Dec 12 2012 Elio Maldonado - 3.14.0.0-10- Remove a patch that caused a regression- Resolves: rhbz#883620 * Wed Nov 07 2012 Elio Maldonado - 3.14.0.0-9- Fix locking issue causing curl hangs and authenticate to the correct session- Resolves: rhbz#872838 * Wed Nov 07 2012 Elio Maldonado - 3.14.0.0-8- PEM peminit returns CKR_CANT_LOCK when needed to inform caller module isn\'t thread safe- Resolves: rhbz#555019 - [PEM] invalid writes in multi-threaded libcurl based application * Thu Nov 01 2012 Elio Maldonado - 3.14.0.0-7- Add dummy sources file to test for and prevent breaking rhpkg commands- Enable testing for \'rhpk upload\' and \'rhpk new-sources\' breakage such as hangs- Related: rhbz#837089 * Sun Oct 28 2012 Elio Maldonado - 3.14.0.0-6- Update the license to MPLv2.0- turn off the aia tests- Resolves: rhbz#837089 * Wed Oct 24 2012 Elio Maldonado - 3.14.0.0-5- Resolves: rhbz#702083 - NSS pem module should not require unique base file names * Sun Oct 21 2012 Elio Maldonado - 3.14.0.0-4- turn on the aia tests- update nss-589636.patch to apply to httpdserv * Fri Oct 12 2012 Kai Engert - 3.14.0.0-3- turn off aia tests for now * Fri Oct 12 2012 Bob Relyea - 3.14.0.0-2- turn off ocsp tests for now * Thu Oct 11 2012 Elio Maldonado - 3.14.0.0-1- Rebase to nss-3.14.0.0-1- Resolves: rhbz#837089- Update ssl-cbc-random-iv patch for new sources- Remove patches rendered obsoleted by rebase to 3.14- Add a patch to enforce no pkcs11 bypass * Sun Jun 24 2012 Elio Maldonado - 3.13.5-3- Resolves: rhbz#830302 - require nspr 4.9.1 * Thu Jun 21 2012 Elio Maldonado - 3.13.5-2- Resolves: rhbz#830302 - revert unwanted changes to nss.pc.in * Wed Jun 20 2012 Elio Maldonado - 3.13.5-1- Resolves: rhbz#830302 - Update RHEL 6.x to NSS 3.13.5 and NSPR 4.9.1 for Mozilla 10.0.6 * Mon Jun 04 2012 Elio Maldonado - 3.13.3-7- Resolves: rhbz#827351 invalid read and free on invalid cert load failure * Mon Apr 16 2012 Elio Maldonado - 3.13.3-6- Resolves: #rhbz#805232 PEM module may attempt to free uninitialized pointer * Fri Mar 16 2012 Elio Maldonado Batiz - 3.13.3-5- Resolves: rhbz#717913 - [PEM] various flaws detected by Coverity- Require nss-util 3.13.3 * Wed Mar 14 2012 Elio Maldonado Batiz - 3.13.3-4- Resolves: rhbz#772628 nss_Init leaks memory * Tue Mar 13 2012 Elio Maldonado - 3.13.3-3- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name- Use completed patch per code review * Tue Mar 13 2012 Elio Maldonado - 3.13.3-2- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name- Resolves: rhbz#768669 - PEM unregistered callback causes SIGSEGV * Mon Mar 05 2012 Elio Maldonado - 3.13.3-1- Update to 3.13.3- Resolves: rhbz#798539 - Distrust MITM subCAs issued by TrustWave- Remove builtins-nssckbi_1_88_rtm.patch which the rebase obsoletes * Tue Feb 28 2012 Elio Maldonado Batiz - 3.13.1-6- Resolves: rhbz#746632 - Adjust the patch for new sources * Tue Feb 28 2012 Elio Maldonado - 3.13.1-5- Resolves: rhbz#746632 - pem_CreateObject() leaks memory given a non-existing file name * Tue Feb 28 2012 Elio Maldonado - 3.13.1-4- Resolves: 784674 - Protect NSS_Shutdown from clients that fail to initialize nss * Mon Feb 20 2012 Elio Maldonado - 3.13.1-4- Add two needed patches- Resolves: rhbz#783315 - Need nss workaround for freebl bug that causes openswan to drop connections- Resolves: rhbz#747387 - Unable to contact LDAP Server during winsync * Mon Jan 30 2012 Martin Stransky 3.13.1-3- Rebuild * Sat Jan 28 2012 Elio Maldonado Batiz - 3.13.1-2- Resolves: Bug 784490 - CVE-2011-3389- Activate a patch that was left out in previous build * Tue Jan 24 2012 Elio Maldonado - 3.13.1-1- Resolves: Bug 744070 - Update to 3.13.1- Resolves: Bug 784674 - nss should protect against being called before nss_Init- Resolves: Bug 784490 - CVE-2011-3389 HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST) * Wed Dec 07 2011 Elio Maldonado - 3.12.10-17- Resolves: Bug 761086 - Fix nss-735047.patch to not revert the nss-bz689031.patch * Tue Nov 08 2011 Elio Maldonado - 3.12.10-16- Update builtins certs to those from NSSCKBI_1_88_RTM * Thu Oct 27 2011 Elio Maldonado - 3.12.10-15- Bug 747387 - Unable to contact LDAP Server during winsync * Wed Oct 19 2011 Elio Maldonado - 3.12.10-14- Add to the spec file the patch for Bug 671266 * Sun Oct 16 2011 Elio Maldonado - 3.12.10-13- More coverity related fixes in the pem module * Sun Oct 16 2011 Elio Maldonado - 3.12.10-12- Coverity related fixes * Tue Sep 27 2011 Elio Maldonado - 3.12.10-11- Add relro support for executables and shared libraries * Mon Sep 19 2011 Elio Maldonado - 3.12.10-10- Add partial RELRO support * Fri Sep 02 2011 Elio Maldonado - 3.12.10-9- Fix the name of the last patch file * Fri Sep 02 2011 Elio Maldonado - 3.12.10-8- Retagging to pick up two missing commits * Fri Sep 02 2011 Elio Maldonado - 3.12.10-7- Update builtins certs to those from NSSCKBI_1_87_RTM * Wed Aug 31 2011 Elio Maldonado - 3.12.10-6- Update builtins certs to those from NSSCKBI_1_86_RTM * Tue Aug 30 2011 Elio Maldonado - 3.12.10-5- Update builtins certs to those from NSSCKBI_1_85_RTM * Sun Aug 14 2011 Elio Maldonado - 3.12.10-4- Fix CMS to verify signed data when SignerInfo indicates signer by subjectKeyID * Fri Aug 12 2011 Elio Maldonado - 3.12.10-3- Fix pem logging to deal with files originally created by root * Mon Jul 11 2011 Elio Maldonado - 3.12.10-2- Retagging for updated patch missing from previous tag * Mon Jul 11 2011 Elio Maldonado - 3.12.10-1- Update to 3.12.10 * Thu Jun 23 2011 Elio Maldonado - 3.12.9-11- Resolves: rhbz# 703658 - Fix crmf hard-coded maximum size for wrapped private keys * Thu Jun 23 2011 Elio Maldonado - 3.12.9-10- Resolves: rhbz#688423 - Enable NSS support for pluggable ECC * Thu Apr 21 2011 Elio Maldonado Batiz - 3.12.9-9- Add \"Conflicts: curl < 7.19.7-26.el6\" to fix Bug 694663 * Thu Apr 07 2011 Elio Maldonado - 3.12.9-8- Construct private key nickname based on the full pathname of the pem file * Wed Apr 06 2011 Elio Maldonado - 3.12.9-7- Update expired PayPayEE.cert test certificate- Conditionalize some database tests on user not being root * Wed Mar 23 2011 Elio Maldonado - 3.12.9-6- Update to NSS_3.12.9_WITH_CKBI_1_82_RTM * Tue Mar 01 2011 Elio Maldonado - 3.12.9-5- Fix memory leaks caused by SECKEY_ImportDERPublicKey * Thu Feb 24 2011 Elio Maldonado - 3.12.9-4- Short-term fix for ssl test suites hangs on ipv6 type connections * Thu Feb 17 2011 Elio Maldonado - 3.12.9-3- Add requires for pkcs11-devel on nss-softokn-freebl devel- Run the test suites in check section per packaging guidelines * Sat Jan 22 2011 Elio Maldonado - 3.12.9-2- Prefer user database ca cert trust settings system\'s ones- Swap internal key slot on fips mode switches * Mon Jan 17 2011 Elio Maldonado - 3.12.9-1- Update to 3.12.9- Fix libnsspem to test for and reject directories * Sat Nov 27 2010 Elio Maldonado - 3.12.8-2- Add suppport for pkcs8 formatted keys in the pem module- Add verify(not md5 size mtime) to configuration files attributes- Prevent nss-sysinit disabling on package upgrade- Create pkcs11.txt with correct permissions regardless of current umask- Add option to setup-nsssysinit.sh to report nss-sysinit status- Update test certificate which had expired * Fri Oct 01 2010 Elio Maldonado - 3.12.8-1- Update to 3.12.8 * Fri Aug 27 2010 Kai Engert - 3.12.7-2- Increase release version number, no code changes * Thu Aug 26 2010 Elio Maldonado - 3.12.7-1- Update to 3.12.7 * Thu Aug 26 2010 Elio Maldonado - 3.12.6-6- Rebuilt * Thu Aug 26 2010 Elio Maldonado - 3.12.6-5- Appying the changes in previous log- Changing some BuildRequires to >= as well- Temporarily disabling all tests for faster builds * Thu Aug 26 2010 Elio Maldonado - 3.12.6-4- Change some = to >= in Requires to enable a rebase next * Mon Jun 07 2010 Elio Maldonado - 3.12.6-3- Fix SIGSEGV within CreateObject (#596783)- Update expired test certificate * Mon Mar 22 2010 Elio Maldonado - 3.12.6-2- Fix nss.pc to not require nss-softokn * Thu Mar 04 2010 Elio Maldonado - 3.12.6-1.2- rebuilt using nss-util 3.2.6 * Thu Mar 04 2010 Elio Maldonado - 3.12.6-1.1- rebuilt using nspr-devel 4.8.4 * Wed Mar 03 2010 Elio Maldonado - 3.12.6-1- Update to 3.12.6 * Wed Feb 24 2010 Elio Maldonado - 3.12.5.99-1- Update to NSS_3_12_6_RC1 * Mon Jan 25 2010 Elio Maldonado - 3.12.5-8- Fix curl related regression and general patch code clean up * Tue Jan 19 2010 Elio Maldonado - 3.12.5-7.3- Resolves: #551784 rebuilt after nss-softokn and nss-util builds- this will generate the coorect nss.spec * Sun Jan 17 2010 Elio Maldonado - 3.12.5-7.2- rebuilt for RHEL-6 candidate, Resolves: #551784 * Sun Jan 17 2010 Elio Maldonado - 3.12.5-7.1- Updated to 3.12.5 from CVS import from Fedora 12- Moved blank legacy databases to the lookaside cache- Reenabled the full test suite- Retagging for a RHEL-6-test-build * Wed Jan 13 2010 Elio Maldonado - 3.12.5-7- Retagged * Wed Jan 13 2010 Elio Maldonado - 3.12.5-6- retagging * Tue Jan 12 2010 Elio Maldonado - 3.12.5-2.1- Fix SIGSEGV on call of NSS_Initialize (#553638) * Wed Jan 06 2010 Elio Maldonado - 3.12.5-2- bump release number and rebuild * Wed Jan 06 2010 Elio Maldonado - 3.12.5-1.14- Fix nsssysinit to allow root to modify the nss system database (#547860) * Wed Jan 06 2010 Elio Maldonado - 3.12.5-1.12.1- Temporarily disabling the ssl tests until Bug 539183 is resolved * Fri Dec 25 2009 Elio Maldonado - 3.12.5-1.11- Fix an error introduced when adapting the patch for 546211 * Sat Dec 19 2009 Elio maldonado - 3.12.5-1.10- Remove some left over trace statements from nsssysinit patching * Thu Dec 17 2009 Elio Maldonado - 3.12.5-1.8- Fix nsssysinit to set the default flags on the crypto module (#545779)- Fix nsssysinit to enable apps to use the system cert store, patch contributed by David Woodhouse (#546221)- Fix segmentation fault when listing keys or certs in the database, patch contributed by Kamil Dudka (#540387)- Sysinit requires coreutils for post install scriplet (#547067)- Remove redundant header from the pem module * Wed Dec 09 2009 Elio Maldonado - 3.12.5-2.1- Remove unneeded patch * Fri Dec 04 2009 Elio Maldonado - 3.12.5-1.2- Update to 3.12.5- CVE-2009-3555 TLS: MITM attacks via session renegotiation * Mon Oct 26 2009 Elio Maldonado - 3.12.4-15- Require nss-softoken of same arch as nss (#527867) * Tue Oct 06 2009 Elio Maldonado - 3.12.4-14- Fix bug where user was prompted for a password when listing keys on an empty system database (#527048)- Fix setup-nsssysinit to handle more general flags formats (#527051) * Sun Sep 27 2009 Elio Maldonado - 3.12.4-12- Fix syntax error in setup-nsssysinit.sh * Sun Sep 27 2009 Elio Maldonado - 3.12.4-11- Fix sysinit to be under mozilla/security/nss/lib * Sat Sep 26 2009 Elio Maldonado - 3.12.4-10- Add nss-sysinit activation/deactivation script * Fri Sep 18 2009 Elio Maldonado* Thu Sep 10 2009 Elio Maldonado - 3.12.4-8- Restoring nssutil and -rpath-link to nss-config for now - 522477 * Tue Sep 08 2009 Elio Maldonado* Tue Sep 08 2009 Elio Maldonado - 3.12.4-6- Installing shared libraries to %{_libdir} * Mon Sep 07 2009 Elio Maldonado - 3.12.4-5- Retagging to pick up new sources * Mon Sep 07 2009 Elio Maldonado - 3.12.4-4- Update pem enabling source tar with latest fixes (509705, 51209) * Sun Sep 06 2009 Elio Maldonado - 3.12.4-3- PEM module implements memory management for internal objects - 509705- PEM module doesn\'t crash when processing malformed key files - 512019 * Sat Sep 05 2009 Elio Maldonado - 3.12.4-2- Remove symbolic links to shared libraries from devel - 521155- No rpath-link in nss-softokn-config * Tue Sep 01 2009 Elio Maldonado - 3.12.4-1- Update to 3.12.4 * Mon Aug 31 2009 Elio Maldonado - 3.12.3.99.3-30- Fix FORTIFY_SOURCE buffer overflows in test suite on ppc and ppc64 - bug 519766- Fixed requires and buildrequires as per recommendations in spec file review * Sun Aug 30 2009 Elio Maldonado - 3.12.3.99.3-29- Restoring patches 2 and 7 as we still compile all sources- Applying the nss-nolocalsql.patch solves nss-tools sqlite dependency problems * Sun Aug 30 2009 Elio Maldonado - 3.12.3.99.3-28- restore require sqlite * Sat Aug 29 2009 Elio Maldonado - 3.12.3.99.3-27- Don\'t require sqlite for nss * Sat Aug 29 2009 Elio Maldonado - 3.12.3.99.3-26- Ensure versions in the requires match those used when creating nss.pc * Fri Aug 28 2009 Elio Maldonado - 3.12.3.99.3-25- Remove nss-prelink.conf as signed all shared libraries moved to nss-softokn- Add a temprary hack to nss.pc.in to unblock builds * Fri Aug 28 2009 Warren Togami - 3.12.3.99.3-24- caolan\'s nss.pc patch * Thu Aug 27 2009 Elio Maldonado - 3.12.3.99.3-23- Bump the release number for a chained build of nss-util, nss-softokn and nss * Thu Aug 27 2009 Elio Maldonado - 3.12.3.99.3-22- Fix nss-config not to include nssutil- Add BuildRequires on nss-softokn and nss-util since build also runs the test suite * Thu Aug 27 2009 Elio Maldonado - 3.12.3.99.3-21- disabling all tests while we investigate a buffer overflow bug * Thu Aug 27 2009 Elio Maldonado - 3.12.3.99.3-20- disabling some tests while we investigate a buffer overflow bug - 519766 * Thu Aug 27 2009 Elio Maldonado - 3.12.3.99.3-19- remove patches that are now in nss-softokn and- remove spurious exec-permissions for nss.pc per rpmlint- single requires line in nss.pc.in * Wed Aug 26 2009 Elio Maldonado - 3.12.3.99.3-18- Fix BuildRequires: nss-softokn-devel release number * Wed Aug 26 2009 Elio Maldonado* Tue Aug 25 2009 Dennis Gilmore - 3.12.3.99.3-16- cleanups for softokn * Tue Aug 25 2009 Dennis Gilmore - 3.12.3.99.3-15- remove the softokn subpackages * Mon Aug 24 2009 Dennis Gilmore - 3.12.3.99.3-14- don install the nss-util pkgconfig bits * Mon Aug 24 2009 Dennis Gilmore - 3.12.3.99.3-13- remove from -devel the 3 headers that ship in nss-util-devel * Mon Aug 24 2009 Dennis Gilmore - 3.12.3.99.3-12- kill off the nss-util nss-util-devel subpackages * Sun Aug 23 2009 Elio Maldonado+emaldonaAATTredhat.com - 3.12.3.99.3-11- split off nss-softokn and nss-util as subpackages with their own rpms- first phase of splitting nss-softokn and nss-util as their own packages * Thu Aug 20 2009 Elio Maldonado - 3.12.3.99.3-10- must install libnssutil3.since nss-util is untagged at the moment- preserve time stamps when installing various files * Thu Aug 20 2009 Dennis Gilmore - 3.12.3.99.3-9- dont install libnssutil3.so since its now in nss-util * Thu Aug 06 2009 Elio Maldonado - 3.12.3.99.3-7.1- Fix spec file problems uncovered by Fedora_12_Mass_Rebuild * Sat Jul 25 2009 Fedora Release Engineering - 3.12.3.99.3-7- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Mon Jun 22 2009 Elio Maldonado - 3.12.3.99.3-6- removed two patch files which are no longer needed and fixed previous change log number * Mon Jun 22 2009 Elio Maldonado - 3.12.3.99.3-5- updated pem module incorporates various patches- fix off-by-one error when computing size to reduce memory leak. (483855)- fix data type to work on x86_64 systems. (429175)- fix various memory leaks and free internal objects on module unload. (501080)- fix to not clone internal objects in collect_objects(). (501118)- fix to not bypass initialization if module arguments are omitted. (501058)- fix numerous gcc warnings. (500815)- fix to support arbitrarily long password while loading a private key. (500180) - fix memory leak in make_key and memory leaks and return values in pem_mdSession_Login (501191) * Mon Jun 08 2009 Elio Maldonado - 3.12.3.99.3-4- add patch for bug 502133 upstream bug 496997 * Fri Jun 05 2009 Kai Engert - 3.12.3.99.3-3- rebuild with higher release number for upgrade sanity * Fri Jun 05 2009 Kai Engert - 3.12.3.99.3-2- updated to NSS_3_12_4_FIPS1_WITH_CKBI_1_75 * Thu May 07 2009 Kai Engert - 3.12.3-7- re-enable test suite- add patch for upstream bug 488646 and add newer paypal certs in order to make the test suite pass * Wed May 06 2009 Kai Engert - 3.12.3-4- add conflicts info in order to fix bug 499436 * Tue Apr 14 2009 Kai Engert - 3.12.3-3- ship .chk files instead of running shlibsign at install time- include .chk file in softokn-freebl subpackage- add patch for upstream nss bug 488350 * Tue Apr 14 2009 Kai Engert - 3.12.3-2- Update to NSS 3.12.3 * Mon Apr 06 2009 Kai Engert - 3.12.2.99.3-7- temporarily disable the test suite because of bug 494266 * Mon Apr 06 2009 Kai Engert - 3.12.2.99.3-6- fix softokn-freebl dependency for multilib (bug 494122) * Thu Apr 02 2009 Kai Engert - 3.12.2.99.3-5- introduce separate nss-softokn-freebl package * Thu Apr 02 2009 Kai Engert - 3.12.2.99.3-4- disable execstack when building freebl * Tue Mar 31 2009 Kai Engert - 3.12.2.99.3-3- add upstream patch to fix bug 483855 * Tue Mar 31 2009 Kai Engert - 3.12.2.99.3-2- build nspr-less freebl library * Tue Mar 31 2009 Kai Engert - 3.12.2.99.3-1- Update to NSS_3_12_3_BETA4 * Wed Feb 25 2009 Fedora Release Engineering - 3.12.2.0-4- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Wed Oct 22 2008 Kai Engert - 3.12.2.0-3- update to NSS_3_12_2_RC1- use system zlib * Tue Sep 30 2008 Dennis Gilmore - 3.12.1.1-4- add sparc64 to the list of 64 bit arches * Wed Sep 24 2008 Kai Engert - 3.12.1.1-3- bug 456847, move pkgconfig requirement to devel package * Fri Sep 05 2008 Kai Engert - 3.12.1.1-2- Update to NSS_3_12_1_RC2 * Fri Aug 22 2008 Kai Engert - 3.12.1.0-2- NSS 3.12.1 RC1 * Fri Aug 15 2008 Kai Engert - 3.12.0.3-7- fix bug bug 429175 in libpem module * Tue Aug 05 2008 Kai Engert - 3.12.0.3-6- bug 456847, add Requires: pkgconfig * Tue Jun 24 2008 Kai Engert - 3.12.0.3-3- nss package should own /etc/prelink.conf.d folder, rhbz#452062- use upstream patch to fix test suite abort * Mon Jun 02 2008 Kai Engert - 3.12.0.3-2- Update to NSS_3_12_RC4 * Mon Apr 14 2008 Kai Engert - 3.12.0.1-1- Update to NSS_3_12_RC2 * Thu Mar 20 2008 Jesse Keating - 3.11.99.5-2- Zapping old Obsoletes/Provides. No longer needed, causes multilib headache. * Mon Mar 17 2008 Kai Engert - 3.11.99.5-1- Update to NSS_3_12_BETA3 * Fri Feb 22 2008 Kai Engert - 3.11.99.4-1- NSS 3.12 Beta 2- Use /usr/lib{64} as devel libdir, create symbolic links. * Sat Feb 16 2008 Kai Engert - 3.11.99.3-6- Apply upstream patch for bug 417664, enable test suite on pcc. * Fri Feb 15 2008 Kai Engert - 3.11.99.3-5- Support concurrent runs of the test suite on a single build host. | |