Key wrapping does inadvisable things with keys

NEW
Unassigned

Status

NSS
Libraries
P3
normal
2 years ago
3 months ago

People

(Reporter: mt, Unassigned)

Tracking

trunk

Firefox Tracking Flags

(firefox47 affected)

Details

(Reporter)

Description

2 years ago
getWrappingKey in ssl3con.c doesn't respect modern rules regarding single use of keys.  It appears as though an ECDSA key is used with ECDH.  RSA signing keys are used to encrypt.

See also Bug 421389.

Updated

a year ago
See Also: → bug 1289259
(Reporter)

Updated

a year ago
See Also: → bug 1325035
Priority: -- → P3
You need to log in before you can comment on or make changes to this bug.