Closed Bug 1779234 Opened 2 years ago Closed 2 years ago

ECH (Retry-)Config bugs

Categories

(NSS :: Libraries, defect, P1)

3.80

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: lschwarz, Assigned: lschwarz)

References

(Blocks 1 open bug)

Details

Attachments

(1 file)

  • NSS client does not check that server ECH extensions containing retry configs are only allowed in the EncryptedExtensions message (and therefore can only be sent by TLS > 1.3 servers).

  • NSS client does not check if a server illegally sent an ECH extension containing retry configs even though it accepted ECH.

  • NSS fails when setting an ECH config containing an unsupported mandatory extensions instead of just skipping it and trying to set possible further extensions.

Status: NEW → ASSIGNED
Blocks: ech
Blocks: 1781224
No longer blocks: 1781224

The severity field is not set for this bug.
:beurdouche, could you have a look please?

For more information, please visit auto_nag documentation.

Flags: needinfo?(bbeurdouche)
Severity: -- → S4
Flags: needinfo?(bbeurdouche)
Priority: -- → P1

There's a r+ patch which didn't land and no activity in this bug for 2 weeks.
:lschwarz, could you have a look please?
If you still have some work to do, you can add an action "Plan Changes" in Phabricator.
For more information, please visit auto_nag documentation.

Flags: needinfo?(lschwarz)
Flags: needinfo?(djackson)
Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Flags: needinfo?(djackson)
Resolution: --- → FIXED
Flags: needinfo?(lschwarz)
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: