Closed
Bug 1930807
Opened 1 year ago
Closed 1 year ago
NSS policy updates
Categories
(NSS :: Libraries, defect, P3)
NSS
Libraries
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: rrelyea, Assigned: rrelyea)
References
(Depends on 1 open bug)
Details
Attachments
(3 files)
The following changes to our policy code from RHEL needs to be picked up:
Various policy tests are failing because the test case is wrong, but the tests weren't run because the tests were triggered on SDB mode, which isn't used anymore upstream because we no longer test dbm code (disabled by default). dbm code is still enabled and tested in some versions of RHEL.
KeySize checks were missing in RSA-PSS.
Cavs tests were failing on rhel-10 because of changes to the output of sum.
Updated•1 year ago
|
Severity: -- → S3
Priority: -- → P3
| Assignee | ||
Comment 1•1 year ago
|
||
- The policy tests aren't running in the CI, update the way we determine that we are using sql db.
1a. Add a new utility to get NSS default values to support getting sqldb state. - turn off key size policy for the weak key tests.
- Make SECKEY_PrivateKeyStrengthInBits more accurate in the normal case.
- Add key length policy enforcements to RSAPss on SSL.
- Fix problem where ASN1 decoder is clobbering the error message, leading to DER errors when the real reason is policy issues.
- Fix errors in the policy tests that were masked by the fact they weren't being run in the CI
| Assignee | ||
Comment 2•1 year ago
|
||
sum has changed formats on newer versions of linux, change the awk to fetch the correct value.
| Assignee | ||
Comment 3•1 year ago
|
||
- Make SECKEY_PrivateKeyStrengthInBits more accurate in the normal case.
- Add key length policy enforcements to RSAPss on SSL.
| Assignee | ||
Updated•1 year ago
|
Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Comment 4•1 year ago
•
|
||
You need to log in
before you can comment on or make changes to this bug.
Description
•