Open
Bug 1930807
Opened 4 months ago
Updated 2 days ago
NSS policy updates
Categories
(NSS :: Libraries, defect, P3)
NSS
Libraries
Tracking
(Not tracked)
NEW
People
(Reporter: rrelyea, Assigned: rrelyea)
References
(Depends on 1 open bug, Blocks 1 open bug)
Details
Attachments
(3 files)
The following changes to our policy code from RHEL needs to be picked up:
Various policy tests are failing because the test case is wrong, but the tests weren't run because the tests were triggered on SDB mode, which isn't used anymore upstream because we no longer test dbm code (disabled by default). dbm code is still enabled and tested in some versions of RHEL.
KeySize checks were missing in RSA-PSS.
Cavs tests were failing on rhel-10 because of changes to the output of sum.
Updated•3 months ago
|
Severity: -- → S3
Priority: -- → P3
Assignee | ||
Comment 1•2 months ago
|
||
- The policy tests aren't running in the CI, update the way we determine that we are using sql db.
1a. Add a new utility to get NSS default values to support getting sqldb state. - turn off key size policy for the weak key tests.
- Make SECKEY_PrivateKeyStrengthInBits more accurate in the normal case.
- Add key length policy enforcements to RSAPss on SSL.
- Fix problem where ASN1 decoder is clobbering the error message, leading to DER errors when the real reason is policy issues.
- Fix errors in the policy tests that were masked by the fact they weren't being run in the CI
Assignee | ||
Comment 2•2 months ago
|
||
sum has changed formats on newer versions of linux, change the awk to fetch the correct value.
Assignee | ||
Comment 3•2 months ago
|
||
- Make SECKEY_PrivateKeyStrengthInBits more accurate in the normal case.
- Add key length policy enforcements to RSAPss on SSL.
You need to log in
before you can comment on or make changes to this bug.
Description
•