NSS 3.122.1: invalid DTLS CertificateVerify signature breaks Firefox WebRTC to pion and webrtc-rs servers
Categories
(NSS :: Libraries, defect, P1)
Tracking
(nss+ 3.124, firefox-esr115 unaffected, firefox-esr140150.0.1+ fixed, firefox150+ fixed, firefox151+ fixed, firefox152+ fixed)
People
(Reporter: marcin.p.porebski, Assigned: jschanck)
References
(Regression)
Details
(Keywords: regression)
Attachments
(2 files)
User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:149.0) Gecko/20100101 Firefox/149.0
Steps to reproduce:
Additional context:
NSS 3.122 works as expected.
These issues start in NSS 3.122.1 and are present in NSS 3.123 as well.
Setting Firefox pref to "media.peerconnection.dtls.version.max": 771," seems to mitigate the issue in NSS >3.122.
Reproduction steps:
- Clone pion:
git clone https://github.com/pion/webrtc
cd webrtc
git checkout f857501780d23284038ca94c2d6a7ee02dda41fe
- Apply this patch to
examples/data-channels/main.goto force pion into passive DTLS role (DTLS server) and pin ephemeral UDP port to 3478 for easier pcap capture:
diff --git a/examples/data-channels/main.go b/examples/data-channels/main.go
index 60e2a4a6..89828301 100644
--- a/examples/data-channels/main.go
+++ b/examples/data-channels/main.go
@@ -32,8 +32,17 @@ func main() {
},
}
+ settingEngine := webrtc.SettingEngine{}
+ if err := settingEngine.SetAnsweringDTLSRole(webrtc.DTLSRoleServer); err != nil {
+ panic(err)
+ }
+ if err := settingEngine.SetEphemeralUDPPortRange(3478, 3478); err != nil {
+ panic(err)
+ }
+ api := webrtc.NewAPI(webrtc.WithSettingEngine(settingEngine))
+
// Create a new RTCPeerConnection
- peerConnection, err := webrtc.NewPeerConnection(config)
+ peerConnection, err := api.NewPeerConnection(config)
if err != nil {
panic(err)
}
- Build and run the example:
cd examples/data-channels
go build
./data-channels
-
Go to this jsfiddle page on Firefox:
https://jsfiddle.net/e41tgovp/ -
Copy browser SDP to clipboard and paste it into stdin of running data-channels example
-
Copy SDP that was printed by the data-channels binary over to the browser and click "Start Session"
Actual results:
data-channels bin prints
Peer Connection State has changed: failed
Peer Connection has gone to failed exiting
and packet capture shows:
DTLSv1.2 57 Alert (Level: Fatal, Description: Bad Certificate)
and CH2 is different than CH1 (e.g. cipher suites differ - there's less of them in CH2) which I think breaks DTLS 1.2 RFC as well
Expected results:
data-channels bin prints
Peer Connection State has changed: connected
New DataChannel foo 60696656497734
Data channel 'foo'-'60696656497734' open. Random messages will now be sent to any connected DataChannels every 5 seconds
and packet capture shows full (not-stripped) CH2 (+ no Bad Certificate alert)
| Assignee | ||
Updated•5 months ago
|
| Assignee | ||
Updated•5 months ago
|
| Assignee | ||
Comment 1•5 months ago
|
||
| Assignee | ||
Updated•5 months ago
|
| Assignee | ||
Comment 3•5 months ago
|
||
[Tracking Requested - why for this release]: The patch for Bug 1935995 was included in NSS 3.90.6 (ESR 115), 3.112.4 (ESR 140), 3.122.1 (Fx 150), and 3.123 (Fx 151). ESR 115 is not affected because DTLS 1.3 had not yet been enabled by default. The other branches are affected. This is probably not a dot release driver. We have Nimbus control over DTLS 1.3 which could be used to reduce the amount of breakage that users experience while we wait for appropriate dot releases for this to ride on.
| Assignee | ||
Comment 4•5 months ago
|
||
[Tracking Requested - why for this release]:
Can we have a new NSS version tagged that includes the fix? Asking for a friend(ly distribution).
Comment 6•5 months ago
|
||
We're planning to build dot releases for 150 and ESR140 next Monday (the 27th). Any chance we could have new NSS releases ready in time for those?
| Assignee | ||
Comment 7•5 months ago
|
||
Yes, I'll cut NSS dot releases no later than Thursday this week.
Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/2d96cee5f461
reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max. r=nss-reviewers,nkulatova
Updated•5 months ago
|
Comment 10•5 months ago
|
||
The patch landed in nightly and beta is affected.
:jschanck, is this bug important enough to require an uplift?
- If yes, please nominate the patch for beta approval.
- See https://wiki.mozilla.org/Release_Management/Requesting_an_Uplift for documentation on how to request an uplift.
- If no, please set
status-firefox151towontfix.
For more information, please visit BugBot documentation.
Comment 11•5 months ago
|
||
Comment 12•5 months ago
|
||
Comment 13•5 months ago
|
||
Updated•5 months ago
|
Updated•5 months ago
|
Description
•