Closed Bug 2033783 Opened 5 months ago Closed 5 months ago

NSS 3.122.1: invalid DTLS CertificateVerify signature breaks Firefox WebRTC to pion and webrtc-rs servers

Categories

(NSS :: Libraries, defect, P1)

Tracking

(nss+ 3.124, firefox-esr115 unaffected, firefox-esr140150.0.1+ fixed, firefox150+ fixed, firefox151+ fixed, firefox152+ fixed)

RESOLVED FIXED
Tracking Status
nss + 3.124
firefox-esr115 --- unaffected
firefox-esr140 150.0.1+ fixed
firefox150 + fixed
firefox151 + fixed
firefox152 + fixed

People

(Reporter: marcin.p.porebski, Assigned: jschanck)

References

(Regression)

Details

(Keywords: regression)

Attachments

(2 files)

User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:149.0) Gecko/20100101 Firefox/149.0

Steps to reproduce:

Additional context:
NSS 3.122 works as expected.
These issues start in NSS 3.122.1 and are present in NSS 3.123 as well.

Setting Firefox pref to "media.peerconnection.dtls.version.max": 771," seems to mitigate the issue in NSS >3.122.

Reproduction steps:

  1. Clone pion:
git clone https://github.com/pion/webrtc
cd webrtc
git checkout f857501780d23284038ca94c2d6a7ee02dda41fe
  1. Apply this patch to examples/data-channels/main.go to force pion into passive DTLS role (DTLS server) and pin ephemeral UDP port to 3478 for easier pcap capture:
diff --git a/examples/data-channels/main.go b/examples/data-channels/main.go
index 60e2a4a6..89828301 100644
--- a/examples/data-channels/main.go
+++ b/examples/data-channels/main.go
@@ -32,8 +32,17 @@ func main() {
 		},
 	}
 
+	settingEngine := webrtc.SettingEngine{}
+	if err := settingEngine.SetAnsweringDTLSRole(webrtc.DTLSRoleServer); err != nil {
+		panic(err)
+	}
+	if err := settingEngine.SetEphemeralUDPPortRange(3478, 3478); err != nil {
+		panic(err)
+	}
+	api := webrtc.NewAPI(webrtc.WithSettingEngine(settingEngine))
+
 	// Create a new RTCPeerConnection
-	peerConnection, err := webrtc.NewPeerConnection(config)
+	peerConnection, err := api.NewPeerConnection(config)
 	if err != nil {
 		panic(err)
 	}
  1. Build and run the example:
cd examples/data-channels
go build
./data-channels
  1. Go to this jsfiddle page on Firefox: https://jsfiddle.net/e41tgovp/

  2. Copy browser SDP to clipboard and paste it into stdin of running data-channels example

  3. Copy SDP that was printed by the data-channels binary over to the browser and click "Start Session"

Actual results:

data-channels bin prints

Peer Connection State has changed: failed
Peer Connection has gone to failed exiting

and packet capture shows:

DTLSv1.2 57 Alert (Level: Fatal, Description: Bad Certificate)

and CH2 is different than CH1 (e.g. cipher suites differ - there's less of them in CH2) which I think breaks DTLS 1.2 RFC as well

Expected results:

data-channels bin prints

Peer Connection State has changed: connected
New DataChannel foo 60696656497734
Data channel 'foo'-'60696656497734' open. Random messages will now be sent to any connected DataChannels every 5 seconds

and packet capture shows full (not-stripped) CH2 (+ no Bad Certificate alert)

See Also: → 2033288
Assignee: nobody → jschanck
Severity: -- → S2
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Priority: -- → P1
Keywords: regression
Regressed by: 1935995
tracking-nss: --- → +
Duplicate of this bug: 2033288

[Tracking Requested - why for this release]: The patch for Bug 1935995 was included in NSS 3.90.6 (ESR 115), 3.112.4 (ESR 140), 3.122.1 (Fx 150), and 3.123 (Fx 151). ESR 115 is not affected because DTLS 1.3 had not yet been enabled by default. The other branches are affected. This is probably not a dot release driver. We have Nimbus control over DTLS 1.3 which could be used to reduce the amount of breakage that users experience while we wait for appropriate dot releases for this to ride on.

[Tracking Requested - why for this release]:

Can we have a new NSS version tagged that includes the fix? Asking for a friend(ly distribution).

We're planning to build dot releases for 150 and ESR140 next Monday (the 27th). Any chance we could have new NSS releases ready in time for those?

Yes, I'll cut NSS dot releases no later than Thursday this week.

Flags: needinfo?(jschanck)
Duplicate of this bug: 2034021
Blocks: 2034186
Blocks: 2034189
Blocks: 2034190

Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/2d96cee5f461
reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max. r=nss-reviewers,nkulatova

Status: ASSIGNED → RESOLVED
Closed: 5 months ago
Resolution: --- → FIXED
Blocks: 2034204
See Also: 2033288 →
Blocks: 2032610

The patch landed in nightly and beta is affected.
:jschanck, is this bug important enough to require an uplift?

For more information, please visit BugBot documentation.

Flags: needinfo?(jschanck)
Pushed by jschanck@mozilla.com: https://hg.mozilla.org/projects/nss/rev/d9936b8c645a reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max. r=nss-reviewers,nkulatova
Pushed by jschanck@mozilla.com: https://hg.mozilla.org/projects/nss/rev/24b097ffc57f reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max. r=nss-reviewers,nkulatova
Pushed by jschanck@mozilla.com: https://hg.mozilla.org/projects/nss/rev/b4b3bf710966 reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max. r=nss-reviewers,nkulatova
Duplicate of this bug: 2034469
Flags: needinfo?(jschanck)
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: