It's not released yet, but eventually we will have to upgrade Mozilla to NSS 3.13.4 final. Here is one motiviation why we might want to do so for Firefox 14, prior to April 24: - Firefox 14 will disable MD5 signatures by default - our current user feedback on affected SSL sites is not helpful - bug 738454 (target NSS 3.13.4) implements a better error code for "disabled by policy" Once this bug is resolved (Mozilla updated to 3.13.4) we'll also need to land 738457 into Mozilla application (PSM), for the user feedback to become effective.
As there will probably be an additional update 3.13.4, which will not yet cover the md5 related work, I'm moving this tracking bug to 3.13.5
Created attachment 617730 [details] upgrade action (placeholder)
Comment on attachment 617730 [details] upgrade action (placeholder) r=wtc.
I'll land the NSS_3_13_5_BETA1 tag. We must keep this open until we land the final release.
landed beta1 into mozilla-central: https://hg.mozilla.org/integration/mozilla-inbound/rev/d22635f771c5
Is this still necessary for FF14 if we're no longer disabling MD5 signatures for that release?
(In reply to Alex Keybl [:akeybl] from comment #7) > Is this still necessary for FF14 if we're no longer disabling MD5 signatures > for that release? If you backout 650355 for FF14: no, not necessary for MD5. But what about bug 745548 ?
Can I please get a r+ (in a comment) for landing beta2 into mozilla-central? Thanks.
r+ on landing beta2 in mozilla-central.
Kai: please push NSS_3_13_5_BETA2 to mozilla-central.
(only difference between beta1 and beta2 was fix for bug 745548.)
(In reply to Kai Engert (:kaie) from comment #12) > landed beta 2: > https://hg.mozilla.org/integration/mozilla-inbound/rev/bb67b169df15 https://hg.mozilla.org/mozilla-central/rev/bb67b169df15
I've checked in the final NSS 3.13.5. https://hg.mozilla.org/integration/mozilla-inbound/rev/5eb0d9e63d5a The only functional change since the beta version was: - a one letter typo in an error string - final version number However, some of the files which belong to NSS, which are copied into mozilla-central, have been modified in mozilla-central to use the MPL2. My change reverts these few license headers to the old tri-license, which is what most of NSS still uses (on this particular stable branch). IMHO that shouldn't be a problem, the license headers will be changed to MPL2 when Mozilla picks up a more recent version of NSS where Gerv has applied the MPL2 headers everywhere.
Sorry, reopening, must wait until inbound has been merged to central.
Kai: that's not a problem, but can you tell me which files those are, so I can check if my script is faulty? Thanks, Gerv
(In reply to Gervase Markham [:gerv] from comment #17) > Kai: that's not a problem, but can you tell me which files those are, so I > can check if my script is faulty? yes, see the commit in coment 15
(In reply to Kai Engert (:kaie) from comment #18) > (In reply to Gervase Markham [:gerv] from comment #17) > > Kai: that's not a problem, but can you tell me which files those are, so I > > can check if my script is faulty? > > yes, see the commit in coment 15 Note that your script might have worked fine on NSS trunk. The cause for this (temporary) reversion (on mozilla-central) is that we still do some work on a separate stable NSS branch.
Proposing for ESR 10.0.6, in order to pick up bug 745548. ESR10 branch already uses NSS 3.13.4. An upgrade to NSS 3.13.5 is a very small change.
Proposing for Firefox 14/Beta, in order to pick up bug 745548. Beta already uses NSS 3.13.4. An upgrade to NSS 3.13.5 is a very small change.
Created attachment 631489 [details] [diff] [review] upgrade action to 3.13.5 final (placeholder)
Comment on attachment 631489 [details] [diff] [review] upgrade action to 3.13.5 final (placeholder) [Triage Comment] Approved for Beta and ESR, given bug 745548.
(In reply to Kai Engert (:kaie) from comment #25) > https://hg.mozilla.org/releases/mozilla-beta/rev/853ac25ddd18 This commit accidentally landed into a release branch. I've backed it out from the release branch: https://hg.mozilla.org/releases/mozilla-beta/rev/87828c8651c6 I hope the following is the correct landing on mozilla-beta "default" branch: https://hg.mozilla.org/releases/mozilla-beta/rev/cc5c3ee63206
Verified fixed by checking hg.mozilla.org: ESR: http://hg.mozilla.org/releases/mozilla-esr10/file/tip/security/nss/TAG-INFO Fx14: http://hg.mozilla.org/releases/mozilla-beta/file/tip/security/nss/TAG-INFO Fx15: http://hg.mozilla.org/releases/mozilla-aurora/file/tip/security/nss/TAG-INFO