Bug 1059682
Summary: | Default cipher ordering doesn't include ECDSA ciphers and doesn't follow current best practice | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 6 | Reporter: | Hubert Kario <hkario> | ||||||||||||
Component: | nss | Assignee: | Elio Maldonado Batiz <emaldona> | ||||||||||||
Status: | CLOSED ERRATA | QA Contact: | Hubert Kario <hkario> | ||||||||||||
Severity: | high | Docs Contact: | Aneta Šteflová Petrová <apetrova> | ||||||||||||
Priority: | high | ||||||||||||||
Version: | 6.5 | CC: | dapospis, hkario, jkurik, mmckinst, nkinder, rrelyea, weeks | ||||||||||||
Target Milestone: | rc | ||||||||||||||
Target Release: | --- | ||||||||||||||
Hardware: | Unspecified | ||||||||||||||
OS: | Unspecified | ||||||||||||||
Whiteboard: | |||||||||||||||
Fixed In Version: | nss-3.21.0-2.el6 | Doc Type: | Release Note | ||||||||||||
Doc Text: |
_nss_ now supports ECDSA certificates
By default, the NSS library did not enable TLS cipher suites that use Elliptic Curve Cryptography (ECC). Applications that did not change the NSS default configuration were unable to connect to servers that mandated support for ECC key exchange, such as ECDHE. In particular, connecting to servers that use certificates with ECDSA keys failed.
This update changes the default configuration to enable TLS cipher suites that allow using ECC by default. As a result, applications using NSS defaults for communication over TLS can now connect to servers that use certificates with ECDSA keys.
|
Story Points: | --- | ||||||||||||
Clone Of: | 1059670 | Environment: | |||||||||||||
Last Closed: | 2016-05-10 21:08:25 UTC | Type: | Bug | ||||||||||||
Regression: | --- | Mount Type: | --- | ||||||||||||
Documentation: | --- | CRM: | |||||||||||||
Verified Versions: | Category: | --- | |||||||||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||||||||
Embargoed: | |||||||||||||||
Bug Depends On: | 1058767, 1059670 | ||||||||||||||
Bug Blocks: | 1057564 | ||||||||||||||
Attachments: |
|
Description
Hubert Kario
2014-01-30 10:58:41 UTC
To be clear, what hubert is asking for is a change in what NSS enables by default. NOTE: Brian smith's list is two things: 1) what the default cipher order is for NSS. 2) what the default ciphers are that mozilla enables. The default cipher order should happen upstream (If firefox has a new order, then a new upstream version of NSS will have that order). The default cipher list is something we can handle either upstream or in redhat (that would be a relatively small patch. I support Huberts call to make this change, but we should get a comment from RHEL 6 release management. It means a semantic change in RHEL 6 (apps would suddenly start using new ciphers they didn't previously use). We aren't turning any ciphers off, so I think this should be OK. This bug subject 'Default cipher ordering doesn't include ECDSA ciphers and doesn't follow current best practice' has to two parts: 1) Enabling the ECDSA ciphers by default - No problem here. 2) Following current best practice - Problematic and it requires a reordering such as was done upstream and what we did for rhel-7. At first I thought it would be would be a subset of what we did in rhel-7. The problem is that reordering would case a regression on Bug 1159926 where we had to introduce a patch to revert the changes done upstream and keep the table with same order of cipher suites as in nss-3.15.5-3. Created attachment 1115485 [details]
Enable ECDSA ciphers by the default
Backport to nss-3.19.1 of what I comitted upstream for nss-3.21.
Created attachment 1115486 [details]
Enable ECDSA ciphers with 3DES by the default
This part was not suitable upstream abut we included as a local patch in fedora. The second change is RSA and maybe dropped given that this request is for ECDSA.
Created attachment 1115487 [details]
Changes to nss.spec - in patch format
Assuming we only have the two patches for enabling which don't do reordering.
(In reply to Elio Maldonado Batiz from comment #4) >> is that reordering would case a regression on Bug 1159926 where we had to Correction: The bug in question is actually Bug 1123092 Comment on attachment 1115485 [details]
Enable ECDSA ciphers by the default
Patch no longer needed because we rebased to nss-3.21.0 which has these ciphers enabled by default.
Comment on attachment 1115487 [details]
Changes to nss.spec - in patch format
Mot needed, the spec file changed with the rebase to NSS 3.21.
Created attachment 1135043 [details]
ssl differences beetween rhel-6.7.z and rhel-6.8 - in patch format
The lib/ssl differences beetween rhel-6.7.z and rhel-6.8 after all patches have been applied.
OK, we only need to turn off AES GCM 128 by default then. Comment on attachment 1115486 [details]
Enable ECDSA ciphers with 3DES by the default
r+
Comment on attachment 1135043 [details]
ssl differences beetween rhel-6.7.z and rhel-6.8 - in patch format
based on the regression, let's turn AES_GCM_128 off by default in 6.8. The rest of the patch is fine.
Created attachment 1135069 [details] disables AES_GCM_128 ciphers by default as suggested in Comment 19 Problem is, that to fix bug 1123092, we would have to disable also TLS_RSA_WITH_AES_128_GCM_SHA256, which was enabled quite far back. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2016-0820.html |