Bug 1204404
| Summary: | Flaws in the disabling of SSL2 may break future versions of Firefox | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Elio Maldonado Batiz <emaldona> |
| Component: | nss | Assignee: | Elio Maldonado Batiz <emaldona> |
| Status: | CLOSED DUPLICATE | QA Contact: | BaseOS QE Security Team <qe-baseos-security> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 7.2 | CC: | hkario, kengert, ksrot, nkinder, rrelyea, stransky |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | nss-3.18.0-1.el7 | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2015-09-02 19:26:14 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Elio Maldonado Batiz
2015-03-21 17:51:43 UTC
Another problem found is that though SSL2 was disabled the export cipher suites weren't. We need to bring those fixes back to RHEL-7. Hmm why weren't we seeing this in RHEL 7? Lots of things call NSS_SetDomesticPolicy(). Are we not failing when we try to set SSL2 in RHEL7 (which may be what I recommended to have minimal impact to applications). bob Bug 1123435 and this one are closely related. Fixes applied as part of work for rebasing nss to 3.18 for Firefox 38 ESR - Bug 1200898. changes pushed to git: http://pkgs.devel.redhat.com/cgit/rpms/nss/commit/?h=rhel-7.2&id=2de7324289c8efca7be7fde403fc2a6308e636d8 Since then fix has evolved and this bug should be closed as duplicate of Bug 1123435 which has a more comprehensive fix. *** This bug has been marked as a duplicate of bug 1123435 *** |