Bug 1141105 - Use ECC ciphers by default
Summary: Use ECC ciphers by default
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: mod_nss
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: ---
Assignee: Matthew Harmsen
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-09-12 08:39 UTC by Adam Williamson
Modified: 2016-07-19 19:32 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2016-07-19 19:30:26 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
patch to use ECC cipher suite by default (4.30 KB, text/plain)
2014-09-12 08:39 UTC, Adam Williamson
no flags Details

Description Adam Williamson 2014-09-12 08:39:04 UTC
Created attachment 936872 [details]
patch to use ECC cipher suite by default

I understand support for crypto-policies is coming to NSS, but in the meantime, perhaps NSS should use the ECC-enabled cipher suite from nss.conf by default? Fedora's nss and mod_nss are both compiled with ECC support. Flipping from one to the other in my FreeIPA web server bumped the Calomel score from 47% (0/20 for PFS) to 88%.

Attaching a patch against current package git master which should implement this.

Comment 1 Jaroslav Reznik 2015-03-03 16:17:06 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 22 development cycle.
Changing version to '22'.

More information and reason for this action is here:
https://fedoraproject.org/wiki/Fedora_Program_Management/HouseKeeping/Fedora22

Comment 2 Matthew Harmsen 2016-01-05 22:18:06 UTC
Per discussion with rcritten, will try to fix this upstream as time permits for inclusion in some future release.

(set new default ciphers)

Comment 3 Rob Crittenden 2016-03-07 15:39:32 UTC
master: 81908fd375160f26b46af4decfe198d41b0115a7

Comment 4 Mike McCune 2016-03-28 23:05:20 UTC
This bug was accidentally moved from POST to MODIFIED via an error in automation, please see mmccune with any questions

Comment 5 Fedora End Of Life 2016-07-19 19:30:26 UTC
Fedora 22 changed to end-of-life (EOL) status on 2016-07-19. Fedora 22 is
no longer maintained, which means that it will not receive any further
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version. If you
are unable to reopen this bug, please file a new report against the
current release. If you experience problems, please add a comment to this
bug.

Thank you for reporting this bug and we are sorry it could not be fixed.

Comment 6 Rob Crittenden 2016-07-19 19:32:34 UTC
This was addressed upstream in 1.0.13.


Note You need to log in before you can comment on or make changes to this bug.