Red Hat Bugzilla – Bug 1312491
NSSProtocol is ignored when NSSFIPS is enabled.
Last modified: 2016-11-03 17:20:20 EDT
Verified. Version :: mod_nss-1.0.14-5.el7.x86_64 Results :: [root@vm3 conf.d]# grep -e FIPS -e TLSv /etc/httpd/conf.d/nss.conf # middle of a range may be excluded, the entry "NSSProtocol SSLv3,TLSv1.1" # is identical to the entry "NSSProtocol SSLv3,TLSv1.0,TLSv1.1". #NSSProtocol TLSv1.0,TLSv1.1,TLSv1.2 NSSProtocol TLSv1.2 NSSFIPS on [root@vm3 conf.d]# systemctl restart httpd [root@vm3 conf.d]# curl --tlsv1.0 https://vm3.example.com:8443/ curl: (35) Peer reports incompatible or unsupported protocol version. [root@vm3 conf.d]# curl --tlsv1.1 https://vm3.example.com:8443/ curl: (35) Peer reports incompatible or unsupported protocol version. [root@vm3 conf.d]# curl --tlsv1.2 https://vm3.example.com:8443/ PASS
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHSA-2016-2602.html