Upgrading to crypto-policies-20160718-1.gitcaa4a8d.fc25 causes dnf to emit: Downloading Packages: The downloaded packages were saved in cache until the next successful transaction. You can remove cached packages by executing 'dnf clean packages'. Error: Error downloading packages: Curl error (60): Peer certificate cannot be authenticated with given CA certificates for https://mirrors.fedoraproject.org/metalink?repo=rawhide&arch=x86_64 [The certificate was signed using a signature algorithm that is disabled because it is not secure.] Downgrading to 20160516-1.git8f69c35.fc25 gets it working again. I am going to untag the 20160718 version so it doesn't go out in tomorrows rawhide until we can get this fixed.
Thank you for reporting that. It was an issue in the generated policy for NSS. I've uploaded crypto-policies-20160718-1.git340cb69 which should address the issue.
Yep. I can confirm the new one works as expected. ;) Thanks for the quick fix.