Red Hat Bugzilla – Bug 1422165
Export CERT_CompareAVA, and Export PK11_HasAttributeSet, required by Firefox to distinguish Mozilla Policy CAs [RHEL 7.x]
Last modified: 2017-08-01 12:50:07 EDT
In order to fix bug 1414564, we require that NSS exports function PK11_HasAttributeSet. It's required to allow Firefox to query p11-kit-trust (or libnssckbi) for the new pkcs#11 attribute, that allows it to distinguish between Mozilla Policy CAs and locally installed CAs. The linked upstream bug will export that API in NSS 3.30. We need to decide if this can be backported to NSS 3.28.x without rebasing. (We probably can, by using the correct version number 3.30 in the nss.def file, IIRC we have done similar things in the past.)
Created attachment 1261929 [details] nss-util-1334976-1336487.patch nss-util patch
Created attachment 1261930 [details] nss-1334976-1336487-1345083.patch nss patch
Daiki, could you please add these patches to nss-util and nss? I've used the patches we already have in Fedora, and on top of that, I added the fix from upstream 1345083. I think it's OK to commit the nss-util patch with "Related: this bug number" This patch also includes the fix for bug 1418891.
*** Bug 1418891 has been marked as a duplicate of this bug. ***
Done as: http://pkgs.devel.redhat.com/cgit/rpms/nss-util/commit/?h=rhel-7.4&id=3000bceb2fbfc06c5b844dcc65d89bac57569451 http://pkgs.devel.redhat.com/cgit/rpms/nss/commit/?h=rhel-7.4&id=6ca8b5966d39cbb878aba7e5d6d42323b9e4b429
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHEA-2017:1977