See bug 499052 for all technical information. The required fix is in the NSS component.
Ondrej, unless Kai or any of the NSS developers can provide you with a NSS testcase, it might be difficult. This is one of those where I have a higher level RHCS usecase that can be verified easily by us with an updated NSS package based on https://bugzilla.redhat.com/show_bug.cgi?id=499052#c0 and confirm that the fix works and you can probably run through your typical NSS regression tests to confirm that nothing else is broken. Would that be ok with you ?
This separate bug is no longer necessary. We'll include the fix with bug 500877. *** This bug has been marked as a duplicate of bug 500877 ***