Red Hat Bugzilla – Bug 591237
Rebase mod_nss in RHEL 5.6
Last modified: 2010-05-11 13:54:37 EDT
mod_nss unknowningly relied on broken behavior in NSS prior to 3.11.9 related to forking and PKCS#11 modules. The PKCS#11 spec says that after a fork a PKCS#11 module needs to reinitialize. The old NSS soft token didn't require this but most hardware modules do. In mod_nss 1.0.3, the version in RHEL, we initialize mod_nss in the Apache parent process and the children inherit this initialization. We need to initialize NSS in each Apache child instead. This is fixed in mod_nss 1.0.8.
The Certificate System also needs some more advanced OCSP configuration that is available in 1.0.8. While these can be backported through patches the resulting mod_nss 1.0.3 code would be virtually indistinguishable from 1.0.8 and yet we would still have to carry and maintain the patches. It would be better to rebase mod_nss.
closing, apparently the rebase bug is enough.