Comment 2Kai Engert (:kaie) (inactive account)
2012-03-21 22:46:48 UTC
We propose that this patch gets added together with the next scheduled FF update (10.0.4) (sharing a single errata).
Comment 3Kai Engert (:kaie) (inactive account)
2012-03-22 15:11:03 UTC
Created attachment 572018[details]
Patch v4 from upstream (smaller context version)
This is the same patch as upstream, however, with less context (5 lines, not 50 lines, shortens the patch, increases likelyhood that patch will continue to apply).
Comment 4Kai Engert (:kaie) (inactive account)
2012-03-22 15:14:32 UTC
If you need a risk assessment:
The patch is limited to changing code related to certificate key pair generation (which is only called when a user visits a CA's web page to apply for a certificate).