Re: NSS_Context and FIPS

Rob Crittenden <[email protected]>
Newsgroups gmane.comp.mozilla.crypto
Message-ID <[email protected]>
Robert Relyea wrote:
> On 10/21/2016 07:04 AM, Rob Crittenden wrote:
>> I'm trying to figure out how to dynamically enable FIPS support for
>> NSS Contexts.
>>
>> I started with multinit.c and initialize FIPS right after calling
>> NSS_InitContext() using this:
>
> So you can't change the state of an already open database. NSS will
> switch all new databases that are opened, and idle the old ones
> (basically they are open, but not really accessible).
>
>
>>
>>     if (!PK11_IsFIPS()) {
>>         fprintf(stderr, "Initializing FIPS\n");
>>         SECMODModule *mod = SECMOD_GetInternalModule();
>>         if (!mod) {
>>             fprintf(stderr, "No module!?\n");
>>             exit(1);
>>         }
>>         char * internal_name = PR_smprintf("%s",
>>             SECMOD_GetInternalModule()->commonName);
>>
>>         if ((SECMOD_DeleteInternalModule(internal_name) != SECSuccess) ||
>>          !PK11_IsFIPS()) {
>>                  fprintf(stderr, "Unable to enable FIPS mode on
>> certificate database\n");
>>                  exit(1);
>>         }
>>
>> I'm executing it like this, initializing only db1 and db2 as contexts:
>
> So when you do an initcontext, you're main database is usually not the
> same as the main database when you open NSS, so it won't get
> automatically switched.
>
> Is there a reason you are trying to do a dynamic switch to FIPS mode
> from within a library? (I'd like to know the use case).

I'm converting mod_nss to use contexts. I previously had an option to 
switch on FIPS mode which turned it on in NSS, did some sanity checking 
on the cipher options and required a password.

I'd be ok requiring an all or nothing with the FIPS databases if that 
simplifies thiungs.

> Dynamic switching is a pretty careful choreographed dance that
> applications like mozilla can execute with care. It usually involves
> both fips and non-fips tokens opened for a short period until all the
> references can be cleared. Databases opened before the switch will
> almost certainly be inaccessible.
>>
>> $ ./multinit --verbose --lib1_db db1/ --lib2_db db2 --lib1_command
>> list_certs --lib2_command list_certs --lib1_readonly --lib2_readonly
>> --order 12zi
>>
>> This is the output:
>>
>> $ ./multinit --verbose --lib1_db db1/ --lib2_db db2 --lib1_command
>> list_certs --lib2_command list_certs  --lib1_readonly --lib2_readonly
>> --order  12zi
>> * initializing with order "12zi"*
>> *NSS_Init for lib1*
>> Checking for FIPS
>> Initializing FIPS
>> *Executing nss command "list_certs" for lib1*
>> cacert CTu,Cu,Cu
>> *       Slot=NSS FIPS 140-2 Certificate DB*
>> *       Nickname=cacert*
>> *       Subject=<CN=Certificate Shack,O=example.com,C=US>*
>> *       Issuer=<CN=Certificate Shack,O=example.com,C=US>*
>> *       SN=01 *
>> Server-Cert                                                  u,u,u
>> *       Slot=NSS FIPS 140-2 Certificate DB*
>> *       Nickname=Server-Cert*
>> *       Subject=<CN=darlene.greyoak.com,O=example.com,C=US>*
>> *       Issuer=<CN=Certificate Shack,O=example.com,C=US>*
>> *       SN=04 *
>> *NSS_Init for lib2*
>> Checking for FIPS
>> FIPS already enabled
>> *Executing nss command "list_certs" for lib1*
>> *Executing nss command "list_certs" for lib2*
>> *NSS_Shutdown for lib2
>> *Shutdown lib2 state = 0
>> *Executing nss command "list_certs" for lib1*
>> *NSS_Shutdown for lib1
>> *Shutdown lib1 state = 0
>>
>> So db1 is successfully put into FIPS mode and the slot names are
>> changed as one would expect, but then lib2 isn't set into FIPS mode
>> and subsequently no certificates are discovered at all (I can only
>> assume because there is a mix of FIPS and non-FIPS tokens so it throws
>> up?)
> yes.
>>
>> Any idea what I'm doing wrong?
> pushing the limits of what is possible;).
>
> So things are acting as I would expect. your other lib will likely need
> to shutdown it's database and reopen it.

I'm still a little unclear. So if I open all the databases, and THEN set 
FIPS mode, that will do the trick? I was pretty sure I tried that but 
who knows.

thanks

rob

-- 
dev-tech-crypto mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-tech-crypto
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.