NSS 3.95 Release
Anna Weine <[email protected]> Mon, 27 Nov 2023 11:06:25 +0100
| Newsgroups | gmane.comp.mozilla.crypto |
|---|---|
| Message-ID | <CAMeH0+pqdXTwL6DLqMAfu92RdmchUa7JUJVamaW_ktoM8YdvCg@mail.gmail.com> |
--0000000000000a67d6060b1f75cd Content-Type: text/plain; charset="UTF-8" Dear all, Network Security Services (NSS) 3.95 was released on 27 November 2023. The HG tag is NSS_3_95_RTM. This version of NSS requires NSPR 4.35 or newer. NSS 3.95 source distributions are available on ftp.mozilla.org for secure HTTPS download: <https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_95_RTM/src/> Changes: - Bug 1842932 - Bump builtins version number. - Bug 1851044: Remove Email trust bit from Autoridad de Certificacion Firmaprofesional CIF A62634068 root cert. - Bug 1855318: Remove 4 DigiCert (Symantec/Verisign) Root Certificates from NSS. - Bug 1851049: Remove 3 TrustCor Root Certificates from NSS. - Bug 1850982 - Remove Camerfirma root certificates from NSS. - Bug 1842935 - Remove old Autoridad de Certificacion Firmaprofesional Certificate. - Bug 1860670 - Add four Commscope root certificates to NSS. - Bug 1850598 - Add TrustAsia Global Root CA G3 and G4 root certificates. - Bug 1863605 - Include P-384 and P-521 Scalar Validation from HACL* - Bug 1861728 - Include P-256 Scalar Validation from HACL*. - Bug 1861265 After the HACL 256 ECC patch, NSS incorrectly encodes 256 ECC without DER wrapping at the softoken level - Bug 1837987:Add means to provide library parameters to C_Initialize - Bug 1573097 - clang format - Bug 1854795 - add OSXSAVE and XCR0 tests to AVX2 detection. - Bug 1858241 - Typo in ssl3_AppendHandshakeNumber - Bug 1858241 - Introducing input check of ssl3_AppendHandshakeNumber - Bug 1573097 - Fix Invalid casts in instance.c NSS 3.95 shared libraries are backwards-compatible with all older NSS 3.x shared libraries. A program linked with older NSS 3.x shared libraries will work with this new version of the shared libraries without recompiling or relinking. Furthermore, applications that restrict their use of NSS APIs to the functions listed in NSS Public Functions will remain compatible with future versions of the NSS shared libraries. Bugs discovered should be reported by filing a bug report at <https://bugzilla.mozilla.org/enter_bug.cgi?product=NSS> Release notes are available at <https://firefox-source-docs.mozilla.org/security/nss/releases/index.html>. Best, Anna -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/CAMeH0%2BpqdXTwL6DLqMAfu92RdmchUa7JUJVamaW_ktoM8YdvCg%40mail.gmail.com. --0000000000000a67d6060b1f75cd Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Dear all,<br><br>Network Security Services (NSS) 3.95 was = released on 27 November 2023.<br><br>The HG tag is NSS_3_95_RTM. This versi= on of NSS requires NSPR 4.35 or newer.<br><br>NSS 3.95 source distributions= are available on <a href=3D"http://ftp.mozilla.org">ftp.mozilla.org</a> fo= r<br>secure HTTPS download:<br><<a href=3D"https://ftp.mozilla.org/pub/s= ecurity/nss/releases/NSS_3_95_RTM/src/">https://ftp.mozilla.org/pub/securit= y/nss/releases/NSS_3_95_RTM/src/</a>><br><br>Changes:<br><br>=C2=A0- Bug= 1842932 - Bump builtins version number.<br>=C2=A0- Bug 1851044: Remove Ema= il trust bit from Autoridad de Certificacion Firmaprofesional CIF A62634068= root cert.<br>=C2=A0- Bug 1855318: Remove 4 DigiCert (Symantec/Verisign) R= oot Certificates from NSS.<br>=C2=A0- Bug 1851049: Remove 3 TrustCor Root C= ertificates from NSS.<br>=C2=A0- Bug 1850982 - Remove Camerfirma root certi= ficates from NSS.<br>=C2=A0- Bug 1842935 - Remove old Autoridad de Certific= acion Firmaprofesional Certificate.<br>=C2=A0- Bug 1860670 - Add four Comms= cope root certificates to NSS.<br>=C2=A0- Bug 1850598 - Add TrustAsia Globa= l Root CA G3 and G4 root certificates.<br>=C2=A0- Bug 1863605 - Include P-3= 84 and P-521 Scalar Validation from HACL*<br>=C2=A0- Bug 1861728 - Include = P-256 Scalar Validation from HACL*.<br>=C2=A0- Bug 1861265 After the HACL 2= 56 ECC patch, NSS incorrectly encodes 256 ECC without DER wrapping at the s= oftoken level<br>=C2=A0- Bug 1837987:Add means to provide library parameter= s to C_Initialize<br>=C2=A0- Bug 1573097 - clang format<br>=C2=A0- Bug 1854= 795 - add OSXSAVE and XCR0 tests to AVX2 detection.<br>=C2=A0- Bug 1858241 = - Typo in ssl3_AppendHandshakeNumber<br>=C2=A0- Bug 1858241 - Introducing i= nput check of ssl3_AppendHandshakeNumber<br>=C2=A0- Bug 1573097 - Fix Inval= id casts in instance.c<br><br><br>NSS 3.95 shared libraries are backwards-c= ompatible with all older NSS<br>3.x shared libraries. A program linked with= older NSS 3.x shared<br>libraries will work with this new version of the s= hared libraries<br>without recompiling or relinking. Furthermore, applicati= ons that<br>restrict their use of NSS APIs to the functions listed in NSS P= ublic<br>Functions will remain compatible with future versions of the NSS<b= r>shared libraries.<br><br>Bugs discovered should be reported by filing a b= ug report at<br><<a href=3D"https://bugzilla.mozilla.org/enter_bug.cgi?p= roduct=3DNSS">https://bugzilla.mozilla.org/enter_bug.cgi?product=3DNSS</a>&= gt;<br><br>Release notes are available at<br><<a href=3D"https://firefox= -source-docs.mozilla.org/security/nss/releases/index.html">https://firefox-= source-docs.mozilla.org/security/nss/releases/index.html</a>>.<br><br>Be= st,<br>Anna</div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;[email protected]" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:[email protected]">dev-tech= [email protected]</a>.<br /> To view this discussion on the web visit <a href=3D"https://groups.google.c= om/a/mozilla.org/d/msgid/dev-tech-crypto/CAMeH0%2BpqdXTwL6DLqMAfu92RdmchUa7= JUJVamaW_ktoM8YdvCg%40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter= ">https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/CAMeH0%2B= pqdXTwL6DLqMAfu92RdmchUa7JUJVamaW_ktoM8YdvCg%40mail.gmail.com</a>.<br /> --0000000000000a67d6060b1f75cd--