Re: building SLES 12 RPM for nss-3.95, missing BL_FIPSRepeatIntegrityCheck()
Martin Sirringhaus <[email protected]> Thu, 30 Nov 2023 07:41:44 +0100
| Newsgroups | gmane.comp.mozilla.crypto |
|---|---|
| Message-ID | <[email protected]> |
> I'm bombing out on three tests, however. They all seem to have this > same flavor of error: > > cert.sh: #291: Enable FIPS mode on database for FIPS PUB 140 Test Certificate (12) - FAILED > cert.sh ERROR: Enable FIPS mode on database for FIPS PUB 140 Test Certificate failed 12 > cert.sh: Setting invalid database password in FIPS mode > -------------------------- > certutil -W -d /home/breichert/rpmbuild/mozilla-nss/BUILD/nss-3.95/tests_results/security/localhost.1/fips -f ../tests.fipspw -@ ../tests.fipsbadpw > Failed to change password. > certutil: Could not set password for the slot: SEC_ERROR_INVALID_PASSWORD: Password entered is invalid. Please pick a different one. > > It is possible these are due to my mismanaging the patches? Or is > this a known issue with this release? Do you have this patch as well? https://build.opensuse.org/package/view_file/mozilla:Factory/mozilla-nss/nss-fips-test.patch?expand=1 That should fix those 3 failing tests. We are currently still discussing, if this behavior is according to FIPS specification or not. But it's not a big deal, and that patch should fix it for now. Cheers, Martin -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/caddf65b-62d9-4e8d-a0e9-0f1573494cd0%40suse.de.