NSS 3.112 Release

"'Dennis Jackson' via [email protected]" <[email protected]> Tue, 27 May 2025 18:27:30 +0100
Newsgroups gmane.comp.mozilla.crypto
Message-ID <CAON8YFMYHQy-UK4ZhvJ8b8tcWYTA71b_eeiB+pQ4byxx3fhLNg@mail.gmail.com>
--000000000000330163063621631c
Content-Type: text/plain; charset="UTF-8"

Network Security Services (NSS) 3.112 was released on 27th May 2025.

The HG tag is NSS_3_112_RTM. This version of NSS requires NSPR
4.35 or newer. The latest version of NSPR is 4.36.

NSS 3.112 source distributions are available on ftp.mozilla.org
for secure HTTPS download:
<https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_112_RTM/src/>

Changes:

   - Bug 1963792 <https://bugzilla.mozilla.org/show_bug.cgi?id=1963792> -
   Fix alias for mac workers on try.
   - Bug 1966786 <https://bugzilla.mozilla.org/show_bug.cgi?id=1966786> -
   ensure all options can be configured with SSL_OptionSet and
   SSL_OptionSetDefault.
   - Bug 1931930 <https://bugzilla.mozilla.org/show_bug.cgi?id=1931930> -
   ABI/API break in ssl certificate processing
   - Bug 1955971 <https://bugzilla.mozilla.org/show_bug.cgi?id=1955971> -
   remove unnecessary assertion in sec_asn1d_init_state_based_on_template.
   - Bug 1965754 <https://bugzilla.mozilla.org/show_bug.cgi?id=1965754> -
   update taskgraph to v14.2.1.
   - Bug 1964358 <https://bugzilla.mozilla.org/show_bug.cgi?id=1964358> -
   Workflow for automation of the release on GitHub when pushing a tag
   - Bug 1952860 <https://bugzilla.mozilla.org/show_bug.cgi?id=1952860> -
   fix faulty assertions in SEC_ASN1DecoderUpdate
   - Bug 1934877 <https://bugzilla.mozilla.org/show_bug.cgi?id=1934877> -
   Renegotiations should use a fresh ECH GREASE buffer.
   - Bug 1951396 <https://bugzilla.mozilla.org/show_bug.cgi?id=1951396> -
   update taskgraph to v14.1.1
   - Bug 1962503 <https://bugzilla.mozilla.org/show_bug.cgi?id=1962503> -
   Partial fix for ACVP build CI job
   - Bug 1961827 <https://bugzilla.mozilla.org/show_bug.cgi?id=1961827> -
   Initialize find in sftk_searchDatabase.
   - Bug 1963121 <https://bugzilla.mozilla.org/show_bug.cgi?id=1963121> -
   Add clang-18 to extra builds.
   - Bug 1963044 <https://bugzilla.mozilla.org/show_bug.cgi?id=1963044> -
   Fault tolerant git fetch for fuzzing.
   - Bug 1962556 <https://bugzilla.mozilla.org/show_bug.cgi?id=1962556> -
   Tolerate intermittent failures in ssl_policy_pkix_ocsp.
   - Bug 1962770 <https://bugzilla.mozilla.org/show_bug.cgi?id=1962770> -
   fix compiler warnings when DEBUG_ASN1D_STATES or CMSDEBUG are set.
   - Bug 1961835 <https://bugzilla.mozilla.org/show_bug.cgi?id=1961835> -
   fix content type tag check in NSS_CMSMessage_ContainsCertsOrCrls.
   - Bug 1963102 <https://bugzilla.mozilla.org/show_bug.cgi?id=1963102> -
   Remove Cryptofuzz CI version check

NSS 3.112 shared libraries are backwards-compatible with all
older NSS 3.x shared libraries. A program linked with older NSS
3.x shared libraries will work with this new version of the
shared libraries without recompiling or relinking. Furthermore,
applications that restrict their use of NSS APIs to the
functions listed in NSS Public Functions will remain compatible
with future versions of the NSS shared libraries.

Bugs discovered should be reported by filing a bug report at
<https://bugzilla.mozilla.org/enter_bug.cgi?product=NSS>

Release notes are available, after a short delay, at
<https://firefox-source-docs.mozilla.org/security/nss/releases/index.html>.

-- 
You received this message because you are subscribed to the Google Groups "[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/CAON8YFMYHQy-UK4ZhvJ8b8tcWYTA71b_eeiB%2BpQ4byxx3fhLNg%40mail.gmail.com.

--000000000000330163063621631c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Network Security Services (NSS) 3.112 was released on=
 27th May 2025.<br>
<br>
The HG tag is NSS_3_112_RTM. This version of NSS requires NSPR<br>
4.35 or newer. The latest version of NSPR is 4.36.<br>
<br>
NSS 3.112 source distributions are available on <a href=3D"http://ftp.mozil=
la.org" rel=3D"noreferrer" target=3D"_blank">ftp.mozilla.org</a><br>
for secure HTTPS download:<br>
&lt;<a href=3D"https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_112_=
RTM/src/" rel=3D"noreferrer" target=3D"_blank">https://ftp.mozilla.org/pub/=
security/nss/releases/NSS_3_112_RTM/src/</a>&gt;<br>
<br></div>
Changes:<div class=3D"gmail-docutils gmail-container">
<ul><li><a class=3D"gmail-reference external" href=3D"https://bugzilla.mozi=
lla.org/show_bug.cgi?id=3D1963792">Bug 1963792</a> - Fix alias for mac work=
ers on try.</li><li><a class=3D"gmail-reference external" href=3D"https://b=
ugzilla.mozilla.org/show_bug.cgi?id=3D1966786">Bug 1966786</a> - ensure all=
 options can be configured with SSL_OptionSet and SSL_OptionSetDefault.</li=
><li><a class=3D"gmail-reference external" href=3D"https://bugzilla.mozilla=
.org/show_bug.cgi?id=3D1931930">Bug 1931930</a> - ABI/API break in ssl cert=
ificate processing</li><li><a class=3D"gmail-reference external" href=3D"ht=
tps://bugzilla.mozilla.org/show_bug.cgi?id=3D1955971">Bug 1955971</a> - rem=
ove unnecessary assertion in sec_asn1d_init_state_based_on_template.</li><l=
i><a class=3D"gmail-reference external" href=3D"https://bugzilla.mozilla.or=
g/show_bug.cgi?id=3D1965754">Bug 1965754</a> - update taskgraph to v14.2.1.=
</li><li><a class=3D"gmail-reference external" href=3D"https://bugzilla.moz=
illa.org/show_bug.cgi?id=3D1964358">Bug 1964358</a> - Workflow for automati=
on of the release on GitHub when pushing a tag</li><li><a class=3D"gmail-re=
ference external" href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D19=
52860">Bug 1952860</a> - fix faulty assertions in SEC_ASN1DecoderUpdate</li=
><li><a class=3D"gmail-reference external" href=3D"https://bugzilla.mozilla=
.org/show_bug.cgi?id=3D1934877">Bug 1934877</a> - Renegotiations should use=
 a fresh ECH GREASE buffer.</li><li><a class=3D"gmail-reference external" h=
ref=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D1951396">Bug 1951396<=
/a> - update taskgraph to v14.1.1</li><li><a class=3D"gmail-reference exter=
nal" href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D1962503">Bug 19=
62503</a> - Partial fix for ACVP build CI job</li><li><a class=3D"gmail-ref=
erence external" href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D196=
1827">Bug 1961827</a> - Initialize find in sftk_searchDatabase.</li><li><a =
class=3D"gmail-reference external" href=3D"https://bugzilla.mozilla.org/sho=
w_bug.cgi?id=3D1963121">Bug 1963121</a> - Add clang-18 to extra builds.</li=
><li><a class=3D"gmail-reference external" href=3D"https://bugzilla.mozilla=
.org/show_bug.cgi?id=3D1963044">Bug 1963044</a> - Fault tolerant git fetch =
for fuzzing.</li><li><a class=3D"gmail-reference external" href=3D"https://=
bugzilla.mozilla.org/show_bug.cgi?id=3D1962556">Bug 1962556</a> - Tolerate =
intermittent failures in ssl_policy_pkix_ocsp.</li><li><a class=3D"gmail-re=
ference external" href=3D"https://bugzilla.mozilla.org/show_bug.cgi?id=3D19=
62770">Bug 1962770</a> - fix compiler warnings when DEBUG_ASN1D_STATES or C=
MSDEBUG are set.</li><li><a class=3D"gmail-reference external" href=3D"http=
s://bugzilla.mozilla.org/show_bug.cgi?id=3D1961835">Bug 1961835</a> - fix c=
ontent type tag check in NSS_CMSMessage_ContainsCertsOrCrls.</li><li><a cla=
ss=3D"gmail-reference external" href=3D"https://bugzilla.mozilla.org/show_b=
ug.cgi?id=3D1963102">Bug 1963102</a> - Remove Cryptofuzz CI version check</=
li></ul></div>NSS 3.112 shared libraries are backwards-compatible with all<=
br>
older NSS 3.x shared libraries. A program linked with older NSS<br>
3.x shared libraries will work with this new version of the<br>
shared libraries without recompiling or relinking. Furthermore,<br>
applications that restrict their use of NSS APIs to the<br>
functions listed in NSS Public Functions will remain compatible<br>
with future versions of the NSS shared libraries.<br>
<br>
Bugs discovered should be reported by filing a bug report at<br>
&lt;<a href=3D"https://bugzilla.mozilla.org/enter_bug.cgi?product=3DNSS" re=
l=3D"noreferrer" target=3D"_blank">https://bugzilla.mozilla.org/enter_bug.c=
gi?product=3DNSS</a>&gt;<br>
<br>
Release notes are available, after a short delay, at<br>
&lt;<a href=3D"https://firefox-source-docs.mozilla.org/security/nss/release=
s/index.html" rel=3D"noreferrer" target=3D"_blank">https://firefox-source-d=
ocs.mozilla.org/security/nss/releases/index.html</a>&gt;.<font color=3D"#88=
8888"><br>
</font><br></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;[email protected]&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">dev-tech=
[email protected]</a>.<br />
To view this discussion visit <a href=3D"https://groups.google.com/a/mozill=
a.org/d/msgid/dev-tech-crypto/CAON8YFMYHQy-UK4ZhvJ8b8tcWYTA71b_eeiB%2BpQ4by=
xx3fhLNg%40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter">https://g=
roups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/CAON8YFMYHQy-UK4ZhvJ=
8b8tcWYTA71b_eeiB%2BpQ4byxx3fhLNg%40mail.gmail.com</a>.<br />

--000000000000330163063621631c--