Opening Firefox v59 keystore with NSS

Renato Alves <[email protected]> Wed, 24 Jan 2018 16:31:26 +0100
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
Hi everyone,

In the past, libnss could be directly initialized by simply pointing the code to a location containing 'cert8.db' and 'key3.db'.
This is the basis of https://github.com/unode/firefox_decrypt a small tool I authored myself with the help of several contributors.

With Firefox 59 key.db and cert.db were modified to use an SQLite format instead of Berkley DB format.
After this change, direct initialization of NSS is no longer possible (tested with older NSS and the latest 3.35).
The latest NSS reports "SEC_ERROR_LEGACY_DATABASE: The certificate/key database is in an old, unsupported format.". The use of "old" in the error message is a little misleading.

With that said, is there any other way to initialize libnss to be able to decode Firefox's profile credentials or is this feature no longer supported?

Many thanks,
Renato

_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEErWzyn8km9Qx1yUkopwPBKi+mXQQFAlpops4ACgkQpwPBKi+m
XQRy1BAAhzwb+C1PryUUMrZaZ8EjBSHavB4/aqbR67uSPfVCBtsua5bjFUo1fkFt
QImy2N8MsTO3O7vovousa2hd+Mm0QOC/PVEXWDF1psw97bu7YDjhnYwxFMaXarPP
vYwO/DgGIZMJWfnlhZ7tAWg57REw+BonWJWHtEIPCtXUOtFT3mPYfxM/qdJNphx9
lEii5ZQps0ifawS7MvfukPk3++GeugP16ZU/5fdwznfHFu1oGpwXYnSMFHmUf08u
ICvzG3nMjeUf/p4iSZ2e2evw44UptoKTjGM/JzHv8Yc78/30iAZS2EP0ij4H9XQO
6/SGb1W+eoEaVe85E4Q3TVLF1lc0iTS1xRu2+/JLcu5MUPmohPVlT7nf0S2JvCA8
BlhLKYhQSQD24i9xw+6nAezAxwqAfanZlVGV/LIQsbI+db0kkyYJeABAIfyK+g1t
kFhi/hSdWsACH1d6zr3qpsFP751hQfrzJxtUP4Rx2Kfbo32/u/xf+ZrSTWcu/XpF
rr4qzO/cwqIVA1EpjBqwo3b8NbKFcd1sfTYJEEhAnP91aNfgbum/qd83GdQ52pi6
EXLvH9WZMUtma1k+x3z5PprZpb2WyEGjZW0xJvWkYzsyuSUbfx6+OfSulE9LckZG
GQmtzdB2UdENUjl9suvWyf/m6vFk3JT0tTs/0ZxwqmOS5R6EVQE=
=ONyI
-----END PGP SIGNATURE-----