Package: libnss3

Please backport
https://hg.mozilla.org/projects/nss/rev/a69c9f36bb8ac1c47cacb6c6ec9f06309de33951
to Sid

This is an upstream bug that has annoying consequences for people that
generate ECC keys on NSS softoken.
The fix does *not* correct the data already stored in DBs so it is
somewhat important to update packages quickly to minimize the number of
people affected.

It should be possible to manually export and then re-import keys to
"fix" the format, but this has not been tested.

The bug was first triggered in the pkcs11-provider upstream project CI
when Fedora imported 3.94 and now it started showing up for Debian (and
MacOS) as well.

Note that Firefox is unaffected because NSS can reformat the keys as it
reads them, the only affected applications are PKCS#11 applications
that use softoken directly.

Fedora 38 fix here:
https://bodhi.fedoraproject.org/updates/FEDORA-2023-eb53986016

HTH,
Simo.

-- 
Simo Sorce,
DE @ RHEL Crypto Team,
Red Hat, Inc

Reply via email to