Package: libnss3 Please backport https://hg.mozilla.org/projects/nss/rev/a69c9f36bb8ac1c47cacb6c6ec9f06309de33951 to Sid
This is an upstream bug that has annoying consequences for people that generate ECC keys on NSS softoken. The fix does *not* correct the data already stored in DBs so it is somewhat important to update packages quickly to minimize the number of people affected. It should be possible to manually export and then re-import keys to "fix" the format, but this has not been tested. The bug was first triggered in the pkcs11-provider upstream project CI when Fedora imported 3.94 and now it started showing up for Debian (and MacOS) as well. Note that Firefox is unaffected because NSS can reformat the keys as it reads them, the only affected applications are PKCS#11 applications that use softoken directly. Fedora 38 fix here: https://bodhi.fedoraproject.org/updates/FEDORA-2023-eb53986016 HTH, Simo. -- Simo Sorce, DE @ RHEL Crypto Team, Red Hat, Inc