[ANNOUNCE] NSS 3.53 release

2020-06-01 Thread JC Jones
The NSS team released Network Security Services (NSS) 3.53 on 29 May 2020. NSS 3.53 will be a long-term support release, supporting Firefox 78 ESR. The NSS team would like to recognize first-time contributors: Jan-Marek Glogowski Jeff Walden The HG tag is NSS_3_53_RTM. NSS 3.53 requir

Re: FIPS mode key import?

2020-06-01 Thread Paul Wouters
On Mon, 1 Jun 2020, Chris Newman wrote: I've been importing the DKIM private key using either PK11_ImportPrivateKeyInfoAndReturnKey or PK11_ImportDERPrivateKeyInfoAndReturnKey, but these APIs don't work in FIPS mode (they map to C_CreateObject which disallows raw key import). If FIPS mode onl

FIPS mode key import?

2020-06-01 Thread Chris Newman
I have NSS-based DKIM signing working in our mail server software, but run into a problem when trying to do it in FIPS mode. I've been importing the DKIM private key using either PK11_ImportPrivateKeyInfoAndReturnKey or PK11_ImportDERPrivateKeyInfoAndReturnKey, but these APIs don't work in FI