Ubuntu builds of libnss lack ECC support

Bug #232392 reported by Kain
2
Affects Status Importance Assigned to Milestone
nss (Debian)
Fix Released
Unknown
nss (Ubuntu)
Fix Released
Medium
Alexander Sack
Hardy
Won't Fix
Undecided
Unassigned

Bug Description

Ubuntu builds of libnss3 do not build with anything equivalent to NSS_ENABLE_ECC=1 on the make commandline in debian/rules. This breaks anyone using a nss application (evolution, thunderbird, firefox, epiphany etc) attempting to use ECC over SSL.

Exists at least on ubuntu hardy.

To reproduce:
start firefox-3
browse to http://ecc.fedora.redhat.com/, and use the ui there to attempt to switch your cipher suite to any ECDSA variant. Bask in the glory of ssl_error_no_cypher_overlap!

To fix: add a NSS_ENABLE_ECC=1 to the defines used in debian/rules

Related branches

Revision history for this message
Kain (kain-kain) wrote :

Attached patch enables ECC cert support in libnss, thus enabling ECC SSL ciphers in at least firefox, xulrunner,and thunderbird.

I have not studied the paths of ECC cert support throughout evolution and it's core dependencies (eds and libcamel) yet, so this does not fix ECC support there fully. What will happen there is ECDSA/ECDH ciphers will work, but you will get server certificate signature errors.

Changed in nss:
status: Unknown → Fix Released
Revision history for this message
Alexander Sack (asac) wrote :

thanks for the patch. this should go to intrepid. we wont enable it in hardy most likely.

Changed in nss:
assignee: nobody → asac
importance: Undecided → Medium
milestone: none → intrepid-alpha-4
status: New → Triaged
Revision history for this message
Alexander Sack (asac) wrote :

setting hardy target to wontfix to reflect my last comment.

Changed in nss:
status: New → Won't Fix
Alexander Sack (asac)
Changed in nss:
status: Triaged → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package nss - 3.12.0.3-0ubuntu5

---------------
nss (3.12.0.3-0ubuntu5) intrepid; urgency=low

  * fix LP: #232392 - "Ubuntu builds of libnss lack ECC support";
    Thanks to Kain for pointing this out.
    - update debian/rules

 -- Alexander Sack <email address hidden> Tue, 12 Aug 2008 17:40:59 +0200

Changed in nss:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.