Re: TLS 1.2 Issue with openldap 2.4.36 built on NSS 3.15.3

2013-11-29 Thread sameerste
Hi, I found some new behavior with openldap server built against Mozilla NSS(3.15.3) and our requirement is to use only TLSv1.2 ciphers only. If I have following LDAP (Server+Client)configuration: Scenario 1: Openldap Server built against NSS(slap.conf) Openldap client built

Re: TLS 1.2 Issue with openldap 2.4.36 built on NSS 3.15.3

2013-11-29 Thread sameerste
@Kurt: Thanks for the information Is there a reason why you disable GCM? I can see no good reason to disable it. It really is what you want in the first place. --It was a user requirement and hence had to be disabled. -- dev-tech-crypto mailing list dev-tech-crypto@lists.mozilla.org

Re: TLS 1.2 Issue with openldap 2.4.36 built on NSS 3.15.3

2013-11-29 Thread Kurt Roeckx
On Fri, Nov 29, 2013 at 04:07:35AM -0800, sameer...@gmail.com wrote: Hi, I found some new behavior with openldap server built against Mozilla NSS(3.15.3) and our requirement is to use only TLSv1.2 ciphers only. I have no idea what you really mean with this. Please note that ciphers can

Re: TLS 1.2 Issue with openldap 2.4.36 built on NSS 3.15.3

2013-11-29 Thread Kurt Roeckx
On Fri, Nov 29, 2013 at 01:43:11PM +0100, Kurt Roeckx wrote: As far as I know, NSS does not have any ciphers with SHA-2 other than GCM, and so I think what you want is not currently possible with NSS. It seems that some are implemented, but at least firefox with the latest version doesn't have

Re: TLS 1.2 Issue with openldap 2.4.36 built on NSS 3.15.3

2013-11-29 Thread Elio Maldonado Batiz
Firefox 27 will support TLS 1.2, see https://bugzilla.mozilla.org/show_bug.cgi?id=861266 On Fri, Nov 29, 2013 at 10:32 AM, Kurt Roeckx k...@roeckx.be wrote: On Fri, Nov 29, 2013 at 01:43:11PM +0100, Kurt Roeckx wrote: As far as I know, NSS does not have any ciphers with SHA-2 other than

Re: TLS 1.2 Issue with openldap 2.4.36 built on NSS 3.15.3

2013-11-29 Thread Kurt Roeckx
On Fri, Nov 29, 2013 at 03:53:09PM -0800, Elio Maldonado Batiz wrote: Firefox 27 will support TLS 1.2, see https://bugzilla.mozilla.org/show_bug.cgi?id=861266 I know, and the only TLS 1.2 cipher will be GCM. Kurt -- dev-tech-crypto mailing list dev-tech-crypto@lists.mozilla.org