Package: libnss3
Version: 2:3.58-1
Severity: important
Tags: upstream
Forwarded: https://bugzilla.mozilla.org/1672855
X-Debbugs-Cc: [email protected]
Dear Maintainer,
After installing libnss3 2:3.58-1, pidgin is unable to connect to (any?)
services using TLS. The issue occurs on all services I tested,
including: IRC (chat.freenode.net), XMPP (talk.google.com), Discord
(gateway.discord), and AIM (slogin.oscar.aol.com). Relevant output from
pidgin --debug:
nss: Handshake failed (-12251)
connection: Connection error on 0x55f37b4e6880 (reason: 5 description: SSL
Handshake Failed)
account: Disconnecting account [email protected] (0x55f37a78c4b0)
connection: Disconnecting connection 0x55f37b4e6880
connection: Destroying connection 0x55f37b4e6880
Downgrading to 2:3.56-1 resolves the issue. I have opened
https://bugzilla.mozilla.org/1672855 to investigate the issue with NSS
upstream.
Cheers,
Kevin
Note: Although the "Handshake failed" is similar to
https://bugs.debian.org/790610, I think this is a different issue caused
by a specific commit rather than the weak FFDHE group causing the issue
in that bug.
-- System Information:
Debian Release: bullseye/sid
APT prefers testing-debug
APT policy: (990, 'testing-debug'), (990, 'testing'), (500,
'unstable-debug'), (500, 'unstable'), (101, 'experimental'), (1,
'experimental-debug')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 5.9.0 (SMP w/4 CPU threads)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages libnss3 depends on:
ii libc6 2.31-4
ii libnspr4 2:4.28-1
ii libsqlite3-0 3.33.0-1
libnss3 recommends no packages.
libnss3 suggests no packages.
-- no debconf information