Package: libnss3 Version: 2:3.58-1 Severity: important Tags: upstream Forwarded: https://bugzilla.mozilla.org/1672855 X-Debbugs-Cc: ste.calleg...@tiscali.it
Dear Maintainer, After installing libnss3 2:3.58-1, pidgin is unable to connect to (any?) services using TLS. The issue occurs on all services I tested, including: IRC (chat.freenode.net), XMPP (talk.google.com), Discord (gateway.discord), and AIM (slogin.oscar.aol.com). Relevant output from pidgin --debug: nss: Handshake failed (-12251) connection: Connection error on 0x55f37b4e6880 (reason: 5 description: SSL Handshake Failed) account: Disconnecting account m...@example.com (0x55f37a78c4b0) connection: Disconnecting connection 0x55f37b4e6880 connection: Destroying connection 0x55f37b4e6880 Downgrading to 2:3.56-1 resolves the issue. I have opened https://bugzilla.mozilla.org/1672855 to investigate the issue with NSS upstream. Cheers, Kevin Note: Although the "Handshake failed" is similar to https://bugs.debian.org/790610, I think this is a different issue caused by a specific commit rather than the weak FFDHE group causing the issue in that bug. -- System Information: Debian Release: bullseye/sid APT prefers testing-debug APT policy: (990, 'testing-debug'), (990, 'testing'), (500, 'unstable-debug'), (500, 'unstable'), (101, 'experimental'), (1, 'experimental-debug') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 5.9.0 (SMP w/4 CPU threads) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled Versions of packages libnss3 depends on: ii libc6 2.31-4 ii libnspr4 2:4.28-1 ii libsqlite3-0 3.33.0-1 libnss3 recommends no packages. libnss3 suggests no packages. -- no debconf information