The NSS Development Team announces the release of NSS 3.15.5.

Network Security Services (NSS) 3.15.5 is a patch release for NSS 3.15.

New functionality:
* Added support for the TLS application layer protocol negotiation 
  (ALPN) extension. Two SSL socket options, SSL_ENABLE_NPN and 
  SSL_ENABLE_ALPN, can be used to control whether NPN or ALPN (or both) 
  should be used for application layer protocol negotiation.
* Added the TLS padding extension. The extension type value is 35655, 
  which may change when an official extension type value is assigned 
  by IANA. NSS automatically adds the padding extension to ClientHello 
  when necessary.
* Added a new macro CERT_LIST_TAIL, defined in certt.h, for getting 
  the tail of a CERTCertList.

Notable Changes:
* Bug 950129: Improve the OCSP fetching policy when verifying OCSP
  responses
* Bug 949060: Validate the iov input argument (an array of PRIOVec 
  structures) of ssl_WriteV (called via PR_Writev). Applications should
  still take care when converting struct iov to PRIOVec because the 
  iov_len members of the two structures have different types 
  (size_t vs. int). size_t is unsigned and may be larger than int.

The full release notes are available at
https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.5_release_notes

The HG tag is NSS_3_15_5_RTM. NSS 3.15.5 requires NSPR 4.10.2 or newer.

NSS 3.15.5 source distributions are also available on ftp.mozilla.org
for secure HTTPS download:
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_5_RTM/src/

A complete list of all bugs resolved in this release can be obtained at
https://bugzilla.mozilla.org/buglist.cgi?resolution=FIXED&classification=Components&query_format=advanced&target_milestone=3.15.5&product=NSS


-- 
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto

Reply via email to