Ben Bucksch wrote:

> Wan-Teh Chang wrote:
> 
>> RSA key pair generation [...] is
>>   also done by all products that generate Certificate Signing
>>   Requests.
> 
> 
> Does PSM do that and when, i.e. is PSM affected?
> 
> 
The PSM binary we release still uses the internal lib crypto version of 
NSS. Any one who builds PSM and NSS on their own should make sure that 
they have the up to date version of NSS to make sure they aren't 
vulnerable to the bug.

bob

Reply via email to