Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-14 Thread Robert Relyea
On 06/13/2010 05:24 PM, Robin H. Johnson wrote: On Sun, Jun 13, 2010 at 03:08:07PM -0700, Nelson B Bolyard wrote: On 2010-06-13 13:02 PDT, Robin H. Johnson wrote: On Sun, Jun 13, 2010 at 02:02:39AM -0700, Nelson B Bolyard wrote: The root of the problem is that the shared

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-13 Thread Robin H. Johnson
On Sat, Jun 12, 2010 at 02:11:14PM -0700, Nelson B Bolyard wrote: You have a problem with a distribution of NSS that is not identical to the NSS as built from the upstream NSS source repository. Mozilla's NSS team supports NSS as it comes from the builds from the upstream NSS source

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-13 Thread Nelson B Bolyard
On 2010/06/13 01:33 PDT, Robin H. Johnson wrote: LOOK at the links I provided, there are ZERO changes to the actual source code. Robin, The point is that the upstream NSS team simply doesn't have time or resources to look at every downstream distribution. There's no point in asking us to do

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-13 Thread Robin H. Johnson
On Sun, Jun 13, 2010 at 02:02:39AM -0700, Nelson B Bolyard wrote: The root of the problem is that the shared libraries can change POST-install, as needed for ELF signing, split-debug and prelinking. The ELF signing is a catch-22. Either I have to run shlibsign afterwards, or I have to not

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-13 Thread Nelson B Bolyard
On 2010-06-13 13:02 PDT, Robin H. Johnson wrote: On Sun, Jun 13, 2010 at 02:02:39AM -0700, Nelson B Bolyard wrote: The root of the problem is that the shared libraries can change POST-install, as needed for ELF signing, split-debug and prelinking. The ELF signing is a catch-22. Either I have

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-13 Thread Robin H. Johnson
On Sun, Jun 13, 2010 at 03:08:07PM -0700, Nelson B Bolyard wrote: On 2010-06-13 13:02 PDT, Robin H. Johnson wrote: On Sun, Jun 13, 2010 at 02:02:39AM -0700, Nelson B Bolyard wrote: The root of the problem is that the shared libraries can change POST-install, as needed for ELF signing,

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-13 Thread Nelson B Bolyard
On 2010-06-13 17:24 PDT, Robin H. Johnson wrote: On Sun, Jun 13, 2010 at 03:08:07PM -0700, Nelson B Bolyard wrote: On 2010-06-13 13:02 PDT, Robin H. Johnson wrote: As an intermediate related question, is there a standalone verification tool for the CHK files shlibsign -V -i seems to

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-13 Thread Nelson B Bolyard
On 2010-06-13 17:56 PDT, I wrote: Perhaps the easiest thing to do is rerun shlibsign and compare the old and new files. Please forget that I wrote that. That won't work. -- dev-tech-crypto mailing list dev-tech-crypto@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-tech-crypto

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-12 Thread Nelson B Bolyard
On 2010-06-10 22:59 PDT, Robin H. Johnson wrote: On Thu, Jun 10, 2010 at 10:45:03PM +, Robin H. Johnson wrote: Testcase 2: (see attached minimal C code, based on posts to the list and used in the modutils source AND Mozilla). Bah, forgot the actual file. The testcase has been run on

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-12 Thread Matt McCutchen
On Jun 12, 2:25 pm, Nelson B Bolyard nel...@bolyard.me wrote: On 2010-06-10 22:59 PDT, Robin H. Johnson wrote: The testcase has been run on Arch and Fedora now, and both of those cases it works fine. Does that mean this problem is resolved? As I read, it is not; it was reported on Gentoo

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-12 Thread Robin H. Johnson
On Sat, Jun 12, 2010 at 12:15:07PM -0700, Matt McCutchen wrote: On Jun 12, 2:25 pm, Nelson B Bolyard nel...@bolyard.me wrote: On 2010-06-10 22:59 PDT, Robin H. Johnson wrote: The testcase has been run on Arch and Fedora now, and both of those cases it works fine. Does that mean this

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-12 Thread Nelson B Bolyard
On 2010-06-12 12:49 PDT, Robin H. Johnson wrote: On Sat, Jun 12, 2010 at 12:15:07PM -0700, Matt McCutchen wrote: On Jun 12, 2:25 pm, Nelson B Bolyard nel...@bolyard.me wrote: On 2010-06-10 22:59 PDT, Robin H. Johnson wrote: The testcase has been run on Arch and Fedora now, and both of those

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-11 Thread Robin H. Johnson
On Thu, Jun 10, 2010 at 10:45:03PM +, Robin H. Johnson wrote: Testcase 2: (see attached minimal C code, based on posts to the list and used in the modutils source AND Mozilla). Bah, forgot the actual file. The testcase has been run on Arch and Fedora now, and both of those cases it works

Re: (nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-11 Thread Robin H. Johnson
On Fri, Jun 11, 2010 at 05:59:27AM +, Robin H. Johnson wrote: On Thu, Jun 10, 2010 at 10:45:03PM +, Robin H. Johnson wrote: Testcase 2: (see attached minimal C code, based on posts to the list and used in the modutils source AND Mozilla). Bah, forgot the actual file. The

(nss-3.12.6) unable to engage FIPS mode: security library: invalid arguments.

2010-06-10 Thread Robin H. Johnson
I was trying to package up the hmaccalc application from Fedora so we can have it in Gentoo as well, and noticed that it was failing when it tried to engage FIPS mode. Doing some backtracing, it seems FIPS isn't enabling at all on my system, as the DeleteInternalModule call is returning