commit mozilla-nss for openSUSE:Factory

2020-10-14 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-10-14 15:38:13

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.3486 (New)


Package is "mozilla-nss"

Wed Oct 14 15:38:13 2020 rev:165 rq:841322 version:3.57

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-10-10 
19:00:44.512375606 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.3486/mozilla-nss.changes
2020-10-14 15:39:05.490360295 +0200
@@ -1,0 +2,6 @@
+Mon Oct 12 15:31:33 UTC 2020 - Dominique Leuenberger 
+
+- Fix build with RPM 4.16: error: bare words are no longer
+  supported, please use "...":  lib64 == lib64.
+
+---



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.sOvb9V/_old  2020-10-14 15:39:06.906360789 +0200
+++ /var/tmp/diff_new_pack.sOvb9V/_new  2020-10-14 15:39:06.906360789 +0200
@@ -82,7 +82,7 @@
 Requires(pre):  libfreebl3 >= %{nss_softokn_fips_version}
 Requires(pre):  libsoftokn3 >= %{nss_softokn_fips_version}
 Requires(pre):  mozilla-nspr >= %{NSPR_min_version}
-%if %{_lib} == lib64
+%if "%{_lib}" == "lib64"
 Requires:   libnssckbi.so()(64bit)
 %else
 Requires:   libnssckbi.so






commit mozilla-nss for openSUSE:Factory

2020-10-10 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-10-10 19:00:34

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.4249 (New)


Package is "mozilla-nss"

Sat Oct 10 19:00:34 2020 rev:164 rq:840031 version:3.57

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-09-29 
18:59:04.053574082 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.4249/mozilla-nss.changes
2020-10-10 19:00:44.512375606 +0200
@@ -1,0 +2,25 @@
+Wed Sep 30 21:06:01 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.57
+  * The following CA certificates were Added:
+bmo#1663049 - CN=Trustwave Global Certification Authority
+SHA-256 Fingerprint: 
97552015F5DDFC3C8788C006944555408894450084F100867086BC1A2BB58DC8
+bmo#1663049 - CN=Trustwave Global ECC P256 Certification Authority
+SHA-256 Fingerprint: 
945BBC825EA554F489D1FD51A73DDF2EA624AC7019A05205225C22A78CCFA8B4
+bmo#1663049 - CN=Trustwave Global ECC P384 Certification Authority
+SHA-256 Fingerprint: 
55903859C8C0C3EBB8759ECE4E2557225FF5758BBD38EBD48276601E1BD58097
+  * The following CA certificates were Removed:
+bmo#1651211 - CN=EE Certification Centre Root CA
+SHA-256 Fingerprint: 
3E84BA4342908516E77573C0992F0979CA084E4685681FF195CCBA8A229B8A76
+bmo#1656077 - O=Government Root Certification Authority; C=TW
+SHA-256 Fingerprint: 
7600295EEFE85B9E1FD624DB76062E59818A54D2774CD4C0B2C01131E1B3
+  * Trust settings for the following CA certificates were Modified:
+bmo#1653092 - CN=OISTE WISeKey Global Root GA CA
+Websites (server authentication) trust bit removed.
+  * 
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes
+- requires NSPR 4.29
+- removed obsolete nss-freebl-fix-aarch64.patch (bmo#1659256)
+- introduced _constraints due to high memory requirements especially
+  for LTO on Tumbleweed
+
+---

Old:

  nss-3.56.tar.gz
  nss-freebl-fix-aarch64.patch

New:

  _constraints
  nss-3.57.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.EBWkdT/_old  2020-10-10 19:00:51.380379016 +0200
+++ /var/tmp/diff_new_pack.EBWkdT/_new  2020-10-10 19:00:51.384379018 +0200
@@ -17,14 +17,14 @@
 #
 
 
-%global nss_softokn_fips_version 3.56
-%define NSPR_min_version 4.28
+%global nss_softokn_fips_version 3.57
+%define NSPR_min_version 4.29
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.56
+Version:3.57
 Release:0
-%define underscore_version 3_56
+%define underscore_version 3_57
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries
@@ -50,26 +50,25 @@
 Patch6: bmo-1400603.patch
 Patch7: nss-sqlitename.patch
 Patch8: ppc-old-abi-v3.patch
-Patch11:nss-fips-use-getrandom.patch
-Patch13:nss-fips-dsa-kat.patch
-Patch15:nss-fips-pairwise-consistency-check.patch
-Patch16:nss-fips-rsa-keygen-strictness.patch
-Patch19:nss-fips-cavs-keywrap.patch
-Patch20:nss-fips-cavs-kas-ffc.patch
-Patch21:nss-fips-cavs-kas-ecc.patch
-Patch22:nss-fips-gcm-ctr.patch
-Patch23:nss-fips-constructor-self-tests.patch
-Patch24:nss-fips-cavs-general.patch
-Patch25:nss-fips-cavs-dsa-fixes.patch
-Patch26:nss-fips-cavs-rsa-fixes.patch
-Patch27:nss-fips-approved-crypto-non-ec.patch
-Patch29:nss-fips-zeroization.patch
-Patch30:nss-fips-tls-allow-md5-prf.patch
-Patch31:nss-fips-use-strong-random-pool.patch
-Patch32:nss-fips-detect-fips-mode-fixes.patch
-Patch34:nss-fips-combined-hash-sign-dsa-ecdsa.patch
-Patch36:nss-fips-aes-keywrap-post.patch
-Patch37:nss-freebl-fix-aarch64.patch
+Patch9: nss-fips-use-getrandom.patch
+Patch10:nss-fips-dsa-kat.patch
+Patch11:nss-fips-pairwise-consistency-check.patch
+Patch12:nss-fips-rsa-keygen-strictness.patch
+Patch13:nss-fips-cavs-keywrap.patch
+Patch14:nss-fips-cavs-kas-ffc.patch
+Patch15:nss-fips-cavs-kas-ecc.patch
+Patch16:nss-fips-gcm-ctr.patch
+Patch17:nss-fips-constructor-self-tests.patch
+Patch18:nss-fips-cavs-general.patch
+Patch19:nss-fips-cavs-dsa-fixes.patch
+Patch20:nss-fips-cavs-rsa-fixes.patch
+Patch21:nss-fips-approved-crypto-non-ec.patch
+Patch22:nss-fips-zeroization.patch
+Patch23:

commit mozilla-nss for openSUSE:Factory

2020-09-29 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-09-29 18:58:59

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.4249 (New)


Package is "mozilla-nss"

Tue Sep 29 18:58:59 2020 rev:163 rq:837281 version:3.56

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-09-24 
16:11:55.488759439 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.4249/mozilla-nss.changes
2020-09-29 18:59:04.053574082 +0200
@@ -1,0 +2,6 @@
+Fri Sep 25 06:55:40 UTC 2020 - Guillaume GARDET 
+
+- Add patch to fix build on aarch64 - boo#1176934:
+  * nss-freebl-fix-aarch64.patch
+
+---

New:

  nss-freebl-fix-aarch64.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.N5v2Np/_old  2020-09-29 18:59:06.397576930 +0200
+++ /var/tmp/diff_new_pack.N5v2Np/_new  2020-09-29 18:59:06.401576935 +0200
@@ -1,7 +1,7 @@
 #
 # spec file for package mozilla-nss
 #
-# Copyright (c) 2020 SUSE LINUX GmbH, Nuernberg, Germany.
+# Copyright (c) 2020 SUSE LLC
 # Copyright (c) 2006-2020 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
@@ -69,6 +69,7 @@
 Patch32:nss-fips-detect-fips-mode-fixes.patch
 Patch34:nss-fips-combined-hash-sign-dsa-ecdsa.patch
 Patch36:nss-fips-aes-keywrap-post.patch
+Patch37:nss-freebl-fix-aarch64.patch
 %if 0%{?sle_version} >= 12 && 0%{?sle_version} < 15
 # aarch64 + gcc4.8 fails to build on SLE-12 due to undefined references
 BuildRequires:  gcc9-c++
@@ -227,6 +228,9 @@
 %patch34 -p1
 %patch36 -p1
 
+# Freebl
+%patch37 -p1
+
 # additional CA certificates
 #cd security/nss/lib/ckfw/builtins
 #cat %{SOURCE2} >> certdata.txt



++ nss-freebl-fix-aarch64.patch ++

diff --git a/lib/freebl/Makefile b/lib/freebl/Makefile
--- a/lib/freebl/Makefile
+++ b/lib/freebl/Makefile
@@ -114,31 +114,47 @@ ifeq (,$(filter-out i386 x386 x86 x86_64
 $(OBJDIR)/gcm-x86.o: CFLAGS += -mpclmul -maes
 $(OBJDIR)/aes-x86.o: CFLAGS += -mpclmul -maes
 ifneq (,$(USE_64)$(USE_X32))
 DEFINES += -DNSS_X64
 else
 DEFINES += -DNSS_X86
 endif
 endif
-ifdef NS_USE_GCC
 ifeq ($(CPU_ARCH),aarch64)
-DEFINES += -DUSE_HW_AES -DUSE_HW_SHA1 -DUSE_HW_SHA2
-EXTRA_SRCS += aes-armv8.c gcm-aarch64.c sha1-armv8.c sha256-armv8.c
-endif
+ifdef CC_IS_CLANG
+DEFINES += -DUSE_HW_AES -DUSE_HW_SHA1 -DUSE_HW_SHA2
+EXTRA_SRCS += aes-armv8.c gcm-aarch64.c sha1-armv8.c sha256-armv8.c
+else ifeq (1,$(CC_IS_GCC))
+# GCC versions older than 4.9 don't support ARM AES. The check
+# is done in two parts, first allows "major.minor" == "4.9",
+# and then rejects any major versions prior to 5. Note that
+# there has been no GCC 4.10, as it was renamed to GCC 5.
+ifneq (,$(filter 4.9,$(word 1,$(GCC_VERSION)).$(word 
2,$(GCC_VERSION
+DEFINES += -DUSE_HW_AES -DUSE_HW_SHA1 -DUSE_HW_SHA2
+EXTRA_SRCS += aes-armv8.c gcm-aarch64.c sha1-armv8.c sha256-armv8.c
+endif
+ifeq (,$(filter 0 1 2 3 4,$(word 1,$(GCC_VERSION
+DEFINES += -DUSE_HW_AES -DUSE_HW_SHA1 -DUSE_HW_SHA2
+EXTRA_SRCS += aes-armv8.c gcm-aarch64.c sha1-armv8.c sha256-armv8.c
+endif
+endif
 endif
 ifeq ($(CPU_ARCH),arm)
 ifndef NSS_DISABLE_ARM32_NEON
 EXTRA_SRCS += gcm-arm32-neon.c
 endif
 ifdef CC_IS_CLANG
 DEFINES += -DUSE_HW_AES -DUSE_HW_SHA1 -DUSE_HW_SHA2
 EXTRA_SRCS += aes-armv8.c sha1-armv8.c sha256-armv8.c
 else ifeq (1,$(CC_IS_GCC))
-# Old compiler doesn't support ARM AES.
+# GCC versions older than 4.9 don't support ARM AES. The check
+# is done in two parts, first allows "major.minor" == "4.9",
+# and then rejects any major versions prior to 5. Note that
+# there has been no GCC 4.10, as it was renamed to GCC 5.
 ifneq (,$(filter 4.9,$(word 1,$(GCC_VERSION)).$(word 
2,$(GCC_VERSION
 DEFINES += -DUSE_HW_AES -DUSE_HW_SHA1 -DUSE_HW_SHA2
 EXTRA_SRCS += aes-armv8.c sha1-armv8.c sha256-armv8.c
 endif
 ifeq (,$(filter 0 1 2 3 4,$(word 1,$(GCC_VERSION
 DEFINES += -DUSE_HW_AES -DUSE_HW_SHA1 -DUSE_HW_SHA2
 EXTRA_SRCS += aes-armv8.c sha1-armv8.c sha256-armv8.c
 endif
@@ -723,24 +739,22 @@ USES_SOFTFLOAT_ABI := $(shell $(CC) -o -
 $(OBJDIR)/$(PROG_PREFIX)aes-armv8$(OBJ_SUFFIX): CFLAGS += -march=armv8-a 
-mfpu=crypto-neon-fp-armv8$(if $(USES_SOFTFLOAT_ABI), -mfloat-abi=softfp)
 $(OBJDIR)/$(PROG_PREFIX)sha1-armv8$(OBJ_SUFFIX): CFLAGS += 

commit mozilla-nss for openSUSE:Factory

2020-09-24 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-09-24 16:11:54

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.4249 (New)


Package is "mozilla-nss"

Thu Sep 24 16:11:54 2020 rev:162 rq:835234 version:3.56

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-09-03 
01:08:30.512354075 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.4249/mozilla-nss.changes
2020-09-24 16:11:55.488759439 +0200
@@ -1,0 +2,36 @@
+Thu Sep 17 13:57:18 UTC 2020 - Hans Petter Jansson 
+
+- Update nss-fips-approved-crypto-non-ec.patch to match RC2 code
+  being moved to deprecated/.
+- Remove nss-fix-dh-pkcs-derive-inverted-logic.patch. This was made
+  obsolete by upstream changes.
+
+---
+Tue Sep  8 20:17:19 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.56
+  Notable changes
+  * bmo#1650702 - Support SHA-1 HW acceleration on ARMv8
+  * bmo#1656981 - Use MPI comba and mulq optimizations on x86-64 MacOS.
+  * bmo#1654142 - Add CPU feature detection for Intel SHA extension.
+  * bmo#1648822 - Add stricter validation of DH keys in FIPS mode.
+  * bmo#1656986 - Properly detect arm64 during GYP build architecture
+  detection.
+  * bmo#1652729 - Add build flag to disable RC2 and relocate to
+  lib/freebl/deprecated.
+  * bmo#1656429 - Correct RTT estimate used in 0-RTT anti-replay.
+  * bmo#1588941 - Send empty certificate message when scheme selection
+  fails.
+  * bmo#1652032 - Fix failure to build in Windows arm64 makefile
+  cross-compilation.
+  * bmo#1625791 - Fix deadlock issue in nssSlot_IsTokenPresent.
+  * bmo#1653975 - Fix 3.53 regression by setting "all" as the default
+  makefile target.
+  * bmo#1659792 - Fix broken libpkix tests with unexpired PayPal cert.
+  * bmo#1659814 - Fix interop.sh failures with newer tls-interop
+  commit and dependencies.
+  * bmo#1656519 - NSPR dependency updated to 4.28
+- do not hard require mozilla-nss-certs-32bit via baselibs
+  (boo#1176206)
+
+---

Old:

  nss-3.55.tar.gz
  nss-fix-dh-pkcs-derive-inverted-logic.patch

New:

  nss-3.56.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.1ojGg9/_old  2020-09-24 16:12:01.056765008 +0200
+++ /var/tmp/diff_new_pack.1ojGg9/_new  2020-09-24 16:12:01.056765008 +0200
@@ -1,7 +1,7 @@
 #
 # spec file for package mozilla-nss
 #
-# Copyright (c) 2020 SUSE LLC
+# Copyright (c) 2020 SUSE LINUX GmbH, Nuernberg, Germany.
 # Copyright (c) 2006-2020 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
@@ -17,14 +17,14 @@
 #
 
 
-%global nss_softokn_fips_version 3.55
-%define NSPR_min_version 4.27
+%global nss_softokn_fips_version 3.56
+%define NSPR_min_version 4.28
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.55
+Version:3.56
 Release:0
-%define underscore_version 3_55
+%define underscore_version 3_56
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries
@@ -68,7 +68,6 @@
 Patch31:nss-fips-use-strong-random-pool.patch
 Patch32:nss-fips-detect-fips-mode-fixes.patch
 Patch34:nss-fips-combined-hash-sign-dsa-ecdsa.patch
-Patch35:nss-fix-dh-pkcs-derive-inverted-logic.patch
 Patch36:nss-fips-aes-keywrap-post.patch
 %if 0%{?sle_version} >= 12 && 0%{?sle_version} < 15
 # aarch64 + gcc4.8 fails to build on SLE-12 due to undefined references
@@ -226,7 +225,6 @@
 %patch31 -p1
 %patch32 -p1
 %patch34 -p1
-%patch35 -p1
 %patch36 -p1
 
 # additional CA certificates

++ baselibs.conf ++
--- /var/tmp/diff_new_pack.1ojGg9/_old  2020-09-24 16:12:01.120765073 +0200
+++ /var/tmp/diff_new_pack.1ojGg9/_new  2020-09-24 16:12:01.120765073 +0200
@@ -2,7 +2,7 @@
   requires "mozilla-nspr- >= 4.25"
   requires "libfreebl3-"
   requires "libsoftokn3-"
-  requires "mozilla-nss-certs-"
+  requires "libnssckbi.so"
 libsoftokn3
   requires "libfreebl3- = "
 libsoftokn3-hmac



++ nss-3.55.tar.gz -> nss-3.56.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.55.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.4249/nss-3.56.tar.gz differ: char 
5, line 1

++ nss-fips-approved-crypto-non-ec.patch ++
--- /var/tmp/diff_new_pack.1ojGg9/_old  2020-09-24 16:12:01.196765149 +0200
+++ /var/tmp/diff_new_pack.1ojGg9/_new  

commit mozilla-nss for openSUSE:Factory

2020-09-02 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-09-03 01:08:00

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.3399 (New)


Package is "mozilla-nss"

Thu Sep  3 01:08:00 2020 rev:161 rq:829609 version:3.55

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-07-30 
09:58:38.391146711 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.3399/mozilla-nss.changes
2020-09-03 01:08:30.512354075 +0200
@@ -1,0 +2,37 @@
+Sat Aug 22 06:41:15 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.55
+  Notable changes
+  * P384 and P521 elliptic curve implementations are replaced with
+verifiable implementations from Fiat-Crypto [0] and ECCKiila [1].
+  * PK11_FindCertInSlot is added. With this function, a given slot
+can be queried with a DER-Encoded certificate, providing performance
+and usability improvements over other mechanisms. (bmo#1649633)
+  * DTLS 1.3 implementation is updated to draft-38. (bmo#1647752)
+  Relevant Bugfixes
+  * bmo#1631583 (CVE-2020-6829, CVE-2020-12400) - Replace P384 and
+P521 with new, verifiable implementations from Fiat-Crypto and ECCKiila.
+  * bmo#1649487 - Move overzealous assertion in VFY_EndWithSignature.
+  * bmo#1631573 (CVE-2020-12401) - Remove unnecessary scalar padding.
+  * bmo#1636771 (CVE-2020-12403) - Explicitly disable multi-part
+ChaCha20 (which was not functioning correctly) and more strictly
+enforce tag length.
+  * bmo#1649648 - Don't memcpy zero bytes (sanitizer fix).
+  * bmo#1649316 - Don't memcpy zero bytes (sanitizer fix).
+  * bmo#1649322 - Don't memcpy zero bytes (sanitizer fix).
+  * bmo#1653202 - Fix initialization bug in blapitest when compiled
+with NSS_DISABLE_DEPRECATED_SEED.
+  * bmo#1646594 - Fix AVX2 detection in makefile builds.
+  * bmo#1649633 - Add PK11_FindCertInSlot to search a given slot
+for a DER-encoded certificate.
+  * bmo#1651520 - Fix slotLock race in NSC_GetTokenInfo.
+  * bmo#1647752 - Update DTLS 1.3 implementation to draft-38.
+  * bmo#1649190 - Run cipher, sdr, and ocsp tests under standard test cycle in 
CI.
+  * bmo#1649226 - Add Wycheproof ECDSA tests.
+  * bmo#1637222 - Consistently enforce IV requirements for DES and 3DES.
+  * bmo#1067214 - Enforce minimum PKCS#1 v1.5 padding length in
+RSA_CheckSignRecover.
+  * bmo#1646324 - Advertise PKCS#1 schemes for certificates in the
+signature_algorithms extension.
+
+---

Old:

  nss-3.54.tar.gz

New:

  nss-3.55.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.B6iuzO/_old  2020-09-03 01:08:37.108356274 +0200
+++ /var/tmp/diff_new_pack.B6iuzO/_new  2020-09-03 01:08:37.112356275 +0200
@@ -17,14 +17,14 @@
 #
 
 
-%global nss_softokn_fips_version 3.54
-%define NSPR_min_version 4.26
+%global nss_softokn_fips_version 3.55
+%define NSPR_min_version 4.27
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.54
+Version:3.55
 Release:0
-%define underscore_version 3_54
+%define underscore_version 3_55
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries



++ nss-3.54.tar.gz -> nss-3.55.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.54.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.3399/nss-3.55.tar.gz differ: char 
5, line 1




commit mozilla-nss for openSUSE:Factory

2020-07-30 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-07-30 09:57:44

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.3592 (New)


Package is "mozilla-nss"

Thu Jul 30 09:57:44 2020 rev:160 rq:823327 version:3.54

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-06-30 
21:52:58.474110783 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.3592/mozilla-nss.changes
2020-07-30 09:58:38.391146711 +0200
@@ -1,0 +2,50 @@
+Thu Jul 23 13:31:51 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.54
+  Notable changes
+  * Support for TLS 1.3 external pre-shared keys (bmo#1603042).
+  * Use ARM Cryptography Extension for SHA256, when available
+(bmo#1528113)
+  * The following CA certificates were Added:
+bmo#1645186 - certSIGN Root CA G2.
+bmo#1645174 - e-Szigno Root CA 2017.
+bmo#1641716 - Microsoft ECC Root Certificate Authority 2017.
+bmo#1641716 - Microsoft RSA Root Certificate Authority 2017.
+  * The following CA certificates were Removed:
+bmo#1645199 - AddTrust Class 1 CA Root.
+bmo#1645199 - AddTrust External CA Root.
+bmo#1641718 - LuxTrust Global Root 2.
+bmo#1639987 - Staat der Nederlanden Root CA - G2.
+bmo#1618402 - Symantec Class 2 Public Primary Certification Authority - G4.
+bmo#1618402 - Symantec Class 1 Public Primary Certification Authority - G4.
+bmo#1618402 - VeriSign Class 3 Public Primary Certification Authority - G3.
+  * A number of certificates had their Email trust bit disabled.
+See bmo#1618402 for a complete list.
+  Bugs fixed
+  * bmo#1528113 - Use ARM Cryptography Extension for SHA256.
+  * bmo#1603042 - Add TLS 1.3 external PSK support.
+  * bmo#1642802 - Add uint128 support for HACL* curve25519 on Windows.
+  * bmo#1645186 - Add "certSIGN Root CA G2" root certificate.
+  * bmo#1645174 - Add Microsec's "e-Szigno Root CA 2017" root certificate.
+  * bmo#1641716 - Add Microsoft's non-EV root certificates.
+  * bmo1621151 - Disable email trust bit for "O=Government
+ Root Certification Authority; C=TW" root.
+  * bmo#1645199 - Remove AddTrust root certificates.
+  * bmo#1641718 - Remove "LuxTrust Global Root 2" root certificate.
+  * bmo#1639987 - Remove "Staat der Nederlanden Root CA - G2" root
+  certificate.
+  * bmo#1618402 - Remove Symantec root certificates and disable email trust
+  bit.
+  * bmo#1640516 - NSS 3.54 should depend on NSPR 4.26.
+  * bmo#1642146 - Fix undefined reference to `PORT_ZAlloc_stub' in seed.c.
+  * bmo#1642153 - Fix infinite recursion building NSS.
+  * bmo#1642638 - Fix fuzzing assertion crash.
+  * bmo#1642871 - Enable SSL_SendSessionTicket after resumption.
+  * bmo#1643123 - Support SSL_ExportEarlyKeyingMaterial with External PSKs.
+  * bmo#1643557 - Fix numerous compile warnings in NSS.
+  * bmo#1644774 - SSL gtests to use ClearServerCache when resetting
+  self-encrypt keys.
+  * bmo#1645479 - Don't use SECITEM_MakeItem in secutil.c.
+  * bmo#1646520 - Stricter enforcement of ASN.1 INTEGER encoding.
+
+---

Old:

  nss-3.53.1.tar.gz

New:

  nss-3.54.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.Tjvwfv/_old  2020-07-30 09:58:45.475153062 +0200
+++ /var/tmp/diff_new_pack.Tjvwfv/_new  2020-07-30 09:58:45.479153065 +0200
@@ -17,14 +17,14 @@
 #
 
 
-%global nss_softokn_fips_version 3.53
-%define NSPR_min_version 4.25
+%global nss_softokn_fips_version 3.54
+%define NSPR_min_version 4.26
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.53.1
+Version:3.54
 Release:0
-%define underscore_version 3_53_1
+%define underscore_version 3_54
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries



++ nss-3.53.1.tar.gz -> nss-3.54.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.53.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.3592/nss-3.54.tar.gz differ: char 
5, line 1




commit mozilla-nss for openSUSE:Factory

2020-06-30 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-06-30 21:52:57

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.3060 (New)


Package is "mozilla-nss"

Tue Jun 30 21:52:57 2020 rev:159 rq:817441 version:3.53.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-06-05 
20:02:36.828412875 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.3060/mozilla-nss.changes
2020-06-30 21:52:58.474110783 +0200
@@ -1,0 +2,59 @@
+Sat Jun 27 21:16:07 UTC 2020 - Wolfgang Rosenauer 
+
+- add FIPS mode patches from SLE stream
+  nss-fips-aes-keywrap-post.patch
+  nss-fips-approved-crypto-non-ec.patch
+  nss-fips-cavs-dsa-fixes.patch
+  nss-fips-cavs-general.patch
+  nss-fips-cavs-kas-ecc.patch
+  nss-fips-cavs-kas-ffc.patch
+  nss-fips-cavs-keywrap.patch
+  nss-fips-cavs-rsa-fixes.patch
+  nss-fips-combined-hash-sign-dsa-ecdsa.patch
+  nss-fips-constructor-self-tests.patch
+  nss-fips-detect-fips-mode-fixes.patch
+  nss-fips-dsa-kat.patch
+  nss-fips-gcm-ctr.patch
+  nss-fips-pairwise-consistency-check.patch
+  nss-fips-rsa-keygen-strictness.patch
+  nss-fips-tls-allow-md5-prf.patch
+  nss-fips-use-getrandom.patch
+  nss-fips-use-strong-random-pool.patch
+  nss-fips-zeroization.patch
+  nss-fix-dh-pkcs-derive-inverted-logic.patch
+
+---
+Tue Jun 23 05:40:12 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.53.1
+  * required for Firefox 78
+  * CVE-2020-12402 - Use constant-time GCD and modular inversion in MPI.
+(bmo#1631597, bsc#1173032)
+
+---
+Sun Jun 21 04:44:40 UTC 2020 - Michel Normand 
+
+- Add ppc-old-abi-v3.patch as per upstream bug
+  https://bugzilla.mozilla.org/show_bug.cgi?id=1642174
+
+---
+Thu Jun 11 20:09:44 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.53
+  Notable changes
+  * SEED is now moved into a new freebl directory freebl/deprecated
+bmo#1636389
+  * SEED will be disabled by default in a future release of NSS. At
+that time, users will need to set the compile-time flag
+(bmo#1622033) to disable that deprecation in order to use the
+algorithm.
+  * Algorithms marked as deprecated will ultimately be removed
+  * Several root certificates in the Mozilla program now set the
+CKA_NSS_SERVER_DISTRUST_AFTER attribute, which NSS consumers
+can query to further refine trust decisions. (bmo#1618404,
+bmo#1621159). If a builtin certificate has a
+CKA_NSS_SERVER_DISTRUST_AFTER timestamp before the SCT or
+NotBefore date of a certificate that builtin issued, then clients
+can elect not to trust it.
+
+---

Old:

  nss-3.52.1.tar.gz

New:

  nss-3.53.1.tar.gz
  nss-fips-aes-keywrap-post.patch
  nss-fips-approved-crypto-non-ec.patch
  nss-fips-cavs-dsa-fixes.patch
  nss-fips-cavs-general.patch
  nss-fips-cavs-kas-ecc.patch
  nss-fips-cavs-kas-ffc.patch
  nss-fips-cavs-keywrap.patch
  nss-fips-cavs-rsa-fixes.patch
  nss-fips-combined-hash-sign-dsa-ecdsa.patch
  nss-fips-constructor-self-tests.patch
  nss-fips-detect-fips-mode-fixes.patch
  nss-fips-dsa-kat.patch
  nss-fips-gcm-ctr.patch
  nss-fips-pairwise-consistency-check.patch
  nss-fips-rsa-keygen-strictness.patch
  nss-fips-tls-allow-md5-prf.patch
  nss-fips-use-getrandom.patch
  nss-fips-use-strong-random-pool.patch
  nss-fips-zeroization.patch
  nss-fix-dh-pkcs-derive-inverted-logic.patch
  ppc-old-abi-v3.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.toDILa/_old  2020-06-30 21:53:07.798139636 +0200
+++ /var/tmp/diff_new_pack.toDILa/_new  2020-06-30 21:53:07.798139636 +0200
@@ -17,14 +17,14 @@
 #
 
 
-%global nss_softokn_fips_version 3.52
+%global nss_softokn_fips_version 3.53
 %define NSPR_min_version 4.25
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.52.1
+Version:3.53.1
 Release:0
-%define underscore_version 3_52_1
+%define underscore_version 3_53_1
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries
@@ -49,7 +49,33 @@
 Patch5: malloc.patch
 Patch6: bmo-1400603.patch
 Patch7: nss-sqlitename.patch
+Patch8: ppc-old-abi-v3.patch
+Patch11:nss-fips-use-getrandom.patch
+Patch13:nss-fips-dsa-kat.patch
+Patch15:nss-fips-pairwise-consistency-check.patch
+Patch16:

commit mozilla-nss for openSUSE:Factory

2020-06-05 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-06-05 20:02:24

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.3606 (New)


Package is "mozilla-nss"

Fri Jun  5 20:02:24 2020 rev:158 rq:810949 version:3.52.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-05-02 
22:15:10.124263455 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.3606/mozilla-nss.changes
2020-06-05 20:02:36.828412875 +0200
@@ -1,0 +2,15 @@
+Tue May 26 09:08:26 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.52.1
+  * required for Firefox 77.0
+  Notable changes
+  * Update NSS to support PKCS#11 v3.0 (bmo#1603628)
+  * Support new PKCS #11 v3.0 Message Interface for AES-GCM and
+ChaChaPoly (bmo#1623374)
+  * Integrate AVX2 ChaCha20, Poly1305, and ChaCha20Poly1305 from HACL*
+(bmo#1612493)
+  * CVE-2020-12399 - Force a fixed length for DSA exponentiation
+(bmo#1631576, boo#1171978)
+- removed obsolete nss-kremlin-ppc64le.patch
+
+---

Old:

  nss-3.51.1.tar.gz
  nss-kremlin-ppc64le.patch

New:

  nss-3.52.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.h2PKiB/_old  2020-06-05 20:02:53.676468139 +0200
+++ /var/tmp/diff_new_pack.h2PKiB/_new  2020-06-05 20:02:53.680468153 +0200
@@ -17,14 +17,14 @@
 #
 
 
-%global nss_softokn_fips_version 3.51
+%global nss_softokn_fips_version 3.52
 %define NSPR_min_version 4.25
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.51.1
+Version:3.52.1
 Release:0
-%define underscore_version 3_51_1
+%define underscore_version 3_52_1
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries
@@ -49,7 +49,6 @@
 Patch5: malloc.patch
 Patch6: bmo-1400603.patch
 Patch7: nss-sqlitename.patch
-Patch8: nss-kremlin-ppc64le.patch
 BuildRequires:  gcc-c++
 BuildRequires:  pkgconfig
 BuildRequires:  pkgconfig(nspr) >= %{NSPR_min_version}
@@ -180,7 +179,6 @@
 %endif
 %patch6 -p1
 %patch7 -p1
-%patch8 -p1
 # additional CA certificates
 #cd security/nss/lib/ckfw/builtins
 #cat %{SOURCE2} >> certdata.txt



++ nss-3.51.1.tar.gz -> nss-3.52.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.51.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.3606/nss-3.52.1.tar.gz differ: char 
5, line 1




commit mozilla-nss for openSUSE:Factory

2020-05-02 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-05-02 22:14:59

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.2738 (New)


Package is "mozilla-nss"

Sat May  2 22:14:59 2020 rev:157 rq:799040 version:3.51.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-04-15 
19:52:15.201538353 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.2738/mozilla-nss.changes
2020-05-02 22:15:10.124263455 +0200
@@ -1,0 +2,5 @@
+Wed Apr 29 13:54:42 UTC 2020 - Martin Liška 
+
+- Set NSS_ENABLE_WERROR=0 in order to fix boo#1169746.
+
+---



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.XsjQil/_old  2020-05-02 22:15:11.484266304 +0200
+++ /var/tmp/diff_new_pack.XsjQil/_new  2020-05-02 22:15:11.488266313 +0200
@@ -199,6 +199,7 @@
 TIME="\"$(date -d "${modified}" "+%%R")\""
 find . -name '*.[ch]' -print -exec sed -i 
"s/__DATE__/${DATE}/g;s/__TIME__/${TIME}/g" {} +
 
+export NSS_ENABLE_WERROR=0
 export NSS_NO_PKCS11_BYPASS=1
 export FREEBL_NO_DEPEND=1
 export FREEBL_LOWHASH=1






commit mozilla-nss for openSUSE:Factory

2020-04-15 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-04-15 19:52:12

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.2738 (New)


Package is "mozilla-nss"

Wed Apr 15 19:52:12 2020 rev:156 rq:793077 version:3.51.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-04-04 
12:05:40.634657764 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.2738/mozilla-nss.changes
2020-04-15 19:52:15.201538353 +0200
@@ -1,0 +2,18 @@
+Sat Apr 11 09:05:47 UTC 2020 - Andreas Stieger 
+
+- update to NSS 3.51.1:
+  * Update Delegated Credentials implementation to draft-07
+(bmo#1617968)
+  * Add workaround option to include both DTLS and TLS versions in
+DTLS supported_versions (bmo#1619102)
+  * Update README: TLS 1.3 is not experimental anymore
+(bmo#1619056)
+  * Don't assert fuzzer behavior in SSL_ParseSessionTicket
+(bmo#1618739)
+  * Fix UBSAN issue in ssl_ParseSessionTicket (bmo#1618915)
+  * Consistently handle NULL slot/session (bmo#1608245)
+  * broken fipstest handling of KI_len (bmo#1608250)
+  * Update Delegated Credentials implementation to draft-07
+(bmo#1617968)
+
+---

Old:

  nss-3.51.tar.gz

New:

  nss-3.51.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.NOgGTL/_old  2020-04-15 19:52:18.041539634 +0200
+++ /var/tmp/diff_new_pack.NOgGTL/_new  2020-04-15 19:52:18.041539634 +0200
@@ -22,9 +22,9 @@
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.51
+Version:3.51.1
 Release:0
-%define underscore_version 3_51
+%define underscore_version 3_51_1
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries



++ nss-3.51.tar.gz -> nss-3.51.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.51.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.2738/nss-3.51.1.tar.gz differ: char 
5, line 1




commit mozilla-nss for openSUSE:Factory

2020-04-04 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-04-04 12:05:24

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.3248 (New)


Package is "mozilla-nss"

Sat Apr  4 12:05:24 2020 rev:155 rq:790238 version:3.51

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-03-14 
09:54:00.435051421 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.3248/mozilla-nss.changes
2020-04-04 12:05:40.634657764 +0200
@@ -1,0 +2,40 @@
+Tue Mar 31 15:14:11 UTC 2020 - Michel Normand 
+
+- Update previous patch nss-kremlin-ppc64le.patch
+  slightly modified to support also ppc64 (BE) versus initial
+  https://github.com/FStarLang/kremlin/issues/166
+
+---
+Tue Mar 31 09:31:14 UTC 2020 - Martin Sirringhaus 
+
+- Add patch nss-kremlin-ppc64le.patch to fix ppc and s390x builds  
+
+---
+Mon Mar 30 13:35:25 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.51
+  * Updated DTLS 1.3 implementation to Draft-34. (bmo#1608892)
+  * Correct swapped PKCS11 values of CKM_AES_CMAC and
+CKM_AES_CMAC_GENERAL (bmo#1611209)
+  * Complete integration of Wycheproof ECDH test cases (bmo#1612259)
+  * Check if PPC __has_include() (bmo#1614183)
+  * Fix a compilation error for ‘getFIPSEnv’ "defined but not used"
+(bmo#1614786)
+  * Send DTLS version numbers in DTLS 1.3 supported_versions extension
+to avoid an incompatibility. (bmo#1615208)
+  * SECU_ReadDERFromFile calls strstr on a string that isn't guaranteed
+to be null-terminated (bmo#1538980)
+  * Correct a warning for comparison of integers of different signs:
+'int' and 'unsigned long' in security/nss/lib/freebl/ecl/ecp_25519.c:88
+(bmo#1561337)
+  * Add test for mp_int clamping (bmo#1609751)
+  * Don't attempt to read the fips_enabled flag on the machine unless
+NSS was built with FIPS enabled (bmo#1582169)
+  * Fix a null pointer dereference in BLAKE2B_Update (bmo#1431940)
+  * Fix compiler warning in secsign.c (bmo#1617387)
+  * Fix a OpenBSD/arm64 compilation error: unused variable 'getauxval'
+(bmo#1618400)
+  * Fix a crash on unaligned CMACContext.aes.keySchedule when using
+AES-NI intrinsics (bmo#1610687)
+
+---

Old:

  nss-3.50.tar.gz

New:

  nss-3.51.tar.gz
  nss-kremlin-ppc64le.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.eg1Y7Y/_old  2020-04-04 12:05:45.786663188 +0200
+++ /var/tmp/diff_new_pack.eg1Y7Y/_new  2020-04-04 12:05:45.790663193 +0200
@@ -17,14 +17,14 @@
 #
 
 
-%global nss_softokn_fips_version 3.50
+%global nss_softokn_fips_version 3.51
 %define NSPR_min_version 4.25
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.50
+Version:3.51
 Release:0
-%define underscore_version 3_50
+%define underscore_version 3_51
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries
@@ -49,6 +49,7 @@
 Patch5: malloc.patch
 Patch6: bmo-1400603.patch
 Patch7: nss-sqlitename.patch
+Patch8: nss-kremlin-ppc64le.patch
 BuildRequires:  gcc-c++
 BuildRequires:  pkgconfig
 BuildRequires:  pkgconfig(nspr) >= %{NSPR_min_version}
@@ -179,6 +180,7 @@
 %endif
 %patch6 -p1
 %patch7 -p1
+%patch8 -p1
 # additional CA certificates
 #cd security/nss/lib/ckfw/builtins
 #cat %{SOURCE2} >> certdata.txt



++ nss-3.50.tar.gz -> nss-3.51.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.50.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.3248/nss-3.51.tar.gz differ: char 
5, line 1

++ nss-kremlin-ppc64le.patch ++
Index: nss/lib/freebl/verified/kremlin/include/kremlin/internal/types.h
===
--- nss.orig/lib/freebl/verified/kremlin/include/kremlin/internal/types.h
+++ nss/lib/freebl/verified/kremlin/include/kremlin/internal/types.h
@@ -56,7 +56,9 @@ typedef const char *Prims_string;
 #include 
 typedef __m128i FStar_UInt128_uint128;
 #elif !defined(KRML_VERIFIED_UINT128) && !defined(_MSC_VER) && \
-(defined(__x86_64__) || defined(__x86_64) || defined(__aarch64__))
+(defined(__x86_64__) || defined(__x86_64) || defined(__aarch64__) || \
+ defined(__powerpc64__) || \
+ defined(__s390x__))
 typedef unsigned __int128 FStar_UInt128_uint128;
 #else
 typedef struct FStar_UInt128_uint128_s {
Index: 

commit mozilla-nss for openSUSE:Factory

2020-03-14 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-03-14 09:54:00

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.3160 (New)


Package is "mozilla-nss"

Sat Mar 14 09:54:00 2020 rev:154 rq:783555 version:3.50

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-02-29 
21:20:14.958010058 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.3160/mozilla-nss.changes
2020-03-14 09:54:00.435051421 +0100
@@ -1,0 +2,16 @@
+Tue Mar  3 21:13:38 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.50
+  * Verified primitives from HACL* were updated, bringing performance
+improvements for several platforms.
+Note that Intel processors with SSE4 but without AVX are currently
+unable to use the improved ChaCha20/Poly1305 due to a build issue;
+such platforms will fall-back to less optimized algorithms.
+See bmo#1609569 for details
+  * Updated DTLS 1.3 implementation to Draft-30.
+See bmo#1599514 for details.
+  * Added NIST SP800-108 KBKDF - PKCS#11 implementation.
+See bmo#1599603 for details.
+  * Several bugfixes and minor changes
+
+---

Old:

  nss-3.49.2.tar.gz

New:

  nss-3.50.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.n71Om7/_old  2020-03-14 09:54:05.779055344 +0100
+++ /var/tmp/diff_new_pack.n71Om7/_new  2020-03-14 09:54:05.783055346 +0100
@@ -17,14 +17,14 @@
 #
 
 
-%global nss_softokn_fips_version 3.49
-%define NSPR_min_version 4.24
+%global nss_softokn_fips_version 3.50
+%define NSPR_min_version 4.25
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.49.2
+Version:3.50
 Release:0
-%define underscore_version 3_49_2
+%define underscore_version 3_50
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries

++ baselibs.conf ++
--- /var/tmp/diff_new_pack.n71Om7/_old  2020-03-14 09:54:05.827055379 +0100
+++ /var/tmp/diff_new_pack.n71Om7/_new  2020-03-14 09:54:05.827055379 +0100
@@ -1,5 +1,5 @@
 mozilla-nss
-  requires "mozilla-nspr- >= 4.23"
+  requires "mozilla-nspr- >= 4.25"
   requires "libfreebl3-"
   requires "libsoftokn3-"
   requires "mozilla-nss-certs-"



++ nss-3.49.2.tar.gz -> nss-3.50.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.49.2.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.3160/nss-3.50.tar.gz differ: char 
5, line 1




commit mozilla-nss for openSUSE:Factory

2020-02-29 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-02-29 21:20:04

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.26092 (New)


Package is "mozilla-nss"

Sat Feb 29 21:20:04 2020 rev:153 rq:780186 version:3.49.2

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-02-14 
16:27:59.275275762 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.26092/mozilla-nss.changes   
2020-02-29 21:20:14.958010058 +0100
@@ -1,0 +2,10 @@
+Thu Feb 27 13:52:10 UTC 2020 - Fridrich Strba 
+
+- Package also the cmac.h needed by blapi.h
+
+---
+Tue Feb 25 13:20:51 UTC 2020 - Guillaume GARDET 
+
+- Disable LTO on %arm as LTO fails on neon errors
+
+---



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.XkuOMC/_old  2020-02-29 21:20:17.282014657 +0100
+++ /var/tmp/diff_new_pack.XkuOMC/_new  2020-02-29 21:20:17.286014665 +0100
@@ -185,7 +185,12 @@
 #make generate
 
 %build
+%ifarch %arm
+# LTO fails on neon errors
+%global _lto_cflags %{nil}
+%else
 %global _lto_cflags %{_lto_cflags} -ffat-lto-objects
+%endif
 cd nss
 modified="$(sed -n '/^/n;s/ - .*$//;p;q' "%{SOURCE99}")"
 DATE="\"$(date -d "${modified}" "+%%b %%e %%Y")\""
@@ -234,7 +239,7 @@
 # copy headers
 cp -rL ../public/nss/*.h %{buildroot}%{_includedir}/nss3
 # copy some freebl include files we also want
-for file in blapi.h alghmac.h
+for file in blapi.h alghmac.h cmac.h
 do
   cp -L ../private/nss/$file %{buildroot}/%{_includedir}/nss3
 done






commit mozilla-nss for openSUSE:Factory

2020-02-14 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-02-14 16:27:50

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.26092 (New)


Package is "mozilla-nss"

Fri Feb 14 16:27:50 2020 rev:152 rq:772451 version:3.49.2

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2020-01-11 
14:38:10.053140337 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.26092/mozilla-nss.changes   
2020-02-14 16:27:59.275275762 +0100
@@ -1,0 +2,23 @@
+Sat Feb  8 16:12:53 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.49.2
+  Fixed bugs:
+  * Fix compilation problems with NEON-specific code in freebl
+(bmo#1608327)
+  * Fix a taskcluster issue with Python 2 / Python 3 (bmo#1608895)
+
+---
+Thu Jan 16 07:01:01 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.49.1
+  3.49.1
+  
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.49.1_release_notes
+  * Cache the most recent PBKDF2 password hash, to speed up repeated
+SDR operations, important with the increased KDF iteration counts 
(bmo#1606992)
+  3.49
+  
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.49_release_notes
+  * The legacy DBM database, libnssdbm, is no longer built by default
+when using gyp builds (bmo#1594933)
+  * several bugfixes
+
+---

Old:

  nss-3.48.tar.gz

New:

  nss-3.49.2.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.QEqmpS/_old  2020-02-14 16:28:07.503280228 +0100
+++ /var/tmp/diff_new_pack.QEqmpS/_new  2020-02-14 16:28:07.503280228 +0100
@@ -2,7 +2,7 @@
 # spec file for package mozilla-nss
 #
 # Copyright (c) 2020 SUSE LLC
-# Copyright (c) 2006-2019 Wolfgang Rosenauer
+# Copyright (c) 2006-2020 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -17,14 +17,14 @@
 #
 
 
-%global nss_softokn_fips_version 3.48
+%global nss_softokn_fips_version 3.49
 %define NSPR_min_version 4.24
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.48
+Version:3.49.2
 Release:0
-%define underscore_version 3_48
+%define underscore_version 3_49_2
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries



++ nss-3.48.tar.gz -> nss-3.49.2.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.48.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.26092/nss-3.49.2.tar.gz differ: 
char 5, line 1




commit mozilla-nss for openSUSE:Factory

2020-01-11 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2020-01-11 14:37:50

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.6675 (New)


Package is "mozilla-nss"

Sat Jan 11 14:37:50 2020 rev:151 rq:761944 version:3.48

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2019-12-11 
12:01:54.296821626 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.6675/mozilla-nss.changes
2020-01-11 14:38:10.053140337 +0100
@@ -1,0 +2,16 @@
+Tue Jan  7 08:24:50 UTC 2020 - Wolfgang Rosenauer 
+
+- update to NSS 3.48
+  
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.48_release_notes
+  Notable Changes
+  * TLS 1.3 is the default maximum TLS version (bmo#1573118)
+  * TLS extended master secret is enabled by default, where possible
+(bmo#1575411)
+  * The master password PBE now uses 10,000 iterations by default when
+using the default sql (key4.db) storage (bmo#1562671)
+  Certificate Authority Changes
+  * Added Entrust Root Certification Authority - G4 Cert (bmo#1591178)
+  Bugfixes
+- requires NSPR 4.24
+
+---
@@ -42,0 +59,2 @@
+  * CVE-2019-17006 Add length checks for cryptographic primitives
+(bmo#1539788)

Old:

  nss-3.47.1.tar.gz

New:

  nss-3.48.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.wWR2an/_old  2020-01-11 14:38:14.717142182 +0100
+++ /var/tmp/diff_new_pack.wWR2an/_new  2020-01-11 14:38:14.721142183 +0100
@@ -1,7 +1,7 @@
 #
 # spec file for package mozilla-nss
 #
-# Copyright (c) 2019 SUSE LLC
+# Copyright (c) 2020 SUSE LLC
 # Copyright (c) 2006-2019 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
@@ -17,14 +17,14 @@
 #
 
 
-%global nss_softokn_fips_version 3.47
-%define NSPR_min_version 4.23
+%global nss_softokn_fips_version 3.48
+%define NSPR_min_version 4.24
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.47.1
+Version:3.48
 Release:0
-%define underscore_version 3_47_1
+%define underscore_version 3_48
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries



++ nss-3.47.1.tar.gz -> nss-3.48.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.47.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.6675/nss-3.48.tar.gz differ: char 
5, line 1




commit mozilla-nss for openSUSE:Factory

2019-12-11 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2019-12-11 12:01:08

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.4691 (New)


Package is "mozilla-nss"

Wed Dec 11 12:01:08 2019 rev:150 rq:754368 version:3.47.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2019-12-02 
11:31:17.334561579 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.4691/mozilla-nss.changes
2019-12-11 12:01:54.296821626 +0100
@@ -5,0 +6 @@
+(boo#1158527)



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.Kr5SMC/_old  2019-12-11 12:02:01.764818485 +0100
+++ /var/tmp/diff_new_pack.Kr5SMC/_new  2019-12-11 12:02:01.764818485 +0100
@@ -1,7 +1,7 @@
 #
 # spec file for package mozilla-nss
 #
-# Copyright (c) 2019 SUSE LLC.
+# Copyright (c) 2019 SUSE LLC
 # Copyright (c) 2006-2019 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
@@ -17,7 +17,7 @@
 #
 
 
-%global nss_softokn_fips_version 3.46
+%global nss_softokn_fips_version 3.47
 %define NSPR_min_version 4.23
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb






commit mozilla-nss for openSUSE:Factory

2019-12-02 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2019-12-02 11:29:10

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.4691 (New)


Package is "mozilla-nss"

Mon Dec  2 11:29:10 2019 rev:149 rq:750687 version:3.47.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2019-11-04 
17:01:18.111933473 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.4691/mozilla-nss.changes
2019-12-02 11:31:17.334561579 +0100
@@ -1,0 +2,24 @@
+Sun Nov 24 07:33:57 UTC 2019 - Wolfgang Rosenauer 
+
+- update to NSS 3.47.1
+  * CVE-2019-11745 - EncryptUpdate should use maxout, not block size
+  * Fix a crash that could be caused by client certificates during startup
+(bmo#1590495)
+  * Fix compile-time warnings from uninitialized variables in a perl script
+(bmo#1589810)
+
+---
+Sun Nov 17 06:23:03 UTC 2019 - Wolfgang Rosenauer 
+
+- update to NSS 3.47
+  * required by Firefox 71.0
+  Notable changes
+  * Support AES HW acceleration on ARMv8 (bmo#1152625)
+  * Allow per-socket run-time ordering of the cipher suites presented
+in ClientHello (bmo#1267894)
+  * Add CMAC to FreeBL and PKCS #11 libraries (bmo#1570501)
+  Bugfixes
+  
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes
+  - requires NSPR 4.23
+
+---

Old:

  nss-3.46.1.tar.gz

New:

  nss-3.47.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.JbEguv/_old  2019-12-02 11:31:23.310558813 +0100
+++ /var/tmp/diff_new_pack.JbEguv/_new  2019-12-02 11:31:23.330558803 +0100
@@ -1,7 +1,7 @@
 #
 # spec file for package mozilla-nss
 #
-# Copyright (c) 2019 SUSE LINUX GmbH, Nuernberg, Germany.
+# Copyright (c) 2019 SUSE LLC.
 # Copyright (c) 2006-2019 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
@@ -18,13 +18,13 @@
 
 
 %global nss_softokn_fips_version 3.46
-%define NSPR_min_version 4.22
+%define NSPR_min_version 4.23
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.46.1
+Version:3.47.1
 Release:0
-%define underscore_version 3_46_1
+%define underscore_version 3_47_1
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries

++ baselibs.conf ++
--- /var/tmp/diff_new_pack.JbEguv/_old  2019-12-02 11:31:23.526558713 +0100
+++ /var/tmp/diff_new_pack.JbEguv/_new  2019-12-02 11:31:23.530558711 +0100
@@ -1,5 +1,5 @@
 mozilla-nss
-  requires "mozilla-nspr- >= 4.22"
+  requires "mozilla-nspr- >= 4.23"
   requires "libfreebl3-"
   requires "libsoftokn3-"
   requires "mozilla-nss-certs-"



++ nss-3.46.1.tar.gz -> nss-3.47.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.46.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.4691/nss-3.47.1.tar.gz differ: char 
5, line 1




commit mozilla-nss for openSUSE:Factory

2019-11-04 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2019-11-04 17:01:15

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.2990 (New)


Package is "mozilla-nss"

Mon Nov  4 17:01:15 2019 rev:148 rq:742855 version:3.46.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2019-10-02 
11:56:07.107458763 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.2990/mozilla-nss.changes
2019-11-04 17:01:18.111933473 +0100
@@ -1,0 +2,19 @@
+Fri Oct 18 20:07:18 UTC 2019 - Wolfgang Rosenauer 
+
+- update to NSS 3.46.1
+  * required by Firefox 70.0
+  Notable changes in 3.46
+  * The following CA certificates were Removed:
+expired Class 2 Primary root certificate
+expired UTN-USERFirst-Client root certificate
+expired Deutsche Telekom Root CA 2 root certificate
+Swisscom Root CA 2 root certificate
+  * Significant improvements to AES-GCM performance on ARM
+  Many bugfixes
+  Bug fixes in 3.46.1
+  * Soft token MAC verification not constant time (bmo#1582343)
+  * Remove arbitrary HKDF output limit by allocating space as needed
+(bmo#1577953)
+- requires NSPR 4.22
+
+---

Old:

  nss-3.45.tar.gz

New:

  nss-3.46.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.XiaYO5/_old  2019-11-04 17:01:24.287940093 +0100
+++ /var/tmp/diff_new_pack.XiaYO5/_new  2019-11-04 17:01:24.295940102 +0100
@@ -17,14 +17,14 @@
 #
 
 
-%global nss_softokn_fips_version 3.45
-%define NSPR_min_version 4.21
+%global nss_softokn_fips_version 3.46
+%define NSPR_min_version 4.22
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 %define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-Version:3.45
+Version:3.46.1
 Release:0
-%define underscore_version 3_45
+%define underscore_version 3_46_1
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries

++ baselibs.conf ++
--- /var/tmp/diff_new_pack.XiaYO5/_old  2019-11-04 17:01:24.627940458 +0100
+++ /var/tmp/diff_new_pack.XiaYO5/_new  2019-11-04 17:01:24.631940462 +0100
@@ -1,5 +1,5 @@
 mozilla-nss
-  requires "mozilla-nspr- >= 4.21"
+  requires "mozilla-nspr- >= 4.22"
   requires "libfreebl3-"
   requires "libsoftokn3-"
   requires "mozilla-nss-certs-"



++ nss-3.45.tar.gz -> nss-3.46.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.45.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.2990/nss-3.46.1.tar.gz differ: char 
5, line 1




commit mozilla-nss for openSUSE:Factory

2019-10-02 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2019-10-02 11:56:05

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.2352 (New)


Package is "mozilla-nss"

Wed Oct  2 11:56:05 2019 rev:147 rq:733663 version:3.45

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2019-09-05 
12:07:10.963887864 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.2352/mozilla-nss.changes
2019-10-02 11:56:07.107458763 +0200
@@ -1,0 +2,5 @@
+Thu Aug 29 01:14:49 UTC 2019 - Martin Pluskal 
+
+- Small packaging cleanup
+
+---



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.78ZuSR/_old  2019-10-02 11:56:09.091453678 +0200
+++ /var/tmp/diff_new_pack.78ZuSR/_new  2019-10-02 11:56:09.095453667 +0200
@@ -19,28 +19,19 @@
 
 %global nss_softokn_fips_version 3.45
 %define NSPR_min_version 4.21
-
+%define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
+%define nssdbdir %{_sysconfdir}/pki/nssdb
 Name:   mozilla-nss
-BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= %{NSPR_min_version}
-BuildRequires:  pkg-config
-BuildRequires:  sqlite-devel
-BuildRequires:  zlib-devel
 Version:3.45
 Release:0
 %define underscore_version 3_45
-# bug437293
-%ifarch ppc64
-Obsoletes:  mozilla-nss-64bit
-%endif
-#
 Summary:Network Security Services
 License:MPL-2.0
 Group:  System/Libraries
-Url:http://www.mozilla.org/projects/security/pki/nss/
+URL:https://www.mozilla.org/projects/security/pki/nss/
 Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_%{underscore_version}_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-%{version}/nss ; cd 
nss-%{version}/nss ; hg up NSS_%{underscore_version}_RTM
-#Source: nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-%%{version}/nss ; cd 
nss-%%{version}/nss ; hg up NSS_%%{underscore_version}_RTM
+#Source: nss-%%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
 Source4:%{name}-rpmlintrc
@@ -58,17 +49,19 @@
 Patch5: malloc.patch
 Patch6: bmo-1400603.patch
 Patch7: nss-sqlitename.patch
-%define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
-PreReq: mozilla-nspr >= %nspr_ver
-PreReq: libfreebl3 >= %{nss_softokn_fips_version}
-PreReq: libsoftokn3 >= %{nss_softokn_fips_version}
+BuildRequires:  gcc-c++
+BuildRequires:  pkgconfig
+BuildRequires:  pkgconfig(nspr) >= %{NSPR_min_version}
+BuildRequires:  pkgconfig(sqlite3)
+BuildRequires:  pkgconfig(zlib)
+Requires(pre):  libfreebl3 >= %{nss_softokn_fips_version}
+Requires(pre):  libsoftokn3 >= %{nss_softokn_fips_version}
+Requires(pre):  mozilla-nspr >= %{NSPR_min_version}
 %if %{_lib} == lib64
 Requires:   libnssckbi.so()(64bit)
 %else
 Requires:   libnssckbi.so
 %endif
-BuildRoot:  %{_tmppath}/%{name}-%{version}-build
-%define nssdbdir %{_sysconfdir}/pki/nssdb
 %ifnarch %sparc
 %if ! 0%{?qemu_user_space_build}
 # disabled temporarily bmo#1236340
@@ -83,18 +76,13 @@
 TLS v1.0, v1.1, v1.2, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3
 certificates, and other security standards.
 
-
 %package devel
 Summary:Network (Netscape) Security Services development files
 Group:  Development/Libraries/C and C++
 Requires:   libfreebl3
 Requires:   libsoftokn3
-Requires:   mozilla-nspr-devel >= %{NSPR_min_version}
 Requires:   mozilla-nss = %{version}-%{release}
-# bug437293
-%ifarch ppc64
-Obsoletes:  mozilla-nss-devel-64bit
-%endif
+Requires:   pkgconfig(nspr) >= %{NSPR_min_version}
 
 %description devel
 Network Security Services (NSS) is a set of libraries designed to
@@ -106,13 +94,12 @@
 %package tools
 Summary:Tools for developing, debugging, and managing applications 
that use NSS
 Group:  System/Management
-PreReq: mozilla-nss >= %{version}
+Requires(pre):  mozilla-nss >= %{version}
 
 %description tools
 The NSS Security Tools allow developers to test, debug, and manage
 applications that use NSS.
 
-
 %package sysinit
 Summary:System NSS Initialization
 Group:  System/Management
@@ -125,7 +112,6 @@
 PKCS #11 modules for NSS and chains with other NSS modules to load
 any system or user configured modules.
 
-
 %package -n libfreebl3
 Summary:Freebl library for the Network Security Services
 Group:  System/Libraries
@@ -140,7 +126,6 @@
 
 This package installs the freebl library from 

commit mozilla-nss for openSUSE:Factory

2019-09-05 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2019-09-05 12:07:05

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.7948 (New)


Package is "mozilla-nss"

Thu Sep  5 12:07:05 2019 rev:146 rq:720828 version:3.45

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2019-07-22 
12:16:04.143733361 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.7948/mozilla-nss.changes
2019-09-05 12:07:10.963887864 +0200
@@ -1,0 +2,73 @@
+Sat Aug  3 21:12:12 UTC 2019 - Wolfgang Rosenauer 
+
+- update to NSS 3.45 (bsc#1141322)
+  * required by Firefox 69.0
+  New functions
+  * PK11_FindRawCertsWithSubject - Finds all certificates on the
+given slot with the given subject distinguished name and returns
+them as DER bytes. If no such certificates can be found, returns
+SECSuccess and sets *results to NULL. If a failure is encountered
+while fetching any of the matching certificates, SECFailure is
+returned and *results will be NULL.
+  Notable changes
+  * bmo#1540403 - Implement Delegated Credentials
+  * bmo#1550579 - Replace ARM32 Curve25519 implementation with one
+from fiat-crypto
+  * bmo#1551129 - Support static linking on Windows
+  * bmo#1552262 - Expose a function PK11_FindRawCertsWithSubject for
+finding certificates with a given subject on a given slot
+  * bmo#1546229 - Add IPSEC IKE support to softoken
+  * bmo#1554616 - Add support for the Elbrus lcc compiler (<=1.23)
+  * bmo#1543874 - Expose an external clock for SSL
+  * bmo#1546477 - Various changes in response to the ongoing FIPS review
+  Certificate Authority Changes
+  * The following CA certificates were Removed:
+bmo#1552374 - CN = Certinomis - Root CA
+  Bugs fixed
+  * bmo#1540541 - Don't unnecessarily strip leading 0's from key material
+during PKCS11 import (CVE-2019-11719)
+  * bmo#1515342 - More thorough input checking (CVE-2019-11729)
+  * bmo#1552208 - Prohibit use of RSASSA-PKCS1-v1_5 algorithms in
+TLS 1.3 (CVE-2019-11727)
+  * bmo#1227090 - Fix a potential divide-by-zero in makePfromQandSeed
+from lib/freebl/pqg.c (static analysis)
+  * bmo#1227096 - Fix a potential divide-by-zero in PQG_VerifyParams
+from lib/freebl/pqg.c  (static analysis)
+  * bmo#1509432 - De-duplicate code between mp_set_long and mp_set_ulong
+  * bmo#1515011 - Fix a mistake with ChaCha20-Poly1305 test code where
+tags could be faked. Only relevant for clients that might have copied
+the unit test code verbatim
+  * bmo#1550022 - Ensure nssutil3 gets built on Android
+  * bmo#1528174 - ChaCha20Poly1305 should no longer modify output
+length on failure
+  * bmo#1549382 - Don't leak in PKCS#11 modules if C_GetSlotInfo()
+returns error
+  * bmo#1551041 - Fix builds using GCC < 4.3 on big-endian architectures
+  * bmo#1554659 - Add versioning to OpenBSD builds to fix link time
+errors using NSS
+  * bmo#1553443 - Send session ticket only after handshake is marked
+as finished
+  * bmo#1550708 - Fix gyp scripts on Solaris SPARC so that libfreebl_64fpu_3.so
+builds
+  * bmo#1554336 - Optimize away unneeded loop in mpi.c
+  * bmo#1559906 - fipstest: use CKM_TLS12_MASTER_KEY_DERIVE instead of vendor
+specific mechanism
+  * bmo#1558126 - TLS_AES_256_GCM_SHA384 should be marked as FIPS compatible
+  * bmo#1555207 - HelloRetryRequestCallback return code for rejecting 0-RTT
+  * bmo#1556591 - Eliminate races in uses of PK11_SetWrapKey
+  * bmo#1558681 - Stop using a global for anti-replay of TLS 1.3 early data
+  * bmo#1561510 - Fix a bug where removing -arch XXX args from CC didn't work
+  * bmo#1561523 - Add a string for the new-ish error
+SSL_ERROR_MISSING_POST_HANDSHAKE_AUTH_EXTENSION
+
+---
+Fri Aug  2 14:43:24 UTC 2019 - Wolfgang Rosenauer 
+
+- split hmac subpackages to match SLE's packaging
+
+---
+Mon Jul 22 07:13:42 UTC 2019 - Martin Liška 
+
+- Use -ffat-lto-objects in order to provide assembly for static libs.
+
+---

Old:

  nss-3.44.1.tar.gz

New:

  nss-3.45.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.kc9rdZ/_old  2019-09-05 12:07:14.599887183 +0200
+++ /var/tmp/diff_new_pack.kc9rdZ/_new  2019-09-05 12:07:14.603887181 +0200
@@ -2,7 +2,7 @@
 # spec file for package mozilla-nss
 #
 # Copyright (c) 2019 SUSE LINUX GmbH, Nuernberg, Germany.
-# Copyright (c) 2006-2018 Wolfgang Rosenauer
+# Copyright (c) 2006-2019 Wolfgang Rosenauer
 #
 # All modifications 

commit mozilla-nss for openSUSE:Factory

2019-07-22 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2019-07-22 12:16:01

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.4126 (New)


Package is "mozilla-nss"

Mon Jul 22 12:16:01 2019 rev:145 rq:713969 version:3.44.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2019-05-17 
23:37:56.866084570 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.4126/mozilla-nss.changes
2019-07-22 12:16:04.143733361 +0200
@@ -1,0 +2,32 @@
+Mon Jul  8 07:14:57 UTC 2019 - Wolfgang Rosenauer 
+
+- update to NSS 3.44.1
+  * required by Firefox 68.0
+  Bugs fixed
+  * bmo#1554336 - Optimize away unneeded loop in mpi.c
+  * bmo#1515342 - More thorough input checking
+  * bmo#1540541 - Don't unnecessarily strip leading 0's from key material
+  during PKCS11 import
+  * bmo#1515236 - Add a SSLKEYLOGFILE enable/disable flag at build.sh
+  * bmo#1546229 - Add IPSEC IKE support to softoken
+  * bmo#1473806 - Fix SECKEY_ConvertToPublicKey handling of non-RSA keys
+  * bmo#1546477 - Updates to testing for FIPS validation
+  * bmo#1552208 - Prohibit use of RSASSA-PKCS1-v1_5 algorithms in TLS 1.3
+  * bmo#1551041 - Unbreak build on GCC < 4.3 big-endian
+
+---
+Wed Jun 12 21:38:18 UTC 2019 - Wolfgang Rosenauer 
+
+- update to NSS 3.44
+  * required by Firefox 68.0
+  New functions
+  * CERT_GetCertificateDer - Access the DER-encoded form of a CERTCertificate
+  Notable changes
+  * It is now possible to build NSS as a static library (bmo#1543545)
+  * Initial support for building for iOS
+  Bugs fixed
+  * full list
+
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.44_release_notes
+- merge some baselibs fixes from SLE
+
+---

Old:

  nss-3.43.tar.gz

New:

  nss-3.44.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.6crtMF/_old  2019-07-22 12:16:07.335732494 +0200
+++ /var/tmp/diff_new_pack.6crtMF/_new  2019-07-22 12:16:07.339732493 +0200
@@ -18,15 +18,17 @@
 
 
 %global nss_softokn_fips_version 3.36
+%define NSPR_min_version 4.21
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.21
+BuildRequires:  mozilla-nspr-devel >= %{NSPR_min_version}
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.43
+Version:3.44.1
 Release:0
+%define underscore_version 3_44_1
 # bug437293
 %ifarch ppc64
 Obsoletes:  mozilla-nss-64bit
@@ -36,8 +38,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_43_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.43/nss ; cd nss-3.43/nss 
; hg up NSS_3_43_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_%{underscore_version}_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-%{version}/nss ; cd 
nss-%{version}/nss ; hg up NSS_%{underscore_version}_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -87,7 +89,7 @@
 Group:  Development/Libraries/C and C++
 Requires:   libfreebl3
 Requires:   libsoftokn3
-Requires:   mozilla-nspr-devel >= 4.20
+Requires:   mozilla-nspr-devel >= %{NSPR_min_version}
 Requires:   mozilla-nss = %{version}-%{release}
 # bug437293
 %ifarch ppc64

++ baselibs.conf ++
--- /var/tmp/diff_new_pack.6crtMF/_old  2019-07-22 12:16:07.375732483 +0200
+++ /var/tmp/diff_new_pack.6crtMF/_new  2019-07-22 12:16:07.375732483 +0200
@@ -1,4 +1,5 @@
 mozilla-nss
+  requires "mozilla-nspr- >= 4.21"
   requires "libfreebl3-"
   requires "libsoftokn3-"
   requires "mozilla-nss-certs-"
@@ -8,5 +9,6 @@
   +/usr/lib/libnssdbm3.chk
 libfreebl3
   +/lib/libfreebl3.chk
+  +/lib/libfreeblpriv3.chk
 mozilla-nss-sysinit
 mozilla-nss-certs



++ nss-3.43.tar.gz -> nss-3.44.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.43.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.4126/nss-3.44.1.tar.gz differ: char 
5, line 1




commit mozilla-nss for openSUSE:Factory

2019-05-17 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2019-05-17 23:37:55

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.5148 (New)


Package is "mozilla-nss"

Fri May 17 23:37:55 2019 rev:144 rq:702840 version:3.43

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2019-03-27 
16:11:45.263662168 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.5148/mozilla-nss.changes
2019-05-17 23:37:56.866084570 +0200
@@ -1,0 +2,35 @@
+Tue Apr 23 12:07:00 UTC 2019 - Wolfgang Rosenauer 
+
+- update to NSS 3.43
+  * required by Firefox 67.0
+  New functions
+  * HASH_GetHashOidTagByHashType - convert type HASH_HashType to type SECOidTag
+  * SSL_SendCertificateRequest - allow server to request post-handshake
+client authentication. To use this both peers need to enable the
+SSL_ENABLE_POST_HANDSHAKE_AUTH option. Note that while the mechanism
+is present, post-handshake authentication is currently not TLS 1.3
+compliant due to bug 1532312
+  Notable changes
+  * The following CA certificates were Added:
+- emSign Root CA - G1
+- emSign ECC Root CA - G3
+- emSign Root CA - C1
+- emSign ECC Root CA - C3
+- Hongkong Post Root CA 3
+  Bugs fixed
+  * Improve Gyp build system handling (bmo#1528669, bmo#1529308)
+  * Improve NSS S/MIME tests for Thunderbird (bmo#1529950, bmo#1521174)
+  * If Docker isn't installed, try running a local clang-format as a
+fallback (bmo#1530134)
+  * Enable FIPS mode automatically if the system FIPS mode flag is set
+(bmo#1531267)
+  * Add a -J option to the strsclnt command to specify sigschemes
+(bmo#1528262)
+  * Add manual for nss-policy-check (bmo#1513909)
+  * Fix a deref after a null check in SECKEY_SetPublicValue (bmo#1531074)
+  * Properly handle ESNI with HRR (bmo#1517714)
+  * Expose HKDF-Expand-Label with mechanism (bmo#1529813)
+  * Align TLS 1.3 HKDF trace levels (bmo#1535122)
+  * Use getentropy on compatible versions of FreeBSD (bmo#1530102)
+
+---

Old:

  nss-3.42.1.tar.gz

New:

  nss-3.43.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.0pBlwi/_old  2019-05-17 23:37:59.026083432 +0200
+++ /var/tmp/diff_new_pack.0pBlwi/_new  2019-05-17 23:37:59.030083430 +0200
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.20
+BuildRequires:  mozilla-nspr-devel >= 4.21
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.42.1
+Version:3.43
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_42_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.42.1/nss ; cd 
nss-3.42.1/nss ; hg up NSS_3_42_1_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_43_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.43/nss ; cd nss-3.43/nss 
; hg up NSS_3_43_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.42.1.tar.gz -> nss-3.43.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.42.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.5148/nss-3.43.tar.gz differ: char 
5, line 1




commit mozilla-nss for openSUSE:Factory

2019-03-27 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2019-03-27 16:11:44

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.25356 (New)


Package is "mozilla-nss"

Wed Mar 27 16:11:44 2019 rev:143 rq:686019 version:3.42.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2019-02-04 
21:24:26.091609984 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.25356/mozilla-nss.changes   
2019-03-27 16:11:45.263662168 +0100
@@ -1,0 +2,14 @@
+Sun Mar 17 09:58:17 UTC 2019 - Wolfgang Rosenauer 
+
+- update to NSS 3.42.1
+  * required by Firefox 66.0
+  New functionality
+  * Support XDG basedir specification (bmo#818686)
+  Notable changes
+  * added some testcases from the Wycheproof project
+  Bugs fixed
+  * Reject invalid CH.legacy_version in TLS 1.3 (bmo#1490006)
+  * A fix for Solaris where Firefox 60 core dumps during start when
+using profile from version 52 (bmo#1513913)
+
+---

Old:

  nss-3.41.1.tar.gz

New:

  nss-3.42.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.BaKofA/_old  2019-03-27 16:11:49.831661003 +0100
+++ /var/tmp/diff_new_pack.BaKofA/_new  2019-03-27 16:11:49.855660997 +0100
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.41.1
+Version:3.42.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_41_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.41.1/nss ; cd 
nss-3.41.1/nss ; hg up NSS_3_41_1_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_42_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.42.1/nss ; cd 
nss-3.42.1/nss ; hg up NSS_3_42_1_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.41.1.tar.gz -> nss-3.42.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.41.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.25356/nss-3.42.1.tar.gz differ: 
char 5, line 1




commit mozilla-nss for openSUSE:Factory

2019-02-04 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2019-02-04 21:24:24

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.28833 (New)


Package is "mozilla-nss"

Mon Feb  4 21:24:24 2019 rev:142 rq:669997 version:3.41.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2018-12-19 
13:26:09.381181650 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.28833/mozilla-nss.changes   
2019-02-04 21:24:26.091609984 +0100
@@ -1,0 +2,42 @@
+Wed Jan 23 16:30:27 UTC 2019 - Wolfgang Rosenauer 
+
+- update to NSS 3.41.1
+  * (3.41) required by Firefox 65.0
+  New functionality
+  * Implemented EKU handling for IPsec IKE. (bmo#1252891)
+  * Enable half-closed states for TLS. (bmo#1423043)
+  * Enabled the following ciphersuites by default: (bmo#1493215)
+TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
+TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
+TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
+TLS_RSA_WITH_AES_256_GCM_SHA384
+  Notable changes
+  * The following CA certificates were added:
+CN = Certigna Root CA
+CN = GTS Root R1
+CN = GTS Root R2
+CN = GTS Root R3
+CN = GTS Root R4
+CN = UCA Global G2 Root
+CN = UCA Extended Validation Root
+  * The following CA certificates were removed:
+CN = AC Raíz Certicámara S.A.
+CN = Certplus Root CA G1
+CN = Certplus Root CA G2
+CN = OpenTrust Root CA G1
+CN = OpenTrust Root CA G2
+CN = OpenTrust Root CA G3
+  Bugs fixed
+  * Reject empty supported_signature_algorithms in Certificate
+Request in TLS 1.2 (bmo#1412829)
+  * Cache side-channel variant of the Bleichenbacher attack (bmo#1485864)
+(CVE-2018-12404)
+  * Resend the same ticket in ClientHello after HelloRetryRequest (bmo#1481271)
+  * Set session_id for external resumption tokens (bmo#1493769)
+  * Reject CCS after handshake is complete in TLS 1.3 (bmo#1507179)
+  * Add additional null checks to several CMS functions to fix a rare
+CMS crash. (bmo#1507135, bmo#1507174) (3.41.1)
+- removed obsolete patches
+  nss-disable-ocsp-test.patch
+
+---

Old:

  nss-3.40.1.tar.gz
  nss-disable-ocsp-test.patch

New:

  nss-3.41.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.mQteJB/_old  2019-02-04 21:24:28.019609508 +0100
+++ /var/tmp/diff_new_pack.mQteJB/_new  2019-02-04 21:24:28.023609506 +0100
@@ -1,7 +1,7 @@
 #
 # spec file for package mozilla-nss
 #
-# Copyright (c) 2018 SUSE LINUX GmbH, Nuernberg, Germany.
+# Copyright (c) 2019 SUSE LINUX GmbH, Nuernberg, Germany.
 # Copyright (c) 2006-2018 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.40.1
+Version:3.41.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_40_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.40.1/nss ; cd 
nss-3.40.1/nss ; hg up NSS_3_40_1_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_41_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.41.1/nss ; cd 
nss-3.41.1/nss ; hg up NSS_3_41_1_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -54,9 +54,8 @@
 Patch3: nss-no-rpath.patch
 Patch4: add-relro-linker-option.patch
 Patch5: malloc.patch
-Patch6: nss-disable-ocsp-test.patch
+Patch6: bmo-1400603.patch
 Patch7: nss-sqlitename.patch
-Patch8: bmo-1400603.patch
 %define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr >= %nspr_ver
 PreReq: libfreebl3 >= %{nss_softokn_fips_version}
@@ -88,7 +87,7 @@
 Group:  Development/Libraries/C and C++
 Requires:   libfreebl3
 Requires:   libsoftokn3
-Requires:   mozilla-nspr-devel >= 4.19
+Requires:   mozilla-nspr-devel >= 4.20
 Requires:   mozilla-nss = %{version}-%{release}
 # bug437293
 %ifarch ppc64
@@ -177,7 +176,6 @@
 %endif
 %patch6 -p1
 %patch7 -p1
-%patch8 -p1
 # additional CA certificates
 #cd security/nss/lib/ckfw/builtins
 #cat %{SOURCE2} >> certdata.txt



++ nss-3.40.1.tar.gz -> nss-3.41.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.40.1.tar.gz 

commit mozilla-nss for openSUSE:Factory

2018-12-19 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2018-12-19 13:26:06

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new.28833 (New)


Package is "mozilla-nss"

Wed Dec 19 13:26:06 2018 rev:141 rq:657061 version:3.40.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2018-10-29 
14:56:55.609732913 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new.28833/mozilla-nss.changes   
2018-12-19 13:26:09.381181650 +0100
@@ -1,0 +2,19 @@
+Mon Dec 10 21:39:03 UTC 2018 - Wolfgang Rosenauer 
+
+- update to NSS 3.40.1
+  * required by Firefox 64.0
+  * patch release fixes CVE-2018-12404
+  Notable bug fixes
+  * FFDHE key exchange sometimes fails with decryption failure (bmo#1478698)
+  New functionality
+  * The draft-00 version of encrypted SNI support is implemented
+  * tstclnt now takes -N option to specify encrypted SNI key
+  Notable changes
+  * The mozilla::pkix library has been ported from Mozilla PSM to NSS.
+This is a C++ library for building certification paths.
+mozilla::pkix APIs are not exposed in the libraries NSS builds.
+  * It is easier to build NSS on Windows in mozilla-build environments
+  * The following CA certificates were Removed:
+CN = Visa eCommerce Root
+
+---

Old:

  nss-3.39.tar.gz

New:

  nss-3.40.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.NeZLC2/_old  2018-12-19 13:26:25.597161919 +0100
+++ /var/tmp/diff_new_pack.NeZLC2/_new  2018-12-19 13:26:25.601161914 +0100
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.39
+Version:3.40.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_39_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.39/nss ; cd nss-3.39/nss 
; hg up NSS_3_39_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_40_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.40.1/nss ; cd 
nss-3.40.1/nss ; hg up NSS_3_40_1_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.39.tar.gz -> nss-3.40.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.39.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new.28833/nss-3.40.1.tar.gz differ: 
char 5, line 1




commit mozilla-nss for openSUSE:Factory

2018-10-29 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2018-10-29 14:15:17

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Mon Oct 29 14:15:17 2018 rev:140 rq:644083 version:3.39

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2018-10-18 
15:29:13.438793367 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2018-10-29 14:56:55.609732913 +0100
@@ -1,0 +2,42 @@
+Sun Oct 21 07:39:58 UTC 2018 - w...@rosenauer.org
+
+- update to NSS 3.39
+  * required by Firefox 63.0
+  Notable bug fixes
+  * NSS responded to an SSLv2-compatible ClientHello with a
+ServerHello that had an all-zero random (CVE-2018-12384) (bmo#1483128)
+  New functionality
+  * The tstclnt and selfserv utilities added support for configuring
+the enabled TLS signature schemes using the -J parameter.
+  * NSS will use RSA-PSS keys to authenticate in TLS. Support for
+these keys is disabled by default but can be enabled using
+SSL_SignatureSchemePrefSet().
+  * certutil added the ability to delete an orphan private key from
+an NSS key database.
+  * Added the nss-policy-check utility, which can be used to check
+an NSS policy configuration for problems.
+  * A PKCS#11 URI can be used as an identifier for a PKCS#11 token.
+  Notable changes
+  * The TLS 1.3 implementation uses the final version number from
+RFC 8446.
+  * Previous versions of NSS accepted an RSA PKCS#1 v1.5 signature
+where the DigestInfo structure was missing the NULL parameter.
+Starting with version 3.39, NSS requires the encoding to contain
+the NULL parameter.
+  * The tstclnt and selfserv test utilities no longer accept the -z
+parameter, as support for TLS compression was removed in a
+previous NSS version.
+  * The CA certificates list was updated to version 2.26.
+  * The following CA certificates were Added:
+- OU = GlobalSign Root CA - R6
+- CN = OISTE WISeKey Global Root GC CA
+  * The following CA certificate was Removed:
+- CN = ComSign
+  * The following CA certificates had the Websites trust bit disabled:
+- CN = Certplus Root CA G1
+- CN = Certplus Root CA G2
+- CN = OpenTrust Root CA G1
+- CN = OpenTrust Root CA G2
+- CN = OpenTrust Root CA G3
+
+---

Old:

  nss-3.38.tar.gz

New:

  nss-3.39.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.7I4LEI/_old  2018-10-29 14:56:57.401739386 +0100
+++ /var/tmp/diff_new_pack.7I4LEI/_new  2018-10-29 14:56:57.401739386 +0100
@@ -13,7 +13,7 @@
 # license that conforms to the Open Source Definition (Version 1.9)
 # published by the Open Source Initiative.
 
-# Please submit bugfixes or comments via http://bugs.opensuse.org/
+# Please submit bugfixes or comments via https://bugs.opensuse.org/
 #
 
 
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.19
+BuildRequires:  mozilla-nspr-devel >= 4.20
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.38
+Version:3.39
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_38_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.38/nss ; cd nss-3.38/nss 
; hg up NSS_3_38_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_39_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.39/nss ; cd nss-3.39/nss 
; hg up NSS_3_39_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -265,6 +265,7 @@
 cp -L  bin/certutil \
bin/cmsutil \
bin/crlutil \
+   bin/nss-policy-check \
bin/modutil \
bin/pk12util \
bin/signtool \



++ malloc.patch ++
--- /var/tmp/diff_new_pack.7I4LEI/_old  2018-10-29 14:56:57.441739529 +0100
+++ /var/tmp/diff_new_pack.7I4LEI/_new  2018-10-29 14:56:57.441739529 +0100
@@ -1,19 +1,8 @@
-# HG changeset patch
-# Parent  032e1235ede0393863f4720ba6746baa24cb68e4
-Index: security/nss/tests/ssl/ssl.sh
-===
-RCS file: /cvsroot/mozilla/security/nss/tests/ssl/ssl.sh,v
-retrieving revision 1.100
-
 diff --git a/tests/ssl/ssl.sh b/tests/ssl/ssl.sh
+index 

commit mozilla-nss for openSUSE:Factory

2018-10-18 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2018-10-18 15:29:09

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Thu Oct 18 15:29:09 2018 rev:139 rq:641946 version:3.38

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2018-10-01 
09:03:08.308011033 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2018-10-18 15:29:13.438793367 +0200
@@ -1,0 +2,5 @@
+Sun Oct 14 08:10:08 UTC 2018 - meiss...@suse.com
+
+- enable PIE support for the included binaries
+
+---



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.aHqleM/_old  2018-10-18 15:29:14.762791813 +0200
+++ /var/tmp/diff_new_pack.aHqleM/_new  2018-10-18 15:29:14.762791813 +0200
@@ -13,7 +13,7 @@
 # license that conforms to the Open Source Definition (Version 1.9)
 # published by the Open Source Initiative.
 
-# Please submit bugfixes or comments via https://bugs.opensuse.org/
+# Please submit bugfixes or comments via http://bugs.opensuse.org/
 #
 
 
@@ -195,7 +195,7 @@
 export FREEBL_LOWHASH=1
 export NSPR_INCLUDE_DIR=`nspr-config --includedir`
 export NSPR_LIB_DIR=`nspr-config --libdir`
-export OPT_FLAGS="%{optflags} -fno-strict-aliasing"
+export OPT_FLAGS="%{optflags} -fno-strict-aliasing -fPIE -pie"
 export LIBDIR=%{_libdir}
 %ifarch x86_64 s390x ppc64 ppc64le ia64 aarch64 riscv64
 export USE_64=1






commit mozilla-nss for openSUSE:Factory

2018-10-01 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2018-10-01 09:03:05

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Mon Oct  1 09:03:05 2018 rev:138 rq:634751 version:3.38

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2018-07-04 
23:48:39.000321782 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2018-10-01 09:03:08.308011033 +0200
@@ -1,0 +2,29 @@
+Fri Aug 10 07:13:18 UTC 2018 - w...@rosenauer.org
+
+- update to NSS 3.38
+  * required by Firefox 62.0
+  New Functionality
+  * Added support for the TLS Record Size Limit Extension
+  * When creating a certificate request (CSR) using certutil -R, an
+existing orphan private key can be reused. Parameter -k may be
+used to specify the ID of an existing orphan key. The available
+orphan key IDs can be displayed using command certutil -K.
+  * When using certutil -O to print the chain for a given certificate
+nickname, the new parameter --simple-self-signed may be provided,
+which can avoid ambiguous output in some scenarios.
+  New Functions
+  * SECITEM_MakeItem - Allocate and make an item with the requested contents
+(secitem.h)
+  New Macros
+  * SSL_RECORD_SIZE_LIMIT - used to control the TLS Record Size Limit
+Extension (in ssl.h)
+  Notable Changes
+  * Fixed CVE-2018-0495 (bmo#1464971)
+  * Various security fixes in the ASN.1 code
+  * NSS automatically enables caching for SQL database storage on
+Linux, if it is located on a network filesystem that's known to
+benefit from caching.
+  * When repeatedly importing the same certificate into an SQL database,
+the existing nickname will be kept.
+
+---

Old:

  nss-3.37.3.tar.gz

New:

  nss-3.38.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.fvtVEz/_old  2018-10-01 09:03:11.028008673 +0200
+++ /var/tmp/diff_new_pack.fvtVEz/_new  2018-10-01 09:03:11.068008638 +0200
@@ -13,7 +13,7 @@
 # license that conforms to the Open Source Definition (Version 1.9)
 # published by the Open Source Initiative.
 
-# Please submit bugfixes or comments via http://bugs.opensuse.org/
+# Please submit bugfixes or comments via https://bugs.opensuse.org/
 #
 
 
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.37.3
+Version:3.38
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_37_3_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.37.3/nss ; cd 
nss-3.37.3/nss ; hg up NSS_3_37_3_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_38_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.38/nss ; cd nss-3.38/nss 
; hg up NSS_3_38_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.37.3.tar.gz -> nss-3.38.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.37.3.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.38.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2018-07-04 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2018-07-04 23:48:37

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Wed Jul  4 23:48:37 2018 rev:137 rq:618894 version:3.37.3

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2018-06-15 
14:32:34.930394330 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2018-07-04 23:48:39.000321782 +0200
@@ -1,0 +2,26 @@
+Sat Jun 23 14:08:46 UTC 2018 - w...@rosenauer.org
+
+- update to NSS 3.37.3
+  * required by Firefox 61.0
+  Notable changes:
+  * The TLS 1.3 implementation was updated to Draft 28.
+  * Added HACL* Poly1305 32-bit
+  * The code to support the NPN protocol has been fully removed.
+  * NSS allows servers now to register ALPN handling callbacks to
+select a protocol.
+  * NSS supports opening SQL databases in read-only mode.
+  * On Linux, some build configurations can use glibc's function
+getentropy(), which uses the kernel's getrandom() function.
+  * The CA list was updated to version 2.24, which removed the
+following CA certificates:
+- CN = S-TRUST Universal Root CA
+- CN = TC TrustCenter Class 3 CA II
+- CN = TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı H5
+  * Fix build on armv6/armv7 and other platforms (bmo#1459739)
+
+---
+Tue Jun 19 15:00:43 UTC 2018 - sch...@suse.de
+
+- Set USE_64 on riscv64
+
+---

Old:

  nss-3.36.4.tar.gz

New:

  nss-3.37.3.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.OCFj9G/_old  2018-07-04 23:48:42.712317674 +0200
+++ /var/tmp/diff_new_pack.OCFj9G/_new  2018-07-04 23:48:42.716317669 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.36.4
+Version:3.37.3
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_36_4_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.36.4/nss ; cd 
nss-3.36.4/nss ; hg up NSS_3_36_4_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_37_3_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.37.3/nss ; cd 
nss-3.37.3/nss ; hg up NSS_3_37_3_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -197,7 +197,7 @@
 export NSPR_LIB_DIR=`nspr-config --libdir`
 export OPT_FLAGS="%{optflags} -fno-strict-aliasing"
 export LIBDIR=%{_libdir}
-%ifarch x86_64 s390x ppc64 ppc64le ia64 aarch64
+%ifarch x86_64 s390x ppc64 ppc64le ia64 aarch64 riscv64
 export USE_64=1
 %endif
 export NSS_USE_SYSTEM_SQLITE=1



++ nss-3.36.4.tar.gz -> nss-3.37.3.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.36.4.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.37.3.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2018-06-15 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2018-06-15 14:32:31

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Fri Jun 15 14:32:31 2018 rev:136 rq:614946 version:3.36.4

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2018-04-26 
13:21:44.495880048 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2018-06-15 14:32:34.930394330 +0200
@@ -1,0 +2,13 @@
+Thu Jun  7 12:30:44 UTC 2018 - w...@rosenauer.org
+
+- update to NSS 3.36.4
+  * required for Firefox 60.0.2 (bsc#1096515)
+  * Fix crash on macOS related to authentication tokens, e.g. PK11or
+WebAuthn. (bmo#1461731)
+  Bugfixes from 3.36.2
+  * Connecting to a server that was recently upgraded to TLS 1.3
+would result in a SSL_RX_MALFORMED_SERVER_HELLO error. (bmo#1462303)
+  * Fix a rare bug with PKCS#12 files. (bmo#1460673)
+- use relro linker option (add-relro-linker-option.patch)
+
+---

Old:

  nss-3.36.1.tar.gz

New:

  add-relro-linker-option.patch
  nss-3.36.4.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.vIkgXy/_old  2018-06-15 14:32:36.922321472 +0200
+++ /var/tmp/diff_new_pack.vIkgXy/_new  2018-06-15 14:32:36.926321325 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.36.1
+Version:3.36.4
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_36_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.36.1/nss ; cd 
nss-3.36.1/nss ; hg up NSS_3_36_1_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_36_4_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.36.4/nss ; cd 
nss-3.36.4/nss ; hg up NSS_3_36_4_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -52,6 +52,7 @@
 Patch1: nss-opt.patch
 Patch2: system-nspr.patch
 Patch3: nss-no-rpath.patch
+Patch4: add-relro-linker-option.patch
 Patch5: malloc.patch
 Patch6: nss-disable-ocsp-test.patch
 Patch7: nss-sqlitename.patch
@@ -170,6 +171,7 @@
 %patch1 -p1
 %patch2 -p1
 %patch3 -p1
+%patch4 -p1
 %if %suse_version > 1110
 %patch5 -p1
 %endif

++ add-relro-linker-option.patch ++
diff -up nss/coreconf/Linux.mk.relro nss/coreconf/Linux.mk
--- nss/coreconf/Linux.mk.relro 2013-04-09 14:29:45.943228682 -0700
+++ nss/coreconf/Linux.mk   2013-04-09 14:31:26.194953927 -0700
@@ -174,6 +174,12 @@ endif
 endif
 endif
 
+# harden DSOs/executables a bit against exploits
+ifeq (2.6,$(firstword $(sort 2.6 $(OS_RELEASE
+DSO_LDOPTS+=-Wl,-z,relro
+LDFLAGS+= -Wl,-z,relro
+endif
+
 USE_SYSTEM_ZLIB = 1
 ZLIB_LIBS = -lz
 


++ nss-3.36.1.tar.gz -> nss-3.36.4.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.36.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.36.4.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2018-04-26 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2018-04-26 13:21:42

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Thu Apr 26 13:21:42 2018 rev:135 rq:600280 version:3.36.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2018-03-24 
16:05:10.509569943 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2018-04-26 13:21:44.495880048 +0200
@@ -1,0 +2,14 @@
+Tue Apr 24 05:58:54 UTC 2018 - w...@rosenauer.org
+
+- update to NSS 3.36.1
+  Notable changes
+  * In NSS version 3.35 the iteration count in optimized builds,
+which is used for password based encryption algorithm related to
+encrypted PKCS#7 or PKCS#12 data, was increased to one million
+iterations. That change had caused an interoperability regression
+with operating systems that are limited to 600 K iterations.
+NSS 3.36.1 has been changed to use the same 600 K limit.
+  Bugs fixed
+  * Certain smartcard operations could result in a deadlock.
+
+---

Old:

  nss-3.36.tar.gz

New:

  nss-3.36.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.BH3jN4/_old  2018-04-26 13:21:46.183818265 +0200
+++ /var/tmp/diff_new_pack.BH3jN4/_new  2018-04-26 13:21:46.187818119 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.36
+Version:3.36.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_36_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.36/nss ; cd nss-3.36/nss 
; hg up NSS_3_36_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_36_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.36.1/nss ; cd 
nss-3.36.1/nss ; hg up NSS_3_36_1_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.36.tar.gz -> nss-3.36.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.36.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.36.1.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2018-03-24 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2018-03-24 16:05:07

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Sat Mar 24 16:05:07 2018 rev:134 rq:587801 version:3.36

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2018-02-24 
16:38:15.323876877 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2018-03-24 16:05:10.509569943 +0100
@@ -1,0 +2,12 @@
+Thu Mar 15 18:13:38 UTC 2018 - cgrobert...@suse.com
+
+- update to NSS 3.36
+  New functionality
+  * Experimental APIs for TLS session cache handling
+  Notable Changes
+  * Replaces existing vectorized ChaCha20 code with verified 
+HACL* implementation.
+- Removed patch as no longer needed: renegotiate-transitional.patch
+  upstream fix
+
+---

Old:

  nss-3.35.tar.gz
  renegotiate-transitional.patch

New:

  nss-3.36.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.F7Njs5/_old  2018-03-24 16:05:12.529497126 +0100
+++ /var/tmp/diff_new_pack.F7Njs5/_new  2018-03-24 16:05:12.541496693 +0100
@@ -17,15 +17,15 @@
 #
 
 
-%global nss_softokn_fips_version 3.35
+%global nss_softokn_fips_version 3.36
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.18
+BuildRequires:  mozilla-nspr-devel >= 4.19
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.35
+Version:3.36
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_35_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.35/nss ; cd nss-3.35/nss 
; hg up NSS_3_35_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_36_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.36/nss ; cd nss-3.36/nss 
; hg up NSS_3_36_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -52,7 +52,6 @@
 Patch1: nss-opt.patch
 Patch2: system-nspr.patch
 Patch3: nss-no-rpath.patch
-Patch4: renegotiate-transitional.patch
 Patch5: malloc.patch
 Patch6: nss-disable-ocsp-test.patch
 Patch7: nss-sqlitename.patch
@@ -88,7 +87,7 @@
 Group:  Development/Libraries/C and C++
 Requires:   libfreebl3
 Requires:   libsoftokn3
-Requires:   mozilla-nspr-devel >= 4.18
+Requires:   mozilla-nspr-devel >= 4.19
 Requires:   mozilla-nss = %{version}-%{release}
 # bug437293
 %ifarch ppc64
@@ -171,7 +170,6 @@
 %patch1 -p1
 %patch2 -p1
 %patch3 -p1
-%patch4 -p1
 %if %suse_version > 1110
 %patch5 -p1
 %endif

++ bmo-1400603.patch ++
--- /var/tmp/diff_new_pack.F7Njs5/_old  2018-03-24 16:05:12.593494819 +0100
+++ /var/tmp/diff_new_pack.F7Njs5/_new  2018-03-24 16:05:12.593494819 +0100
@@ -4,10 +4,8 @@
 Subject: [PATCH] freebl: Reorganize AES-GCM source code based on hw/sw
  implementation
 
-
 diff --git a/lib/freebl/gcm-hw.c b/lib/freebl/gcm-hw.c
 new file mode 100644
-index 000..df77d1e
 --- /dev/null
 +++ b/lib/freebl/gcm-hw.c
 @@ -0,0 +1,151 @@
@@ -164,7 +162,6 @@
 +
 diff --git a/lib/freebl/rijndael-hw.c b/lib/freebl/rijndael-hw.c
 new file mode 100644
-index 000..b9c4b22
 --- /dev/null
 +++ b/lib/freebl/rijndael-hw.c
 @@ -0,0 +1,170 @@



++ malloc.patch ++
--- /var/tmp/diff_new_pack.F7Njs5/_old  2018-03-24 16:05:12.613494098 +0100
+++ /var/tmp/diff_new_pack.F7Njs5/_new  2018-03-24 16:05:12.613494098 +0100
@@ -1,11 +1,19 @@
+# HG changeset patch
+# Parent  032e1235ede0393863f4720ba6746baa24cb68e4
 Index: security/nss/tests/ssl/ssl.sh
 ===
 RCS file: /cvsroot/mozilla/security/nss/tests/ssl/ssl.sh,v
 retrieving revision 1.100
-diff -u -r1.100 ssl.sh
 security/nss/tests/ssl/ssl.sh  26 Mar 2009 23:14:34 -  1.100
-+++ nss/tests/ssl/ssl.sh   6 Jun 2009 06:21:07 -
-@@ -974,6 +974,7 @@
+
+diff --git a/tests/ssl/ssl.sh b/tests/ssl/ssl.sh
+--- a/tests/ssl/ssl.sh
 b/tests/ssl/ssl.sh
+@@ -1354,12 +1354,13 @@ ssl_run_tests()
+ fi
+ ;;
+ esac
+ done
+ }
  
  # main #
  
@@ -13,3 +21,4 @@
  ssl_init
  ssl_run_tests
  ssl_cleanup
+ 

++ 

commit mozilla-nss for openSUSE:Factory

2018-02-24 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2018-02-24 16:38:12

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Sat Feb 24 16:38:12 2018 rev:133 rq:574217 version:3.35

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2018-01-22 
15:56:52.942674065 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2018-02-24 16:38:15.323876877 +0100
@@ -1,0 +2,55 @@
+Thu Feb  8 06:11:12 UTC 2018 - w...@rosenauer.org
+
+- update to NSS 3.35
+  New functionality
+  * TLS 1.3 support has been updated to draft -23. This includes a
+large number of changes since 3.34, which supported only draft
+-18. See below for details.
+  New Types
+  * SSLHandshakeType - The type of a TLS handshake message.
+  * For the SSLSignatureScheme enum, the enumerated values
+ssl_sig_rsa_pss_sha* are deprecated in response to a change in
+TLS 1.3.  Please use the equivalent ssl_sig_rsa_pss_rsae_sha*
+for rsaEncryption keys, or ssl_sig_rsa_pss_pss_sha* for PSS keys.
+Note that this release does not include support for the latter.
+  Notable Changes
+  * Previously, NSS used the DBM file format by default. Starting
+with version 3.35, NSS uses the SQL file format by default.
+Additional information can be found on this Fedora Linux project
+page: https://fedoraproject.org/wiki/Changes/NSSDefaultFileFormatSql
+  * Added formally verified implementations of non-vectorized Chacha20
+and non-vectorized Poly1305 64-bit.
+  * For stronger security, when creating encrypted PKCS#7 or PKCS#12 data,
+the iteration count for the password based encryption algorithm
+has been increased to one million iterations. Note that debug builds
+will use a lower count, for better performance in test environments.
+  * NSS 3.30 had introduced a regression, preventing NSS from reading
+some AES encrypted data, produced by older versions of NSS.
+NSS 3.35 fixes this regression and restores the ability to read
+affected data.
+  * The following CA certificates were Removed:
+OU = Security Communication EV RootCA1
+CN = CA Disig Root R1
+CN = DST ACES CA X6
+Subject CN = VeriSign Class 3 Secure Server CA - G2
+  * The Websites (TLS/SSL) trust bit was turned off for the following
+CA certificates:
+CN = Chambers of Commerce Root
+CN = Global Chambersign Root
+  * TLS servers are able to handle a ClientHello statelessly, if the
+client supports TLS 1.3.  If the server sends a HelloRetryRequest,
+it is possible to discard the server socket, and make a new socket
+to handle any subsequent ClientHello. This better enables stateless
+server operation. (This feature is added in support of QUIC, but it
+also has utility for DTLS 1.3 servers.)
+  * The tstclnt utility now supports DTLS, using the -P option.  Note that
+a DTLS server is also provided in tstclnt.
+  * TLS compression is no longer possible with NSS. The option can be
+enabled, but NSS will no longer negotiate compression.
+  * The signatures of functions SSL_OptionSet, SSL_OptionGet,
+SSL_OptionSetDefault and SSL_OptionGetDefault have been modified,
+to take a PRIntn argument rather than PRBool. This makes it clearer,
+that options can have values other than 0 or 1.  Note this does
+not affect ABI compatibility, because PRBool is a typedef for PRIntn.
+
+---

Old:

  nss-3.34.1.tar.gz

New:

  nss-3.35.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.tjmAvn/_old  2018-02-24 16:38:18.607758691 +0100
+++ /var/tmp/diff_new_pack.tjmAvn/_new  2018-02-24 16:38:18.611758547 +0100
@@ -2,7 +2,7 @@
 # spec file for package mozilla-nss
 #
 # Copyright (c) 2018 SUSE LINUX GmbH, Nuernberg, Germany.
-# Copyright (c) 2006-2017 Wolfgang Rosenauer
+# Copyright (c) 2006-2018 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -17,15 +17,15 @@
 #
 
 
-%global nss_softokn_fips_version 3.34.1
+%global nss_softokn_fips_version 3.35
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.17
+BuildRequires:  mozilla-nspr-devel >= 4.18
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.34.1
+Version:3.35
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:

commit mozilla-nss for openSUSE:Factory

2018-01-22 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2018-01-22 15:56:48

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Mon Jan 22 15:56:48 2018 rev:132 rq:567964 version:3.34.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-12-12 
21:20:34.337371201 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2018-01-22 15:56:52.942674065 +0100
@@ -1,0 +2,53 @@
+Tue Jan  9 12:50:19 UTC 2018 - w...@rosenauer.org
+
+- update to NSS 3.34.1
+  Changes in 3.34:
+  Notable changes
+  * The following CA certificates were Added:
+GDCA TrustAUTH R5 ROOT
+SSL.com Root Certification Authority RSA
+SSL.com Root Certification Authority ECC
+SSL.com EV Root Certification Authority RSA R2
+SSL.com EV Root Certification Authority ECC
+TrustCor RootCert CA-1
+TrustCor RootCert CA-2
+TrustCor ECA-1
+  * The following CA certificates were Removed:
+Certum CA, O=Unizeto Sp. z o.o.
+StartCom Certification Authority
+StartCom Certification Authority G2
+TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı - Sürüm 3
+ACEDICOM Root
+Certinomis - Autorité Racine
+TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı
+PSCProcert
+CA 沃通根证书, O=WoSign CA Limited
+Certification Authority of WoSign
+Certification Authority of WoSign G2
+CA WoSign ECC Root
+  * libfreebl no longer requires SSE2 instructions
+  New functionality
+  * When listing an NSS database using certutil -L, but the database
+hasn't yet been initialized with any non-empty or empty password,
+the text "Database needs user init" will be included in the listing.
+  * When using certutil to set an inacceptable password in FIPS mode,
+a correct explanation of acceptable passwords will be printed.
+  * SSLKEYLOGFILE is now supported with TLS 1.3, see bmo#1287711 for details.
+  * SSLChannelInfo has two new fields (bmo#1396525):
+SSLNamedGroup originalKeaGroup holds the key exchange group of
+the original handshake when the session was resumed.
+PRBool resumed is PR_TRUE when the session is resumed and PR_FALSE
+otherwise.
+  * RSA-PSS signatures are now supported on certificates. Certificates
+with RSA-PSS or RSA-PKCS#1v1.5 keys can be used to create an RSA-PSS
+signature on a certificate using the --pss-sign argument to certutil.
+  Changes in 3.34.1:
+  * The following CA certificate was Re-Added. It was removed in NSS
+3.34, but has been re-added with only the Email trust bit set.
+(bmo#1418678):
+libfreebl no longer requires SSE2 instructionsCN = Certum CA, O=Unizeto 
Sp. z o.o.
+  * Removed entries from certdata.txt for actively distrusted
+certificates that have expired (bmo#1409872)
+  * The version of the CA list was set to 2.20.
+
+---

Old:

  nss-3.33.tar.gz

New:

  nss-3.34.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.KzHeyM/_old  2018-01-22 15:56:56.986484798 +0100
+++ /var/tmp/diff_new_pack.KzHeyM/_new  2018-01-22 15:56:56.990484612 +0100
@@ -1,7 +1,7 @@
 #
 # spec file for package mozilla-nss
 #
-# Copyright (c) 2017 SUSE LINUX GmbH, Nuernberg, Germany.
+# Copyright (c) 2018 SUSE LINUX GmbH, Nuernberg, Germany.
 # Copyright (c) 2006-2017 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
@@ -17,7 +17,7 @@
 #
 
 
-%global nss_softokn_fips_version 3.28
+%global nss_softokn_fips_version 3.34.1
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.33
+Version:3.34.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_33_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.33/nss ; cd nss-3.33/nss 
; hg up NSS_3_33_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_34_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.34.1/nss ; cd 
nss-3.34.1/nss ; hg up NSS_3_34_1_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -88,7 +88,7 @@
 Group:  Development/Libraries/C and C++
 Requires:   libfreebl3
 Requires:   libsoftokn3

commit mozilla-nss for openSUSE:Factory

2017-12-12 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-12-12 21:20:33

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Tue Dec 12 21:20:33 2017 rev:131 rq:555849 version:3.33

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-10-10 
11:35:13.283920834 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-12-12 21:20:34.337371201 +0100
@@ -1,0 +2,6 @@
+Thu Dec  7 11:13:11 UTC 2017 - dims...@opensuse.org
+
+- Escape the usage of %{VERSION} when calling out to rpm.
+  RPM 4.14 has %{VERSION} defined as 'the main packages version'.
+
+---



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.Wz4ikU/_old  2017-12-12 21:20:35.653307675 +0100
+++ /var/tmp/diff_new_pack.Wz4ikU/_new  2017-12-12 21:20:35.657307482 +0100
@@ -57,7 +57,7 @@
 Patch6: nss-disable-ocsp-test.patch
 Patch7: nss-sqlitename.patch
 Patch8: bmo-1400603.patch
-%define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
+%define nspr_ver %(rpm -q --queryformat '%%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr >= %nspr_ver
 PreReq: libfreebl3 >= %{nss_softokn_fips_version}
 PreReq: libsoftokn3 >= %{nss_softokn_fips_version}






commit mozilla-nss for openSUSE:Factory

2017-10-10 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-10-10 11:35:10

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Tue Oct 10 11:35:10 2017 rev:130 rq:531472 version:3.33

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-09-25 
13:55:10.126692551 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-10-10 11:35:13.283920834 +0200
@@ -1,0 +2,39 @@
+Tue Oct  3 17:53:11 UTC 2017 - w...@rosenauer.org
+
+- update to NSS 3.33
+  Notable changes
+  * TLS compression is no longer supported. API calls that attempt
+to enable compression are accepted without failure. However,
+TLS compression will remain disabled.
+  * This version of NSS uses a formally verified implementation of
+Curve25519 on 64-bit systems.
+  * The compile time flag DISABLE_ECC has been removed.
+  * When NSS is compiled without NSS_FORCE_FIPS=1 startup checks
+are not performed anymore.
+  * Various minor improvements and correctness fixes.
+  New functionality
+  * When listing an NSS database using certutil -L, but the database
+hasn't yet been initialized with any non-empty or empty password,
+the text "Database needs user init" will be included in the listing.
+  * When using certutil to set an inacceptable password in FIPS mode,
+a correct explanation of acceptable passwords will be printed.
+  New functions
+  * CERT_FindCertByIssuerAndSNCX - a variation of existing function
+CERT_FindCertByIssuerAndSN that accepts an additional password
+context parameter.
+  * CERT_FindCertByNicknameOrEmailAddrCX - a variation of existing
+function CERT_FindCertByNicknameOrEmailAddr that accepts an
+additional password context parameter.
+  * CERT_FindCertByNicknameOrEmailAddrForUsageCX - a variation of
+existing function CERT_FindCertByNicknameOrEmailAddrForUsage that
+accepts an additional password context parameter.
+  * NSS_SecureMemcmpZero - check if a memory region is all zero in
+constant time.
+  * PORT_ZAllocAligned - allocate aligned memory.
+  * PORT_ZAllocAlignedOffset - allocate aligned memory for structs.
+  * SSL_GetExperimentalAPI - access experimental APIs in libssl.
+- add patch to separate hw and sw implementations for AES and GCM
+  to avoid implicit execution of SSE2 methods if compiled for i586
+  (bmo-1400603.patch, boo#1061204)
+
+---

Old:

  nss-3.32.1.tar.gz

New:

  bmo-1400603.patch
  nss-3.33.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.DquhsI/_old  2017-10-10 11:35:15.183837449 +0200
+++ /var/tmp/diff_new_pack.DquhsI/_new  2017-10-10 11:35:15.191837099 +0200
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.16
+BuildRequires:  mozilla-nspr-devel >= 4.17
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.32.1
+Version:3.33
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_32_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.32.1/nss ; cd 
nss-3.32.1/nss ; hg up NSS_3_32_1_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_33_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.33/nss ; cd nss-3.33/nss 
; hg up NSS_3_33_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -56,6 +56,7 @@
 Patch5: malloc.patch
 Patch6: nss-disable-ocsp-test.patch
 Patch7: nss-sqlitename.patch
+Patch8: bmo-1400603.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr >= %nspr_ver
 PreReq: libfreebl3 >= %{nss_softokn_fips_version}
@@ -176,6 +177,7 @@
 %endif
 %patch6 -p1
 %patch7 -p1
+%patch8 -p1
 # additional CA certificates
 #cd security/nss/lib/ckfw/builtins
 #cat %{SOURCE2} >> certdata.txt

++ bmo-1400603.patch ++
>From b2f3a6407d2d6ec89522410d7ac4c56d310c92b1 Mon Sep 17 00:00:00 2001
From: Daiki Ueno 
Date: Mon, 18 Sep 2017 11:24:00 +0200
Subject: [PATCH] freebl: Reorganize AES-GCM source code based on hw/sw
 implementation


diff --git a/lib/freebl/gcm-hw.c b/lib/freebl/gcm-hw.c
new file mode 100644

commit mozilla-nss for openSUSE:Factory

2017-09-25 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-09-25 13:55:06

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Mon Sep 25 13:55:06 2017 rev:129 rq:528036 version:3.32.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-09-13 
21:36:39.936752395 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-09-25 13:55:10.126692551 +0200
@@ -1,0 +2,32 @@
+Fri Sep 15 13:56:36 UTC 2017 - w...@rosenauer.org
+
+- update to NSS 3.32.1
+  * no upstream changelog/releasenote provided
+
+---
+Tue Sep 12 09:26:03 UTC 2017 - w...@rosenauer.org
+
+- update to NSS 3.32
+  Notable changes
+  * Various minor improvements and correctness fixes.
+  * The Code Signing trust bit was turned off for all included root 
certificates.
+  * The Websites (TLS/SSL) trust bit was turned off for the following
+root certificates:
+AddTrust Class 1 CA Root
+Swisscom Root CA 2
+  * The following CA certificates were Removed:
+AddTrust Public CA Root
+AddTrust Qualified CA Root
+China Internet Network Information Center EV Certificates Root
+CNNIC ROOT
+ComSign Secured CA
+GeoTrust Global CA 2
+Secure Certificate Services
+Swisscom Root CA 1
+Swisscom Root EV CA 2
+Trusted Certificate Services
+UTN-USERFirst-Hardware
+UTN-USERFirst-Object
+- requires NSPR 4.16
+
+---

Old:

  nss-3.31.1.tar.gz

New:

  nss-3.32.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.nFb8Vm/_old  2017-09-25 13:55:13.042282336 +0200
+++ /var/tmp/diff_new_pack.nFb8Vm/_new  2017-09-25 13:55:13.046281774 +0200
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.15
+BuildRequires:  mozilla-nspr-devel >= 4.16
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.31.1
+Version:3.32.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_31_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.31.1/nss ; cd 
nss-3.31.1/nss ; hg up NSS_3_31_1_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_32_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.32.1/nss ; cd 
nss-3.32.1/nss ; hg up NSS_3_32_1_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.31.1.tar.gz -> nss-3.32.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.31.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.32.1.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2017-09-13 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-09-13 21:36:33

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Wed Sep 13 21:36:33 2017 rev:128 rq:523645 version:3.31.1

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-08-17 
11:48:29.880663218 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-09-13 21:36:39.936752395 +0200
@@ -1,0 +2,6 @@
+Tue Sep 12 08:56:48 UTC 2017 - w...@rosenauer.org
+
+- update to NSS 3.31.1
+  * Potential deadlock when using an external PKCS#11 token (bmo#1381784)
+
+---

Old:

  nss-3.31.tar.gz

New:

  nss-3.31.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.kgI1op/_old  2017-09-13 21:37:10.724420592 +0200
+++ /var/tmp/diff_new_pack.kgI1op/_new  2017-09-13 21:37:10.728420029 +0200
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.14
+BuildRequires:  mozilla-nspr-devel >= 4.15
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.31
+Version:3.31.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_31_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.31/nss ; cd nss-3.31/nss 
; hg up NSS_3_31_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_31_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.31.1/nss ; cd 
nss-3.31.1/nss ; hg up NSS_3_31_1_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.31.tar.gz -> nss-3.31.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.31.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.31.1.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2017-08-17 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-08-17 11:47:59

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Thu Aug 17 11:47:59 2017 rev:127 rq:516062 version:3.31

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-05-06 
18:26:17.487674036 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-08-17 11:48:29.880663218 +0200
@@ -1,0 +2,49 @@
+Sat Aug  5 13:15:09 UTC 2017 - w...@rosenauer.org
+
+- update to NSS 3.31
+  New functionality
+  * Allow certificates to be specified by RFC7512 PKCS#11 URIs.
+  * Allow querying a certificate object for its temporary or permanent
+storage status in a thread safe way.
+  New functions
+  * CERT_GetCertIsPerm - retrieve the permanent storage status attribute of a
+certificate in a thread safe way.
+  * CERT_GetCertIsTemp - retrieve the temporary storage status attribute of a
+certificate in a thread safe way.
+  * PK11_FindCertFromURI - find a certificate identified by the given URI.
+  * PK11_FindCertsFromURI - find a list of certificates identified by the given
+URI.
+  * PK11_GetModuleURI - retrieve the URI of the given module.
+  * PK11_GetTokenURI - retrieve the URI of a token based on the given slot
+information.
+  * PK11URI_CreateURI - create a new PK11URI object from a set of attributes.
+  * PK11URI_DestroyURI - destroy a PK11URI object.
+  * PK11URI_FormatURI - format a PK11URI object to a string.
+  * PK11URI_GetPathAttribute - retrieve a path attribute with the given name.
+  * PK11URI_GetQueryAttribute - retrieve a query attribute with the given name.
+  * PK11URI_ParseURI - parse PKCS#11 URI and return a new PK11URI object.
+  New macros
+  * Several new macros that start with PK11URI_PATTR_ for path attributes 
defined
+in RFC7512.
+  * Several new macros that start with PK11URI_QATTR_ for query attributes 
defined
+in RFC7512.
+  Notable changes
+  * The APIs that set a TLS version range have been changed to trim the 
requested
+range to the overlap with a systemwide crypto policy, if configured.
+SSL_VersionRangeGetSupported can be used to query the overlap between the
+library's supported range of TLS versions and the systemwide policy.
+  * Previously, SSL_VersionRangeSet and SSL_VersionRangeSetDefault returned a
+failure if the requested version range wasn't fully allowed by the 
systemwide
+crypto policy. They have been changed to return success, if at least one 
TLS
+version overlaps between the requested range and the systemwide policy. An
+application may call SSL_VersionRangeGet and SSL_VersionRangeGetDefault to
+query the TLS version range that was effectively activated.
+  * Corrected the encoding of Domain Name Constraints extensions created by
+certutil.
+  * NSS supports a clean seeding mechanism for *NIX systems now using only
+/dev/urandom. This is used only when SEED_ONLY_DEV_URANDOM is set at 
compile
+time.
+  * CERT_AsciiToName can handle OIDs in dotted decimal form now.
+- removed obsolete nss-fix-hash.patch
+
+---

Old:

  nss-3.30.2.tar.gz
  nss-fix-hash.patch

New:

  nss-3.31.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.L3dDnE/_old  2017-08-17 11:48:42.970815818 +0200
+++ /var/tmp/diff_new_pack.L3dDnE/_new  2017-08-17 11:48:42.978814689 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.30.2
+Version:3.31
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_30_2_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.30.2/nss ; cd 
nss-3.30.2/nss ; hg up NSS_3_30_2_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_31_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.31/nss ; cd nss-3.31/nss 
; hg up NSS_3_31_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -56,7 +56,6 @@
 Patch5: malloc.patch
 Patch6: nss-disable-ocsp-test.patch
 Patch7: nss-sqlitename.patch
-Patch8: nss-fix-hash.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr >= %nspr_ver
 

commit mozilla-nss for openSUSE:Factory

2017-05-06 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-05-06 18:26:16

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Sat May  6 18:26:16 2017 rev:126 rq:492757 version:3.30.2

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-04-18 
13:47:29.879100604 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-05-06 18:26:17.487674036 +0200
@@ -1,0 +2,52 @@
+Wed Apr 26 21:30:30 UTC 2017 - w...@rosenauer.org
+
+- update to NSS 3.30.2
+  New Functionality
+  * In the PKCS#11 root CA module (nssckbi), CAs with positive trust
+are marked with a new boolean attribute, CKA_NSS_MOZILLA_CA_POLICY,
+set to true. Applications that need to distinguish them from other
+other root CAs, may use the exported function PK11_HasAttributeSet.
+  * Support for callback functions that can be used to monitor SSL/TLS
+alerts that are sent or received.
+  New Functions
+  * CERT_CompareAVA - performs a comparison of two CERTAVA structures,
+and returns a SECComparison result.
+  * PK11_HasAttributeSet - allows to check if a PKCS#11 object in a
+given slot has a specific boolean attribute set.
+  * SSL_AlertReceivedCallback - register a callback function, that will
+be called whenever an SSL/TLS alert is received
+  * SSL_AlertSentCallback - register a callback function, that will be
+called whenever an SSL/TLS alert is sent
+  * SSL_SetSessionTicketKeyPair - configures an asymmetric key pair,
+for use in wrapping session ticket keys, used by the server. This
+function currently only accepts an RSA public/private key pair.
+  New Macros
+  * PKCS12_AES_CBC_128, PKCS12_AES_CBC_192, PKCS12_AES_CBC_256
+cipher family identifiers corresponding to the PKCS#5 v2.1 AES
+based encryption schemes used in the PKCS#12 support in NSS
+  * CKA_NSS_MOZILLA_CA_POLICY - identifier for a boolean PKCS#11
+attribute, that should be set to true, if a CA is present because
+of it's acceptance according to the Mozilla CA Policy
+  Notable Changes
+  * The TLS server code has been enhanced to support session tickets
+when no RSA certificate (e.g. only an ECDSA certificate) is configured.
+  * RSA-PSS signatures produced by key pairs with a modulus bit length
+that is not a multiple of 8 are now supported.
+  * The pk12util tool now supports importing and exporting data encrypted
+in the AES based schemes defined in PKCS#5 v2.1.
+  Root CA updates
+  * The following CA certificates were Removed
+- O = Japanese Government, OU = ApplicationCA
+- CN = WellsSecure Public Root Certificate Authority
+- CN = TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı H6
+- CN = Microsec e-Szigno Root
+  * The following CA certificates were Added
+- CN = D-TRUST Root CA 3 2013
+- CN = TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 1
+  * The version number of the updated root CA list has been set to 2.14
+(bmo#1350859)
+  * Domain name constraints for one of the new CAs have been added to the
+NSS code (bmo#1349705)
+- removed obsolete nss-bmo1320695.patch
+
+---

Old:

  nss-3.29.5.tar.gz
  nss-bmo1320695.patch

New:

  nss-3.30.2.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.GibI0O/_old  2017-05-06 18:26:19.175435885 +0200
+++ /var/tmp/diff_new_pack.GibI0O/_new  2017-05-06 18:26:19.179435320 +0200
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.13.1
+BuildRequires:  mozilla-nspr-devel >= 4.14
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.29.5
+Version:3.30.2
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_29_5_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.29.5/nss ; cd 
nss-3.29.5/nss ; hg up NSS_3_29_5_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_30_2_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.30.2/nss ; cd 
nss-3.30.2/nss ; hg up NSS_3_30_2_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -57,7 +57,6 @@
 Patch6: nss-disable-ocsp-test.patch
 Patch7: 

commit mozilla-nss for openSUSE:Factory

2017-04-18 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-04-18 13:47:28

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Tue Apr 18 13:47:28 2017 rev:125 rq:487715 version:3.29.5

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-03-31 
15:02:08.466699226 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-04-18 13:47:29.879100604 +0200
@@ -1,0 +2,10 @@
+Wed Apr 12 21:21:38 UTC 2017 - w...@rosenauer.org
+
+- update to NSS 3.29.5
+  * Rare crashes in the base 64 decoder and encoder were fixed.
+(bmo#1344380)
+  * A carry over bug in the RNG was fixed. (bmo#1345089)
+- Allow use of session tickets when there is no ticket wrapping key
+  (boo#1015499, bmo#1320695) (nss-bmo1320695.patch)
+
+---

Old:

  nss-3.29.3.tar.gz

New:

  nss-3.29.5.tar.gz
  nss-bmo1320695.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.gte7Bd/_old  2017-04-18 13:47:31.714840777 +0200
+++ /var/tmp/diff_new_pack.gte7Bd/_new  2017-04-18 13:47:31.718840210 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.29.3
+Version:3.29.5
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_29_3_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.29.3/nss ; cd 
nss-3.29.3/nss ; hg up NSS_3_29_3_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_29_5_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.29.5/nss ; cd 
nss-3.29.5/nss ; hg up NSS_3_29_5_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -51,12 +51,13 @@
 Source99:   %{name}.changes
 Patch1: nss-opt.patch
 Patch2: system-nspr.patch
-Patch4: nss-no-rpath.patch
-Patch5: renegotiate-transitional.patch
-Patch6: malloc.patch
-Patch7: nss-disable-ocsp-test.patch
-Patch8: nss-sqlitename.patch
-Patch9: nss-fix-hash.patch
+Patch3: nss-no-rpath.patch
+Patch4: renegotiate-transitional.patch
+Patch5: malloc.patch
+Patch6: nss-disable-ocsp-test.patch
+Patch7: nss-sqlitename.patch
+Patch8: nss-fix-hash.patch
+Patch9: nss-bmo1320695.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr >= %nspr_ver
 PreReq: libfreebl3 >= %{nss_softokn_fips_version}
@@ -170,11 +171,12 @@
 cd nss
 %patch1 -p1
 %patch2 -p1
+%patch3 -p1
 %patch4 -p1
-%patch5 -p1
 %if %suse_version > 1110
-%patch6 -p1
+%patch5 -p1
 %endif
+%patch6 -p1
 %patch7 -p1
 %patch8 -p1
 %patch9 -p1



++ nss-3.29.3.tar.gz -> nss-3.29.5.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.29.3.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.29.5.tar.gz differ: char 5, 
line 1

++ nss-bmo1320695.patch ++
# HG changeset patch
# User Daiki Ueno 
# Date 1481108447 -3600
#  Wed Dec 07 12:00:47 2016 +0100
# Branch wip/dueno/ec-session-ticket
# Node ID 86c3a4cb4eb55f50f80904796f0664e11d9b5d73
# Parent  5796201e791e6cbffc3615cb0c894cf1b0fc09a1
Bug 1320695 - Using SessionTicket extension along with any ECDHE-ECDSA 
ciphersuite renders selfserv unusable

When session ticket is used and wrapping key pair (for caching
generated keys at server side) is not available, disable caching
instead of returning an error.

diff --git a/lib/ssl/ssl3exthandle.c b/lib/ssl/ssl3exthandle.c
--- a/lib/ssl/ssl3exthandle.c
+++ b/lib/ssl/ssl3exthandle.c
@@ -99,21 +99,22 @@ ssl3_GenerateSessionTicketKeys(void *dat
 sslSocket *ss = (sslSocket *)data;
 sslServerCertType certType = { ssl_auth_rsa_decrypt, NULL };
 const sslServerCert *sc;
-SECKEYPrivateKey *svrPrivKey;
-SECKEYPublicKey *svrPubKey;
+SECKEYPrivateKey *svrPrivKey = NULL;
+SECKEYPublicKey *svrPubKey = NULL;
 
 sc = ssl_FindServerCert(ss, );
 if (!sc || !sc->serverKeyPair) {
 SSL_DBG(("%d: SSL[%d]: No ssl_auth_rsa_decrypt cert and key pair",
  SSL_GETPID(), ss->fd));
-goto loser;
-}
-svrPrivKey = sc->serverKeyPair->privKey;
-svrPubKey = sc->serverKeyPair->pubKey;
-if (svrPrivKey == NULL || 

commit mozilla-nss for openSUSE:Factory

2017-03-31 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-03-31 15:02:07

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Fri Mar 31 15:02:07 2017 rev:124 rq:482051 version:3.29.3

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-03-21 
22:44:21.466817939 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-03-31 15:02:08.466699226 +0200
@@ -1,0 +2,9 @@
+Thu Mar 16 20:27:50 UTC 2017 - w...@rosenauer.org
+
+- update to NSS 3.29.3
+  * enables TLS 1.3 by default
+- TLS 1.3 was already enabled in 3.28.x builds for openSUSE.
+  This build option was removed.
+- required for Firefox 53
+
+---

Old:

  nss-3.28.3.tar.gz

New:

  nss-3.29.3.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.3QHUvL/_old  2017-03-31 15:02:10.642391659 +0200
+++ /var/tmp/diff_new_pack.3QHUvL/_new  2017-03-31 15:02:10.642391659 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.28.3
+Version:3.29.3
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_28_3_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.28.3/nss ; cd 
nss-3.28.3/nss ; hg up NSS_3_28_3_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_29_3_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.29.3/nss ; cd 
nss-3.29.3/nss ; hg up NSS_3_29_3_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -200,7 +200,6 @@
 export USE_64=1
 %endif
 export NSS_USE_SYSTEM_SQLITE=1
-export NSS_ENABLE_TLS_1_3=1
 #export SQLITE_LIB_NAME=nsssqlite3
 MAKE_FLAGS="BUILD_OPT=1"
 make nss_build_all $MAKE_FLAGS



++ nss-3.28.3.tar.gz -> nss-3.29.3.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.28.3.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.29.3.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2017-03-21 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-03-21 22:44:19

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Tue Mar 21 22:44:19 2017 rev:123 rq:480619 version:3.28.3

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-02-22 
13:51:30.369636683 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-03-21 22:44:21.466817939 +0100
@@ -1,0 +2,6 @@
+Thu Mar 16 09:11:53 UTC 2017 - rguent...@suse.com
+
+- Add nss-fix-hash.patch to fix hash computation (and build with
+  GCC 7 which complains about shifts of boolean values).
+
+---

New:

  nss-fix-hash.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.cucZzF/_old  2017-03-21 22:44:23.562521657 +0100
+++ /var/tmp/diff_new_pack.cucZzF/_new  2017-03-21 22:44:23.566521092 +0100
@@ -56,6 +56,7 @@
 Patch6: malloc.patch
 Patch7: nss-disable-ocsp-test.patch
 Patch8: nss-sqlitename.patch
+Patch9: nss-fix-hash.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr >= %nspr_ver
 PreReq: libfreebl3 >= %{nss_softokn_fips_version}
@@ -176,6 +177,7 @@
 %endif
 %patch7 -p1
 %patch8 -p1
+%patch9 -p1
 # additional CA certificates
 #cd security/nss/lib/ckfw/builtins
 #cat %{SOURCE2} >> certdata.txt



++ nss-fix-hash.patch ++
--- nss/lib/libpkix/pkix_pl_nss/pki/pkix_pl_ocsprequest.c.orig  2017-03-16 
09:01:59.024372645 +
+++ nss/lib/libpkix/pkix_pl_nss/pki/pkix_pl_ocsprequest.c   2017-03-16 
09:02:37.280938434 +
@@ -89,8 +89,8 @@
 PKIX_HASHCODE(ocspRq->signerCert, , plContext,
 PKIX_CERTHASHCODEFAILED);
 
-*pHashcode = (extensionHash << 8) || certHash) << 8) ||
-dateHash) << 8) || signerHash;
+*pHashcode = (extensionHash << 8) | certHash) << 8) |
+dateHash) << 8) | signerHash;
 
 cleanup:
 



commit mozilla-nss for openSUSE:Factory

2017-02-22 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-02-22 13:51:29

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-02-14 
00:39:42.631850469 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-02-22 13:51:30.369636683 +0100
@@ -1,0 +2,25 @@
+Mon Feb 20 11:53:55 UTC 2017 - w...@rosenauer.org
+
+- update to NSS 3.28.3
+  * This is a patch release to fix binary compatibility issues.
+NSS version 3.28, 3.28.1 and 3.28.2 contained changes that were
+in violation with the NSS compatibility promise.
+
+ECParams, which is part of the public API of the freebl/softokn
+parts of NSS, had been changed to include an additional attribute.
+That size increase caused crashes or malfunctioning with applications
+that use that data structure directly, or indirectly through
+ECPublicKey, ECPrivateKey, NSSLOWKEYPublicKey, NSSLOWKEYPrivateKey,
+or potentially other data structures that reference ECParams.
+The change has been reverted to the original state in bug
+bmo#1334108.
+
+SECKEYECPublicKey had been extended with a new attribute, named
+"encoding". If an application passed type SECKEYECPublicKey to NSS
+(as part of SECKEYPublicKey), the NSS library read the uninitialized
+attribute. With this NSS release SECKEYECPublicKey.encoding is
+deprecated. NSS no longer reads the attribute, and will always
+set it to ECPoint_Undefined. See bug bmo#1340103.
+- requires NSPR >= 4.13.1
+
+---

Old:

  nss-3.28.2.tar.gz

New:

  nss-3.28.3.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.iQ60Tc/_old  2017-02-22 13:51:31.481478437 +0100
+++ /var/tmp/diff_new_pack.iQ60Tc/_new  2017-02-22 13:51:31.481478437 +0100
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.13
+BuildRequires:  mozilla-nspr-devel >= 4.13.1
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.28.2
+Version:3.28.3
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_28_2_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.28.2/nss ; cd 
nss-3.28.2/nss ; hg up NSS_3_28_2_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_28_3_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.28.3/nss ; cd 
nss-3.28.3/nss ; hg up NSS_3_28_3_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.28.2.tar.gz -> nss-3.28.3.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.28.2.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.28.3.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2017-02-13 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-02-14 00:39:41

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2017-02-03 
17:50:45.645913849 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-02-14 00:39:42.631850469 +0100
@@ -1,0 +2,13 @@
+Sun Feb 12 07:31:29 UTC 2017 - w...@rosenauer.org
+
+- update to NSS 3.28.2
+  This is a stability and compatibility release. Below is a summary of
+  the changes.
+  * Fixed a NSS 3.28 regression in the signature scheme flexibility that
+causes connectivity issues between iOS 8 clients and NSS servers
+with ECDSA certificates (bmo#1334114)
+  * Fixed a possible crash on some Windows systems (bmo#1323150)
+  * Fixed a compatibility issue with TLS clients that do not provide a
+list of supported key exchange groups (bmo#1330612)
+
+---

Old:

  nss-3.28.1.tar.gz

New:

  nss-3.28.2.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.aFbvWs/_old  2017-02-14 00:39:45.319471032 +0100
+++ /var/tmp/diff_new_pack.aFbvWs/_new  2017-02-14 00:39:45.323470468 +0100
@@ -2,7 +2,7 @@
 # spec file for package mozilla-nss
 #
 # Copyright (c) 2017 SUSE LINUX GmbH, Nuernberg, Germany.
-# Copyright (c) 2006-2016 Wolfgang Rosenauer
+# Copyright (c) 2006-2017 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.13.1
+BuildRequires:  mozilla-nspr-devel >= 4.13
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.28.1
+Version:3.28.2
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_28_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.28.1/nss ; cd 
nss-3.28.1/nss ; hg up NSS_3_28_1_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_28_2_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.28.2/nss ; cd 
nss-3.28.2/nss ; hg up NSS_3_28_2_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.28.1.tar.gz -> nss-3.28.2.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.28.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.28.2.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2017-02-03 Thread root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2017-01-29 10:29:48

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2016-11-17 
12:19:23.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2017-02-03 17:50:45.645913849 +0100
@@ -1,0 +2,82 @@
+Wed Jan 18 22:00:31 UTC 2017 - w...@rosenauer.org
+
+- update to NSS 3.28.1
+  No new functionality is introduced in this release. This is a patch release 
to
+  update the list of root CA certificates and address a minor TLS compatibility
+  issue that some applications experienced with NSS 3.28.
+  * The following CA certificates were Removed
+CN = Buypass Class 2 CA 1
+CN = Root CA Generalitat Valenciana
+OU = RSA Security 2048 V3
+  * The following CA certificates were Added
+OU = AC RAIZ FNMT-RCM
+CN = Amazon Root CA 1
+CN = Amazon Root CA 2
+CN = Amazon Root CA 3
+CN = Amazon Root CA 4
+CN = LuxTrust Global Root 2
+CN = Symantec Class 1 Public Primary Certification Authority - G4
+CN = Symantec Class 1 Public Primary Certification Authority - G6
+CN = Symantec Class 2 Public Primary Certification Authority - G4
+CN = Symantec Class 2 Public Primary Certification Authority - G6
+  * The version number of the updated root CA list has been set to 2.11
+  * A misleading assertion/alert has been removed when NSS tries to flush data
+to the peer but the connection was already reset.
+- update to NSS 3.28
+  New functionality:
+  * NSS includes support for TLS 1.3 draft -18. This includes a number
+of improvements to TLS 1.3:
+- The signed certificate timestamp, used in certificate
+  transparency, is supported in TLS 1.3.
+- Key exporters for TLS 1.3 are supported. This includes the early
+  key exporter, which can be used if 0-RTT is enabled. Note that
+  there is a difference between TLS 1.3 and key exporters in older
+  versions of TLS. TLS 1.3 does not distinguish between an empty
+  context and no context.
+- The TLS 1.3 (draft) protocol can be enabled, by defining
+  NSS_ENABLE_TLS_1_3=1 when building NSS.
+- NSS includes support for the X25519 key exchange algorithm,
+  which is supported and enabled by default in all versions of TLS.
+  New Functions:
+  * SSL_ExportEarlyKeyingMaterial
+  * SSL_SendAdditionalKeyShares
+  * SSL_SignatureSchemePrefSet
+  * SSL_SignatureSchemePrefGet
+  Notable Changes:
+  * NSS can no longer be compiled with support for additional elliptic curves.
+This was previously possible by replacing certain NSS source files.
+  * NSS will now detect the presence of tokens that support additional
+elliptic curves and enable those curves for use in TLS.
+Note that this detection has a one-off performance cost, which can be
+avoided by using the SSL_NamedGroupConfig function to limit supported
+groups to those that NSS provides.
+  * PKCS#11 bypass for TLS is no longer supported and has been removed.
+  * Support for "export" grade SSL/TLS cipher suites has been removed.
+  * NSS now uses the signature schemes definition in TLS 1.3.
+This also affects TLS 1.2. NSS will now only generate signatures with the
+combinations of hash and signature scheme that are defined in TLS 1.3,
+even when negotiating TLS 1.2.
+- This means that SHA-256 will only be used with P-256 ECDSA certificates,
+  SHA-384 with P-384 certificates, and SHA-512 with P-521 certificates.
+  SHA-1 is permitted (in TLS 1.2 only) with any certificate for backward
+  compatibility reasons.
+- New functions to configure signature schemes are provided:
+  SSL_SignatureSchemePrefSet, SSL_SignatureSchemePrefGet.
+  The old SSL_SignaturePrefSet and SSL_SignaturePrefSet functions are
+  now deprecated.
+- NSS will now no longer assume that default signature schemes are
+  supported by a peer if there was no commonly supported signature scheme.
+  * NSS will now check if RSA-PSS signing is supported by the token that holds
+the private key prior to using it for TLS.
+  * The certificate validation code contains checks to no longer trust
+certificates that are issued by old WoSign and StartCom CAs after
+October 21, 2016. This is equivalent to the behavior that Mozilla will
+release with Firefox 51.
+- update to NSS 3.27.2
+  * SSL_SetTrustAnchors leaks (bmo#1318561)
+- removed upstreamed patch
+  * nss-uninitialized.patch
+- raised the minimum softokn/freebl version to 3.28 as reported in
+  boo#1021636
+
+---

Old:

 

commit mozilla-nss for openSUSE:Factory

2016-11-17 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2016-11-17 12:19:22

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2016-09-25 
14:29:24.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2016-11-17 12:19:23.0 +0100
@@ -1,0 +2,27 @@
+Mon Nov 14 12:35:55 UTC 2016 - w...@rosenauer.org
+
+- update to NSS 3.26.2
+  * required for Firefox 50.0
+  Changes in 3.26
+  New Functionality:
+  * the selfserv test utility has been enhanced to support ALPN
+(HTTP/1.1) and 0-RTT
+  * added support for the System-wide crypto policy available on
+Fedora Linux see http://fedoraproject.org/wiki/Changes/CryptoPolicy
+  * introduced build flag NSS_DISABLE_LIBPKIX that allows compilation
+of NSS without the libpkix library
+  Notable Changes:
+  * The following CA certificate was Added
+CN = ISRG Root X1
+  * NPN is disabled and ALPN is enabled by default
+  * the NSS test suite now completes with the experimental TLS 1.3
+code enabled
+  * several test improvements and additions, including a NIST known answer test
+  Changes in 3.26.2
+  * MD5 signature algorithms sent by the server in CertificateRequest
+messages are now properly ignored. Previously, with rare server
+configurations, an MD5 signature algorithm might have been selected
+for client authentication and caused the client to abort the
+connection soon after.
+
+---

Old:

  nss-3.25.tar.gz

New:

  nss-3.26.2.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.BRuvph/_old  2016-11-17 12:19:25.0 +0100
+++ /var/tmp/diff_new_pack.BRuvph/_new  2016-11-17 12:19:25.0 +0100
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.25
+Version:3.26.2
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_25_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.25/nss ; cd nss-3.25/nss 
; hg up NSS_3_25_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_26_2_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.26.2/nss ; cd 
nss-3.26.2/nss ; hg up NSS_3_26_2_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.25.tar.gz -> nss-3.26.2.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.25.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.26.2.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2016-09-25 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2016-09-25 14:29:21

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2016-08-26 
23:13:23.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2016-09-25 14:29:24.0 +0200
@@ -1,0 +2,35 @@
+Mon Aug 22 13:02:08 UTC 2016 - w...@rosenauer.org
+
+- update to NSS 3.25
+  New functionality:
+  * Implemented DHE key agreement for TLS 1.3
+  * Added support for ChaCha with TLS 1.3
+  * Added support for TLS 1.2 ciphersuites that use SHA384 as the PRF
+  * In previous versions, when using client authentication with TLS 1.2,
+NSS only supported certificate_verify messages that used the same
+signature hash algorithm as used by the PRF. This limitation has
+been removed.
+  * Several functions have been added to the public API of the
+NSS Cryptoki Framework.
+  New functions:
+  * NSSCKFWSlot_GetSlotID
+  * NSSCKFWSession_GetFWSlot
+  * NSSCKFWInstance_DestroySessionHandle
+  * NSSCKFWInstance_FindSessionHandle
+  Notable changes:
+  * An SSL socket can no longer be configured to allow both TLS 1.3 and SSLv3
+  * Regression fix: NSS no longer reports a failure if an application
+attempts to disable the SSLv2 protocol.
+  * The list of trusted CA certificates has been updated to version 2.8
+  * The following CA certificate was Removed
+Sonera Class1 CA
+  * The following CA certificates were Added
+Hellenic Academic and Research Institutions RootCA 2015
+Hellenic Academic and Research Institutions ECC RootCA 2015
+Certplus Root CA G1
+Certplus Root CA G2
+OpenTrust Root CA G1
+OpenTrust Root CA G2
+OpenTrust Root CA G3
+
+---

Old:

  nss-3.24.tar.gz

New:

  nss-3.25.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.0ovNUq/_old  2016-09-25 14:29:27.0 +0200
+++ /var/tmp/diff_new_pack.0ovNUq/_new  2016-09-25 14:29:27.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.24
+Version:3.25
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_24_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.24/nss ; cd nss-3.24/nss 
; hg up NSS_3_24_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_25_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.25/nss ; cd nss-3.25/nss 
; hg up NSS_3_25_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.24.tar.gz -> nss-3.25.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.24.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.25.tar.gz differ: char 5, 
line 1

++ renegotiate-transitional.patch ++
--- /var/tmp/diff_new_pack.0ovNUq/_old  2016-09-25 14:29:27.0 +0200
+++ /var/tmp/diff_new_pack.0ovNUq/_new  2016-09-25 14:29:27.0 +0200
@@ -1,22 +1,13 @@
 diff --git a/lib/ssl/sslsock.c b/lib/ssl/sslsock.c
+index dc83219..276f4a8 100644
 --- a/lib/ssl/sslsock.c
 +++ b/lib/ssl/sslsock.c
-@@ -72,17 +72,17 @@ static sslOptions ssl_defaults = {
- PR_FALSE,
- /* v2CompatibleHello  */ /* now defaults to off in NSS 3.13 */
- PR_TRUE, /* detectRollBack */
- PR_FALSE,/* noStepDown */
- PR_FALSE,/* bypassPKCS11   */
- PR_FALSE,/* noLocks*/
- PR_FALSE,/* enableSessionTickets */
- PR_FALSE,/* enableDeflate  */
--2,   /* enableRenegotiation (default: requires 
extension) */
-+3,   /* enableRenegotiation (default: requires 
extension) */
- PR_FALSE,/* requireSafeNegotiation */
- PR_FALSE,/* enableFalseStart   */
- PR_TRUE, /* cbcRandomIV*/
- PR_FALSE,/* enableOCSPStapling */
- PR_TRUE, /* enableNPN  */
- PR_FALSE,/* enableALPN */
- PR_TRUE, /* reuseServerECDHEKey */
- PR_FALSE,/* 

commit mozilla-nss for openSUSE:Factory

2016-08-26 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2016-08-26 23:13:21

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2016-08-12 
15:33:39.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2016-08-26 23:13:23.0 +0200
@@ -1,0 +2,7 @@
+Mon Aug 22 12:54:15 UTC 2016 - w...@rosenauer.org
+
+- fix build on certain toolchains (nss-uninitialized.patch)
+  jarfile.c:805:13: error: 'it' may be used uninitialized in this
+  function [-Werror=maybe-uninitialized]
+
+---

New:

  nss-uninitialized.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.7PaqfJ/_old  2016-08-26 23:13:24.0 +0200
+++ /var/tmp/diff_new_pack.7PaqfJ/_new  2016-08-26 23:13:24.0 +0200
@@ -51,6 +51,7 @@
 Source99:   %{name}.changes
 Patch1: nss-opt.patch
 Patch2: system-nspr.patch
+Patch3: nss-uninitialized.patch
 Patch4: nss-no-rpath.patch
 Patch5: renegotiate-transitional.patch
 Patch6: malloc.patch
@@ -169,6 +170,7 @@
 cd nss
 %patch1 -p1
 %patch2 -p1
+%patch3 -p1
 %patch4 -p1
 %patch5 -p1
 %if %suse_version > 1110



++ nss-uninitialized.patch ++
diff --git a/lib/jar/jarfile.c b/lib/jar/jarfile.c
--- a/lib/jar/jarfile.c
+++ b/lib/jar/jarfile.c
@@ -652,17 +652,17 @@ jar_gen_index(JAR *jar, jarArch format, 
  *  List the physical contents of a Phil Katz
  *  style .ZIP file into the JAR linked list.
  *
  */
 static int
 jar_listzip(JAR *jar, JAR_FILE fp)
 {
 ZZLink *ent;
-JAR_Item *it;
+JAR_Item *it = NULL;
 JAR_Physical *phy = NULL;
 struct ZipLocal *Local = PORT_ZNew(struct ZipLocal);
 struct ZipCentral *Central = PORT_ZNew(struct ZipCentral);
 struct ZipEnd *End = PORT_ZNew(struct ZipEnd);
 
 int err = 0;
 long pos = 0L;
 unsigned int compression;



commit mozilla-nss for openSUSE:Factory

2016-08-12 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2016-08-12 15:33:38

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2016-06-12 
18:51:20.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2016-08-12 15:33:39.0 +0200
@@ -1,0 +2,93 @@
+Thu Aug  4 20:28:32 UTC 2016 - w...@rosenauer.org
+
+- also sign libfreeblpriv3.so to allow FIPS mode again (boo#992236)
+
+---
+Sat Jul 30 08:53:02 UTC 2016 - w...@rosenauer.org
+
+- update to NSS 3.24
+  New functionality:
+  * NSS softoken has been updated with the latest National Institute
+of Standards and Technology (NIST) guidance (as of 2015):
+- Software integrity checks and POST functions are executed on
+  shared library load. These checks have been disabled by default,
+  as they can cause a performance regression. To enable these
+  checks, you must define symbol NSS_FORCE_FIPS when building NSS.
+- Counter mode and Galois/Counter Mode (GCM) have checks to
+  prevent counter overflow.
+- Additional CSPs are zeroed in the code.
+- NSS softoken uses new guidance for how many Rabin-Miller tests
+  are needed to verify a prime based on prime size.
+  * NSS softoken has also been updated to allow NSS to run in FIPS
+Level 1 (no password). This mode is triggered by setting the
+database password to the empty string. In FIPS mode, you may move
+from Level 1 to Level 2 (by setting an appropriate password),
+but not the reverse.
+  * A SSL_ConfigServerCert function has been added for configuring
+SSL/TLS server sockets with a certificate and private key. Use
+this new function in place of SSL_ConfigSecureServer,
+SSL_ConfigSecureServerWithCertChain, SSL_SetStapledOCSPResponses,
+and SSL_SetSignedCertTimestamps. SSL_ConfigServerCert automatically
+determines the certificate type from the certificate and private key.
+The caller is no longer required to use SSLKEAType explicitly to
+select a "slot" into which the certificate is configured (which
+incorrectly identifies a key agreement type rather than a certificate).
+Separate functions for configuring Online Certificate Status Protocol
+(OCSP) responses or Signed Certificate Timestamps are not needed,
+since these can be added to the optional SSLExtraServerCertData struct
+provided to SSL_ConfigServerCert.  Also, partial support for RSA
+Probabilistic Signature Scheme (RSA-PSS) certificates has been added.
+Although these certificates can be configured, they will not be
+used by NSS in this version.
+  New functions
+  * SSL_ConfigServerCert - Configures an SSL/TLS socket with a
+certificate, private key, and other information.
+  * PORT_InitCheapArena - Initializes an arena that was created on
+the stack. (See PORTCheapArenaPool.=
+  * PORT_DestroyCheapArena - Destroys an arena that was created on
+the stack. (See PORTCheapArenaPool.)
+  New types
+  * SSLExtraServerCertData - Optionally passed as an argument to
+SSL_ConfigServerCert. This struct contains supplementary information
+about a certificate, such as the intended type of the certificate,
+stapled OCSP responses, or Signed Certificate Timestamps (used for
+certificate transparency).
+  * PORTCheapArenaPool - A stack-allocated arena pool, to be used for
+temporary arena allocations.
+  New macros
+  * CKM_TLS12_MAC
+  * SEC_OID_TLS_ECDHE_PSK - This OID governs the use of the
+TLS_ECDHE_PSK_WITH_AES_128_GCM_SHA256 cipher suite, which is used
+only for session resumption in TLS 1.3.
+  Notable changes:
+  * Deprecate the following functions. (Applications should instead use the new
+SSL_ConfigServerCert function.):
+- SSL_SetStapledOCSPResponses
+- SSL_SetSignedCertTimestamps
+- SSL_ConfigSecureServer
+- SSL_ConfigSecureServerWithCertChain
+  * Deprecate the NSS_FindCertKEAType function, as it reports a misleading
+value for certificates that might be used for signing rather than
+key exchange.
+  * Update SSLAuthType to define a larger number of authentication key types.
+  * Deprecate the member attribute authAlgorithm of type SSLCipherSuiteInfo.
+Instead, applications should use the newly added attribute authType.
+  * Rename ssl_auth_rsa to ssl_auth_rsa_decrypt.
+  * Add a shared library (libfreeblpriv3) on Linux platforms that
+define FREEBL_LOWHASH.
+  * Remove most code related to SSL v2, including the ability to actively
+send a SSLv2-compatible client hello. However, the 

commit mozilla-nss for openSUSE:Factory

2016-06-12 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2016-06-12 18:51:18

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2016-05-31 
12:10:07.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2016-06-12 18:51:20.0 +0200
@@ -1,0 +2,46 @@
+Thu May 26 05:59:03 UTC 2016 - w...@rosenauer.org
+
+- update to NSS 3.23
+  New functionality:
+  * ChaCha20/Poly1305 cipher and TLS cipher suites now supported
+  * Experimental-only support TLS 1.3 1-RTT mode (draft-11).
+This code is not ready for production use.
+  New functions:
+  * SSL_SetDowngradeCheckVersion - Set maximum version for new
+ServerRandom anti-downgrade mechanism. Clients that perform a
+version downgrade (which is generally a very bad idea) call this
+with the highest version number that they possibly support.
+This gives them access to the version downgrade protection from
+TLS 1.3.
+  Notable changes:
+  * The copy of SQLite shipped with NSS has been updated to version
+3.10.2
+  * The list of TLS extensions sent in the TLS handshake has been
+reordered to increase compatibility of the Extended Master Secret
+with with servers
+  * The build time environment variable NSS_ENABLE_ZLIB has been
+renamed to NSS_SSL_ENABLE_ZLIB
+  * The build time environment variable NSS_DISABLE_CHACHAPOLY was
+added, which can be used to prevent compilation of the
+ChaCha20/Poly1305 code.
+  * The following CA certificates were Removed
+- Staat der Nederlanden Root CA
+- NetLock Minositett Kozjegyzoi (Class QA) Tanusitvanykiado
+- NetLock Kozjegyzoi (Class A) Tanusitvanykiado
+- NetLock Uzleti (Class B) Tanusitvanykiado
+- NetLock Expressz (Class C) Tanusitvanykiado
+- VeriSign Class 1 Public PCA – G2
+- VeriSign Class 3 Public PCA
+- VeriSign Class 3 Public PCA – G2
+- CA Disig
+  * The following CA certificates were Added
++ SZAFIR ROOT CA2
++ Certum Trusted Network CA 2
+  * The following CA certificate had the Email trust bit turned on
++ Actalis Authentication Root CA
+  Security fixes:
+  * CVE-2016-2834: Memory safety bugs (boo#983639)
+MFSA-2016-61 bmo#1206283 bmo#1221620 bmo#1241034 bmo#1241037
+- removed obsolete nss_gcc6_change.patch
+
+---
@@ -13,0 +60,5 @@
+  * Fixed a heap-based buffer overflow related to the parsing of
+certain ASN.1 structures. An attacker could create a specially-crafted
+certificate which, when parsed by NSS, would cause a crash or
+execution of arbitrary code with the permissions of the user.
+(CVE-2016-1950, bmo#1245528)

Old:

  nss-3.22.3.tar.gz
  nss_gcc6_change.patch

New:

  nss-3.23.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.L4xRhd/_old  2016-06-12 18:51:21.0 +0200
+++ /var/tmp/diff_new_pack.L4xRhd/_new  2016-06-12 18:51:21.0 +0200
@@ -2,7 +2,7 @@
 # spec file for package mozilla-nss
 #
 # Copyright (c) 2016 SUSE LINUX GmbH, Nuernberg, Germany.
-# Copyright (c) 2006-2015 Wolfgang Rosenauer
+# Copyright (c) 2006-2016 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.22.3
+Version:3.23
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_22_3_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.22.3/nss ; cd 
nss-3.22.3/nss ; hg up NSS_3_22_3_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_23_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.23/nss ; cd nss-3.23/nss 
; hg up NSS_3_23_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -57,7 +57,6 @@
 Patch7: nss-disable-ocsp-test.patch
 Patch8: nss-sqlitename.patch
 Patch9: nss-bmo1236011.patch
-Patch10:nss_gcc6_change.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr >= %nspr_ver
 PreReq: libfreebl3 >= 

commit mozilla-nss for openSUSE:Factory

2016-05-31 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2016-05-31 12:10:06

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2016-04-11 
09:12:17.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2016-05-31 12:10:07.0 +0200
@@ -1,0 +2,5 @@
+Mon Apr 18 15:53:40 UTC 2016 - norm...@linux.vnet.ibm.com
+
+-  add nss_gcc6_change.patch
+
+---

New:

  nss_gcc6_change.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.bisC5U/_old  2016-05-31 12:10:08.0 +0200
+++ /var/tmp/diff_new_pack.bisC5U/_new  2016-05-31 12:10:08.0 +0200
@@ -57,6 +57,7 @@
 Patch7: nss-disable-ocsp-test.patch
 Patch8: nss-sqlitename.patch
 Patch9: nss-bmo1236011.patch
+Patch10:nss_gcc6_change.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr >= %nspr_ver
 PreReq: libfreebl3 >= %{nss_softokn_fips_version}
@@ -178,6 +179,7 @@
 %patch7 -p1
 %patch8 -p1
 %patch9 -p1
+%patch10 -p1
 # additional CA certificates
 #cd security/nss/lib/ckfw/builtins
 #cat %{SOURCE2} >> certdata.txt



++ nss_gcc6_change.patch ++
From: Michel Normand 
Subject: nss gcc6 change
Date: Mon, 18 Apr 2016 19:11:03 +0200

nss changes required to avoid build error with gcc6 like:
===
[   58s] h_page.c: In function 'new_lseek':
[   58s] h_page.c:117:8: error: this 'if' clause does not guard... 
[-Werror=misleading-indentation]
[   58s] if(offset < 1)
[   58s] ^~
[   58s] h_page.c:120:3: note: ...this statement, but the latter is 
misleadingly indented as if it is guarded by the 'if'
[   58s]cur_pos = lseek(fd, 0, SEEK_CUR);
[   58s]^~~
===

Signed-off-by: Michel Normand 
---
 cmd/bltest/blapitest.c  |4 +--
 cmd/vfychain/vfychain.c |3 +-
 lib/dbm/src/h_page.c|   55 +---
 lib/dbm/src/hash.c  |   60 
 4 files changed, 61 insertions(+), 61 deletions(-)

Index: nss/lib/dbm/src/h_page.c
===
--- nss.orig/lib/dbm/src/h_page.c
+++ nss/lib/dbm/src/h_page.c
@@ -112,26 +112,25 @@ long new_lseek(int fd, long offset, int
long end_pos=0;
long seek_pos=0;
 
-   if(origin == SEEK_CUR)
-  {
-   if(offset < 1)
-   return(lseek(fd, offset, SEEK_CUR));
+   if (origin == SEEK_CUR) {
+   if  (offset < 1)
+   return(lseek(fd, offset, SEEK_CUR));
 
-   cur_pos = lseek(fd, 0, SEEK_CUR);
+   cur_pos = lseek(fd, 0, SEEK_CUR);
+
+   if (cur_pos < 0)
+   return(cur_pos);
+   }
 
-   if(cur_pos < 0)
-   return(cur_pos);
- }
-   
 
end_pos = lseek(fd, 0, SEEK_END);
-   if(end_pos < 0)
+   if (end_pos < 0)
return(end_pos);
 
-   if(origin == SEEK_SET)
+   if (origin == SEEK_SET)
seek_pos = offset;
-   else if(origin == SEEK_CUR)
+   else if (origin == SEEK_CUR)
seek_pos = cur_pos + offset;
-   else if(origin == SEEK_END)
+   else if (origin == SEEK_END)
seek_pos = end_pos + offset;
else
  {
@@ -143,7 +142,7 @@ long new_lseek(int fd, long offset, int
 * end of the file.  We don't need
 * to do anything special except the seek.
 */
-   if(seek_pos <= end_pos)
+   if (seek_pos <= end_pos)
return(lseek(fd, seek_pos, SEEK_SET));

  /* the seek position is beyond the end of the
@@ -161,7 +160,7 @@ long new_lseek(int fd, long offset, int
memset(buffer, 0, 1024);
while(len > 0)
  {
-   if(write(fd, buffer, (size_t)(1024 > len ? len : 1024)) < 0)
+   if (write(fd, buffer, (size_t)(1024 > len ? len : 1024)) < 0)
return(-1);
len -= 1024;
  }
@@ -245,10 +244,10 @@ __delpair(HTAB *hashp, BUFHEAD *bufp, in
 * Once we know dst_offset is < BSIZE, we can subtract it from 
BSIZE
 * to get an upper bound on length.
 

commit mozilla-nss for openSUSE:Factory

2016-04-11 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2016-04-11 09:12:15

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2016-03-16 
10:24:29.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2016-04-11 09:12:17.0 +0200
@@ -1,0 +2,51 @@
+Tue Mar 15 10:25:38 UTC 2016 - w...@rosenauer.org
+
+- update to NSS 3.22.3
+  * required for Firefox 46.0
+  * Increase compatibility of TLS extended master secret,
+don't send an empty TLS extension last in the handshake
+(bmo#1243641)
+
+---
+Wed Mar  9 15:42:01 UTC 2016 - w...@rosenauer.org
+
+- update to NSS 3.22.2
+  New functionality:
+  * RSA-PSS signatures are now supported (bmo#1215295)
+  * Pseudorandom functions based on hashes other than SHA-1 are now supported
+  * Enforce an External Policy on NSS from a config file (bmo#1009429)
+  New functions:
+  * PK11_SignWithMechanism - an extended version PK11_Sign()
+  * PK11_VerifyWithMechanism - an extended version of PK11_Verify()
+  * SSL_PeerSignedCertTimestamps - Get signed_certificate_timestamp
+TLS extension data
+  * SSL_SetSignedCertTimestamps - Set signed_certificate_timestamp
+TLS extension data
+  New types:
+  * ssl_signed_cert_timestamp_xtn is added to SSLExtensionType
+  * Constants for several object IDs are added to SECOidTag
+  New macros:
+  * SSL_ENABLE_SIGNED_CERT_TIMESTAMPS
+  * NSS_USE_ALG_IN_SSL
+  * NSS_USE_POLICY_IN_SSL
+  * NSS_RSA_MIN_KEY_SIZE
+  * NSS_DH_MIN_KEY_SIZE
+  * NSS_DSA_MIN_KEY_SIZE
+  * NSS_TLS_VERSION_MIN_POLICY
+  * NSS_TLS_VERSION_MAX_POLICY
+  * NSS_DTLS_VERSION_MIN_POLICY
+  * NSS_DTLS_VERSION_MAX_POLICY
+  * CKP_PKCS5_PBKD2_HMAC_SHA224
+  * CKP_PKCS5_PBKD2_HMAC_SHA256
+  * CKP_PKCS5_PBKD2_HMAC_SHA384
+  * CKP_PKCS5_PBKD2_HMAC_SHA512
+  * CKP_PKCS5_PBKD2_HMAC_GOSTR3411 - (not supported)
+  * CKP_PKCS5_PBKD2_HMAC_SHA512_224 - (not supported)
+  * CKP_PKCS5_PBKD2_HMAC_SHA512_256 - (not supported)
+  Notable changes:
+  * NSS C++ tests are built by default, requiring a C++11 compiler.
+Set the NSS_DISABLE_GTESTS variable to 1 to disable building these tests.
+  * NSS has been changed to use the PR_GetEnvSecure function that
+was made available in NSPR 4.12
+
+---
@@ -8 +58,0 @@
-(fixed by requiring 3.21.1)
@@ -11 +60,0 @@
-(fixed by requiring 3.21.1)

Old:

  nss-3.21.1.tar.gz

New:

  nss-3.22.3.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.iFsiI6/_old  2016-04-11 09:12:19.0 +0200
+++ /var/tmp/diff_new_pack.iFsiI6/_new  2016-04-11 09:12:19.0 +0200
@@ -2,7 +2,7 @@
 # spec file for package mozilla-nss
 #
 # Copyright (c) 2016 SUSE LINUX GmbH, Nuernberg, Germany.
-# Copyright (c) 2006-2016 Wolfgang Rosenauer
+# Copyright (c) 2006-2015 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.10.10
+BuildRequires:  mozilla-nspr-devel >= 4.12
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.21.1
+Version:3.22.3
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_21_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.21.1/nss ; cd 
nss-3.21.1/nss ; hg up NSS_3_21_1_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_22_3_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.22.3/nss ; cd 
nss-3.22.3/nss ; hg up NSS_3_22_3_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.21.1.tar.gz -> nss-3.22.3.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.21.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.22.3.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2016-03-16 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2016-03-16 10:24:28

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2016-02-03 
10:16:17.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2016-03-16 10:24:29.0 +0100
@@ -1,0 +2,12 @@
+Mon Mar  7 15:41:50 UTC 2016 - w...@rosenauer.org
+
+- update to NSS 3.21.1 (bmo#969894)
+  * required for Firefox 45.0
+  * MFSA 2016-35/CVE-2016-1950 (bmo#1245528)
+Buffer overflow during ASN.1 decoding in NSS
+(fixed by requiring 3.21.1)
+  * MFSA 2016-36/CVE-2016-1979 (bmo#1185033)
+Use-after-free during processing of DER encoded keys in NSS
+(fixed by requiring 3.21.1)
+
+---

Old:

  nss-3.21.tar.gz

New:

  nss-3.21.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.efmw8Q/_old  2016-03-16 10:24:31.0 +0100
+++ /var/tmp/diff_new_pack.efmw8Q/_new  2016-03-16 10:24:31.0 +0100
@@ -2,7 +2,7 @@
 # spec file for package mozilla-nss
 #
 # Copyright (c) 2016 SUSE LINUX GmbH, Nuernberg, Germany.
-# Copyright (c) 2006-2015 Wolfgang Rosenauer
+# Copyright (c) 2006-2016 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.21
+Version:3.21.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_21_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.21/nss ; cd nss-3.21/nss 
; hg up NSS_3_21_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_21_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.21.1/nss ; cd 
nss-3.21.1/nss ; hg up NSS_3_21_1_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.21.tar.gz -> nss-3.21.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.21.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.21.1.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2016-02-03 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2016-02-03 10:16:06

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2016-01-05 
21:53:39.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2016-02-03 10:16:17.0 +0100
@@ -1,0 +2,106 @@
+Sun Dec 20 10:12:35 UTC 2015 - w...@rosenauer.org
+
+- update to NSS 3.21
+  * required for Firefox 44.0
+  New functionality:
+  * certutil now supports a --rename option to change a nickname (bmo#1142209)
+  * TLS extended master secret extension (RFC 7627) is supported (bmo#1117022)
+  * New info functions added for use during mid-handshake callbacks 
(bmo#1084669)
+  New Functions:
+  * NSS_OptionSet - sets NSS global options
+  * NSS_OptionGet - gets the current value of NSS global options
+  * SECMOD_CreateModuleEx - Create a new SECMODModule structure from module 
name
+string, module parameters string, NSS specific parameters string, and NSS
+configuration parameter string. The module represented by the module
+structure is not loaded. The difference with SECMOD_CreateModule is the new
+function handles NSS configuration parameter strings.
+  * SSL_GetPreliminaryChannelInfo - obtains information about a TLS channel 
prior
+to the handshake being completed, for use with the callbacks that are 
invoked
+during the handshake
+  * SSL_SignaturePrefSet - configures the enabled signature and hash algorithms
+for TLS
+  * SSL_SignaturePrefGet - retrieves the currently configured signature and 
hash
+algorithms
+  * SSL_SignatureMaxCount - obtains the maximum number signature algorithms 
that
+can be configured with SSL_SignaturePrefSet
+  * NSSUTIL_ArgParseModuleSpecEx - takes a module spec and breaks it into 
shared
+library string, module name string, module parameters string, NSS specific
+parameters string, and NSS configuration parameter strings. The returned
+strings must be freed by the caller. The difference with
+NSS_ArgParseModuleSpec is the new function handles NSS configuration
+parameter strings.
+  * NSSUTIL_MkModuleSpecEx - take a shared library string, module name string,
+module parameters string, NSS specific parameters string, and NSS
+configuration parameter string and returns a module string which the caller
+must free when it is done. The difference with NSS_MkModuleSpec is the new
+function handles NSS configuration parameter strings.
+  New Types:
+  * CK_TLS12_MASTER_KEY_DERIVE_PARAMS{_PTR} - parameters {or pointer} for
+CKM_TLS12_MASTER_KEY_DERIVE
+  * CK_TLS12_KEY_MAT_PARAMS{_PTR} - parameters {or pointer} for
+CKM_TLS12_KEY_AND_MAC_DERIVE
+  * CK_TLS_KDF_PARAMS{_PTR} - parameters {or pointer} for CKM_TLS_KDF
+  * CK_TLS_MAC_PARAMS{_PTR} - parameters {or pointer} for CKM_TLS_MAC
+  * SSLHashType - identifies a hash function
+  * SSLSignatureAndHashAlg - identifies a signature and hash function
+  * SSLPreliminaryChannelInfo - provides information about the session state
+prior to handshake completion
+  New Macros:
+  * NSS_RSA_MIN_KEY_SIZE - used with NSS_OptionSet and NSS_OptionGet to set or
+get the minimum RSA key size
+  * NSS_DH_MIN_KEY_SIZE - used with NSS_OptionSet and NSS_OptionGet to set or
+get the minimum DH key size
+  * NSS_DSA_MIN_KEY_SIZE - used with NSS_OptionSet and NSS_OptionGet to set or
+get the minimum DSA key size
+  * CKM_TLS12_MASTER_KEY_DERIVE - derives TLS 1.2 master secret
+  * CKM_TLS12_KEY_AND_MAC_DERIVE - derives TLS 1.2 traffic key and IV
+  * CKM_TLS12_MASTER_KEY_DERIVE_DH - derives TLS 1.2 master secret for DH (and
+ECDH) cipher suites
+  * CKM_TLS12_KEY_SAFE_DERIVE and CKM_TLS_KDF are identifiers for additional
+PKCS#12 mechanisms for TLS 1.2 that are currently unused in NSS.
+  * CKM_TLS_MAC - computes TLS Finished MAC
+  * NSS_USE_ALG_IN_SSL_KX - policy flag indicating that keys are used in TLS 
key
+exchange
+  * SSL_ERROR_RX_SHORT_DTLS_READ - error code for failure to include a complete
+DTLS record in a UDP packet
+  * SSL_ERROR_NO_SUPPORTED_SIGNATURE_ALGORITHM - error code for when no valid
+signature and hash algorithm is available
+  * SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM - error code for when an
+unsupported signature and hash algorithm is configured
+  * SSL_ERROR_MISSING_EXTENDED_MASTER_SECRET - error code for when the extended
+master secret is missing after having been negotiated
+  * SSL_ERROR_UNEXPECTED_EXTENDED_MASTER_SECRET - error code for receiving an
+extended master secret when previously not negotiated
+  * SSL_ENABLE_EXTENDED_MASTER_SECRET 

commit mozilla-nss for openSUSE:Factory

2016-01-05 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2016-01-05 21:53:14

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2015-12-27 
01:59:13.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2016-01-05 21:53:39.0 +0100
@@ -4,0 +5,3 @@
+  * MFSA 2015-150/CVE-2015-7575 (bmo#1158489)
+MD5 signatures accepted within TLS 1.2 ServerKeyExchange in
+server signature



Other differences:
--





commit mozilla-nss for openSUSE:Factory

2015-12-26 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2015-12-27 01:59:12

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2015-11-08 
11:25:00.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2015-12-27 01:59:13.0 +0100
@@ -1,0 +2,5 @@
+Sat Dec 19 17:13:21 UTC 2015 - w...@rosenauer.org
+
+- update to NSS 3.20.2 (bnc#959888)
+
+---
@@ -4 +9 @@
-- update to NSS 4.20.1 (bnc#952810)
+- update to NSS 3.20.1 (bnc#952810)

Old:

  nss-3.20.1.tar.gz

New:

  nss-3.20.2.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.grd8ml/_old  2015-12-27 01:59:16.0 +0100
+++ /var/tmp/diff_new_pack.grd8ml/_new  2015-12-27 01:59:16.0 +0100
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.20.1
+Version:3.20.2
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_20_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.20.1/nss ; cd 
nss-3.20.1/nss ; hg up NSS_3_20_1_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_20_2_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.20.2/nss ; cd 
nss-3.20.2/nss ; hg up NSS_3_20_2_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.20.1.tar.gz -> nss-3.20.2.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.20.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.20.2.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2015-11-08 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2015-11-08 11:24:50

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2015-10-03 
20:29:20.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2015-11-08 11:25:00.0 +0100
@@ -1,0 +2,8 @@
+Sun Oct 25 14:44:21 UTC 2015 - w...@rosenauer.org
+
+- update to NSS 4.20.1 (bnc#952810)
+  * requires NSPR 4.10.10
+  * MFSA 2015-133/CVE-2015-7181/CVE-2015-7182 (bmo#1192028, bmo#1202868)
+memory corruption issues
+
+---

Old:

  nss-3.20.tar.gz

New:

  nss-3.20.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.nDFq8L/_old  2015-11-08 11:25:02.0 +0100
+++ /var/tmp/diff_new_pack.nDFq8L/_new  2015-11-08 11:25:02.0 +0100
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel >= 4.10.8
+BuildRequires:  mozilla-nspr-devel >= 4.10.10
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.20
+Version:3.20.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_20_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.20/nss ; cd nss-3.20/nss 
; hg up NSS_3_20_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_20_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.20.1/nss ; cd 
nss-3.20.1/nss ; hg up NSS_3_20_1_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.20.tar.gz -> nss-3.20.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.20.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.20.1.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2015-10-03 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2015-10-03 20:28:20

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is "mozilla-nss"

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2015-07-19 
11:44:25.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2015-10-03 20:29:20.0 +0200
@@ -1,0 +2,87 @@
+Thu Sep 24 15:41:09 UTC 2015 - fst...@suse.com
+
+- Install the static libfreebl.a that is needed in order to link
+  Sun elliptical curves provider in Java 7.
+
+---
+Thu Sep 24 09:39:17 UTC 2015 - w...@rosenauer.org
+
+- update to NSS 3.20
+  New functionality:
+  * The TLS library has been extended to support DHE ciphersuites in
+server applications.
+  New Functions:
+  * SSL_DHEGroupPrefSet - Configure the set of allowed/enabled DHE group
+parameters that can be used by NSS for a server socket.
+  * SSL_EnableWeakDHEPrimeGroup - Enable the use of weak DHE group
+parameters that are smaller than the library default's minimum size.
+  New Types:
+  * SSLDHEGroupType - Enumerates the set of DHE parameters embedded in
+NSS that can be used with function SSL_DHEGroupPrefSet.
+  New Macros:
+  * SSL_ENABLE_SERVER_DHE - A socket option user to enable or disable
+DHE ciphersuites for a server socket.
+  Notable Changes:
+  * For backwards compatibility reasons, the server side implementation
+of the TLS library keeps all DHE ciphersuites disabled by default.
+They can be enabled with the new socket option SSL_ENABLE_SERVER_DHE
+and the SSL_OptionSet or the SSL_OptionSetDefault API.
+  * The server side implementation of the TLS implementation does not
+support session tickets when using a DHE ciphersuite (see bmo#1174677).
+  * Support for the following ciphersuites has been added:
+- TLS_DHE_DSS_WITH_AES_128_GCM_SHA256
+- TLS_DHE_DSS_WITH_AES_128_CBC_SHA256
+- TLS_DHE_DSS_WITH_AES_256_CBC_SHA256
+  * By default, the server side TLS implementation will use DHE
+parameters with a size of 2048 bits when using DHE ciphersuites.
+  * NSS embeds fixed DHE parameters sized 2048, 3072, 4096, 6144 and
+8192 bits, which were copied from version 08 of the Internet-Draft
+"Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for
+TLS", Appendix A.
+  * A new API SSL_DHEGroupPrefSet has been added to NSS, which allows a
+server application to select one or multiple of the embedded DHE
+parameters as the preferred parameters. The current implementation of
+NSS will always use the first entry in the array that is passed as a
+parameter to the SSL_DHEGroupPrefSet API. In future versions of the
+TLS implementation, a TLS client might signal a preference for
+certain DHE parameters, and the NSS TLS server side implementation
+might select a matching entry from the set of parameters that have
+been configured as preferred on the server side.
+  * NSS optionally supports the use of weak DHE parameters with DHE
+ciphersuites to support legacy clients. In order to enable this
+support, the new API SSL_EnableWeakDHEPrimeGroup must be used. Each
+time this API is called for the first time in a process, a fresh set
+of weak DHE parameters will be randomly created, which may take a
+long amount of time. Please refer to the comments in the header file
+that declares the SSL_EnableWeakDHEPrimeGroup API for additional
+details.
+  * The size of the default PQG parameters used by certutil when
+creating DSA keys has been increased to use 2048 bit parameters.
+  * The selfserv utility has been enhanced to support the new DHE features.
+  * NSS no longer supports C compilers that predate the ANSI C standard (C89).
+
+---
+Thu Sep 24 09:38:17 UTC 2015 - w...@rosenauer.org
+
+- update to NSS 3.19.3; certstore updates only
+  * The following CA certificates were removed
+- Buypass Class 3 CA 1
+- TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı
+- SG TRUST SERVICES RACINE
+- TC TrustCenter Universal CA I
+- TC TrustCenter Class 2 CA II
+  * The following CA certificate had the Websites trust bit turned off
+- ComSign Secured CA
+  * The following CA certificates were added
+- TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı H5
+- TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı H6
+- Certinomis - Root CA
+  * The version number of the updated root CA list has been set to 2.5
+
+---
+Thu Sep 24 09:31:11 UTC 2015 - fst...@suse.com
+

commit mozilla-nss for openSUSE:Factory

2015-07-19 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2015-07-19 11:44:24

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2015-06-30 
10:15:20.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2015-07-19 11:44:25.0 +0200
@@ -35,0 +36 @@
+(MFSA 2015-70/CVE-2015-4000)
@@ -40,0 +42,2 @@
+  * NSS incorrectly permits skipping of ServerKeyExchange
+(bmo#1086145) (MFSA 2015-71/CVE-2015-2721)



Other differences:
--





commit mozilla-nss for openSUSE:Factory

2015-06-30 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2015-06-30 10:15:18

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2015-06-03 
08:21:08.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2015-06-30 10:15:20.0 +0200
@@ -1,0 +2,25 @@
+Wed Jun 24 12:45:09 UTC 2015 - meiss...@suse.com
+
+- as the .chk files are contained in libfreebl3 and libsoftokn
+  directly, provide the -hmac alias names to help :42 building.
+
+---
+Tue Jun 23 06:00:13 UTC 2015 - w...@rosenauer.org
+
+- update to 3.19.2
+  * required for Firefox 39.0
+  * No new functionality is introduced in this release. This release
+addresses a backwards compatibility issue with the NSS 3.19.1
+release.
+  * In NSS 3.19.1, the minimum key sizes that the freebl cryptographic
+implementation (part of the softoken cryptographic module used
+by default by NSS) was willing to generate or use was increased
+- for RSA keys, to 512 bits, and for DH keys, 1023 bits. This
+was done as part of a security fix for Bug 1138554 / CVE-2015-4000.
+Applications that requested or attempted to use keys smaller
+then the minimum size would fail. However,  this change in behaviour
+unintentionally broke existing NSS applications that need to
+generate or use such keys, via APIs such as
+SECKEY_CreateRSAPrivateKey or SECKEY_CreateDHPrivateKey.
+
+---

Old:

  nss-3.19.1.tar.gz

New:

  nss-3.19.2.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.UNPSco/_old  2015-06-30 10:15:21.0 +0200
+++ /var/tmp/diff_new_pack.UNPSco/_new  2015-06-30 10:15:21.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.19.1
+Version:3.19.2
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_19_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.19.1/nss ; cd 
nss-3.19.1/nss ; hg up NSS_3_19_1_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_19_2_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.19.2/nss ; cd 
nss-3.19.2/nss ; hg up NSS_3_19_2_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -126,6 +126,7 @@
 %package -n libfreebl3
 Summary:Freebl library for the Network Security Services
 Group:  System/Libraries
+Provides:   libfreebl3-hmac
 
 %description -n libfreebl3
 Network Security Services (NSS) is a set of libraries designed to
@@ -141,6 +142,7 @@
 Summary:Network Security Services Softoken Module
 Group:  System/Libraries
 Requires:   libfreebl3 = %{version}-%{release}
+Provides:   libsoftokn3-hmac
 
 %description -n libsoftokn3
 Network Security Services (NSS) is a set of libraries designed to



++ nss-3.19.1.tar.gz - nss-3.19.2.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.19.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.19.2.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2015-06-03 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2015-06-03 08:21:07

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2015-06-01 
09:48:40.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2015-06-03 08:21:08.0 +0200
@@ -1,0 +2,16 @@
+Sun May 31 13:22:47 UTC 2015 - w...@rosenauer.org
+
+- update to 3.19.1
+  No new functionality is introduced in this release. This patch
+  release includes a fix for the recently published logjam attack.
+  Notable Changes:
+  * The minimum strength of keys that libssl will accept for
+finite field algorithms (RSA, Diffie-Hellman, and DSA) have
+been increased to 1023 bits (bmo#1138554).
+  * NSS reports the bit length of keys more accurately.  Thus,
+the SECKEY_PublicKeyStrength and SECKEY_PublicKeyStrengthInBits
+functions could report smaller values for values that have
+leading zero values. This affects the key strength values that
+are reported by SSL_GetChannelInfo.
+
+---

Old:

  nss-3.19.tar.gz

New:

  nss-3.19.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.jaf2s4/_old  2015-06-03 08:21:10.0 +0200
+++ /var/tmp/diff_new_pack.jaf2s4/_new  2015-06-03 08:21:10.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.19
+Version:3.19.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_19_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.19/nss ; cd nss-3.19/nss 
; hg up NSS_3_19_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_19_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.19.1/nss ; cd 
nss-3.19.1/nss ; hg up NSS_3_19_1_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.19.tar.gz - nss-3.19.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.19.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.19.1.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2015-06-01 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2015-06-01 09:48:39

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2015-04-25 
16:47:28.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2015-06-01 09:48:40.0 +0200
@@ -1,0 +2,23 @@
+Sat May 23 07:36:27 UTC 2015 - w...@rosenauer.org
+
+- update to 3.19
+  * Firefox target release 39
+  New functionality:
+  * For some certificates, such as root CA certificates, that don't
+embed any constraints, NSS might impose additional constraints,
+such as name constraints. A new API has been added that allows
+to lookup imposed constraints.
+  * It is possible to override the directory in which the NSS build
+system will look for the sqlite library.
+  New Functions:
+  * CERT_GetImposedNameConstraints
+  Notable Changes:
+  * The SSL 3 protocol has been disabled by default.
+  * NSS now more strictly validates TLS extensions and will fail a
+handshake that contains malformed extensions.
+  * Fixed a bug related to the ordering of TLS handshake messages.
+  * In TLS 1.2 handshakes, NSS advertises support for the SHA512
+hash algorithm, in order to be compatible with TLS servers
+that use certificates with a SHA512 signature.
+
+---

Old:

  nss-3.18.1.tar.gz

New:

  nss-3.19.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.ntVBBL/_old  2015-06-01 09:48:42.0 +0200
+++ /var/tmp/diff_new_pack.ntVBBL/_new  2015-06-01 09:48:42.0 +0200
@@ -17,7 +17,7 @@
 #
 
 
-%global nss_softokn_fips_version 3.12.4
+%global nss_softokn_fips_version 3.18
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.18.1
+Version:3.19
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_18_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.18.1/nss ; cd 
nss-3.18.1/nss ; hg up NSS_3_18_1_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_19_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.19/nss ; cd nss-3.19/nss 
; hg up NSS_3_19_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.18.1.tar.gz - nss-3.19.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.18.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.19.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2015-04-25 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2015-04-25 16:47:27

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2015-04-07 
09:28:50.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2015-04-25 16:47:28.0 +0200
@@ -1,0 +2,20 @@
+Thu Apr 23 06:35:27 UTC 2015 - w...@rosenauer.org
+
+- update to 3.18.1
+  * Firefox target release 38
+  * No new functionality is introduced in this release.
+  Notable Changes:
+  * The following CA certificate had the Websites and Code Signing
+trust bits restored to their original state to allow more time
+to develop a better transition strategy for affected sites:
+- OU = Equifax Secure Certificate Authority
+  * The following CA certificate was removed:
+- CN = e-Guven Kok Elektronik Sertifika Hizmet Saglayicisi
+  * The following intermediate CA certificate has been added as
+actively distrusted because it was mis-used to issue certificates
+for domain names the holder did not own or control:
+- CN=MCSHOLDING TEST, O=MCSHOLDING, C=EG
+  * The version number of the updated root CA list has been set
+to 2.4
+
+---

Old:

  nss-3.18.tar.gz

New:

  nss-3.18.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.GGDFSh/_old  2015-04-25 16:47:29.0 +0200
+++ /var/tmp/diff_new_pack.GGDFSh/_new  2015-04-25 16:47:29.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.18
+Version:3.18.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_18_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.18/nss ; cd nss-3.18/nss 
; hg up NSS_3_18_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_18_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.18.1/nss ; cd 
nss-3.18.1/nss ; hg up NSS_3_18_1_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.18.tar.gz - nss-3.18.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.18.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.18.1.tar.gz differ: char 5, 
line 1




commit mozilla-nss for openSUSE:Factory

2015-04-07 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2015-04-07 09:28:49

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2015-02-11 
16:31:35.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2015-04-07 09:28:50.0 +0200
@@ -1,0 +2,52 @@
+Fri Apr  3 08:34:59 UTC 2015 - w...@rosenauer.org
+
+- update to 3.18
+  * Firefox target release 38
+  New functionality:
+  * When importing certificates and keys from a PKCS#12 source,
+it's now possible to override the nicknames, prior to importing
+them into the NSS database, using new API
+SEC_PKCS12DecoderRenameCertNicknames.
+  * The tstclnt test utility program has new command-line options
+-C, -D, -b and -R.
+Use -C one, two or three times to print information about the
+certificates received from a server, and information about the
+locally found and trusted issuer certificates, to diagnose
+server side configuration issues. It is possible to run tstclnt
+without providing a database (-D). A PKCS#11 library that
+contains root CA certificates can be loaded by tstclnt, which
+may either be the nssckbi library provided by NSS (-b) or
+another compatible library (-R).
+  New Functions:
+  * SEC_CheckCrlTimes
+  * SEC_GetCrlTimes
+  * SEC_PKCS12DecoderRenameCertNicknames
+  New Types:
+  * SEC_PKCS12NicknameRenameCallback
+  Notable Changes:
+  * The highest TLS protocol version enabled by default has been
+increased from TLS 1.0 to TLS 1.2. Similarly, the highest DTLS
+protocol version enabled by default has been increased from
+DTLS 1.0 to DTLS 1.2.
+  * The default key size used by certutil when creating an RSA key
+pair has been increased from 1024 bits to 2048 bits.
+  * The following CA certificates had the Websites and Code Signing
+trust bits turned off:
+- Equifax Secure Certificate Authority
+- Equifax Secure Global eBusiness CA-1
+- TC TrustCenter Class 3 CA II
+  * The following CA certificates were added:
+- Staat der Nederlanden Root CA - G3
+- Staat der Nederlanden EV Root CA
+- IdenTrust Commercial Root CA 1
+- IdenTrust Public Sector Root CA 1
+- S-TRUST Universal Root CA
+- Entrust Root Certification Authority - G2
+- Entrust Root Certification Authority - EC1
+- CFCA EV ROOT
+  * The version number of the updated root CA list has been set
+to 2.3
+- add the changes file as source so the .src.rpm builds (used for
+  fake build time)
+
+---

Old:

  nss-3.17.4.tar.gz

New:

  nss-3.18.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.yaiMg8/_old  2015-04-07 09:28:51.0 +0200
+++ /var/tmp/diff_new_pack.yaiMg8/_new  2015-04-07 09:28:51.0 +0200
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel = 4.10.7
+BuildRequires:  mozilla-nspr-devel = 4.10.8
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.17.4
+Version:3.18
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_4_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.17.4/nss ; cd 
nss-3.17.4/nss ; hg up NSS_3_17_4_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_18_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.18/nss ; cd nss-3.18/nss 
; hg up NSS_3_18_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -48,6 +48,7 @@
 Source8:key4.db
 Source9:pkcs11.txt
 #Source10:   PayPalEE.cert
+Source99:   %{name}.changes
 Patch1: nss-opt.patch
 Patch2: system-nspr.patch
 Patch4: nss-no-rpath.patch
@@ -179,7 +180,7 @@
 
 %build
 cd nss
-modified=$(sed -n '/^/n;s/ - .*$//;p;q' %{_sourcedir}/%{name}.changes)
+modified=$(sed -n '/^/n;s/ - .*$//;p;q' %{S:99})
 DATE=\$(date -d ${modified} +%%b %%e %%Y)\
 TIME=\$(date -d ${modified} +%%R)\
 find . -name '*.[ch]' -print -exec sed -i 
s/__DATE__/${DATE}/g;s/__TIME__/${TIME}/g {} +



++ nss-3.17.4.tar.gz - nss-3.18.tar.gz ++

commit mozilla-nss for openSUSE:Factory

2015-02-11 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2015-02-11 16:31:34

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2015-01-05 
04:43:00.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2015-02-11 16:31:35.0 +0100
@@ -1,0 +2,20 @@
+Sat Jan 31 17:53:49 UTC 2015 - w...@rosenauer.org
+
+- update to 3.17.4
+  * Firefox target release 36
+  Notable Changes:
+  * bmo#1084986: If an SSL/TLS connection fails, because client and
+ server don't have any common protocol version enabled,
+NSS has been changed to report error code
+SSL_ERROR_UNSUPPORTED_VERSION (instead of reporting
+SSL_ERROR_NO_CYPHER_OVERLAP).
+  * bmo#1112461: libpkix was fixed to prefer the newest certificate,
+ if multiple certificates match.
+  * bmo#1094492: fixed a memory corruption issue during failure of
+ keypair generation.
+  * bmo#1113632: fixed a failure to reload a PKCS#11 module in FIPS
+ mode.
+  * bmo#1119983: fixed interoperability of NSS server code with a
+ LibreSSL client.
+
+---
@@ -5 +24,0 @@
-  * Firefox target release 36

Old:

  nss-3.17.3.tar.gz

New:

  nss-3.17.4.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.JgwqD2/_old  2015-02-11 16:31:37.0 +0100
+++ /var/tmp/diff_new_pack.JgwqD2/_new  2015-02-11 16:31:37.0 +0100
@@ -1,7 +1,7 @@
 #
 # spec file for package mozilla-nss
 #
-# Copyright (c) 2014 SUSE LINUX Products GmbH, Nuernberg, Germany.
+# Copyright (c) 2015 SUSE LINUX GmbH, Nuernberg, Germany.
 # Copyright (c) 2006-2014 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.17.3
+Version:3.17.4
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_3_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.17.3/nss ; cd 
nss-3.17.3/nss ; hg up NSS_3_17_3_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_4_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.17.4/nss ; cd 
nss-3.17.4/nss ; hg up NSS_3_17_4_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.17.3.tar.gz - nss-3.17.4.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.17.3.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.17.4.tar.gz differ: char 5, 
line 1

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2015-01-04 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2015-01-05 04:42:57

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2014-10-29 
21:09:13.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2015-01-05 04:43:00.0 +0100
@@ -1,0 +2,30 @@
+Sat Dec  6 18:27:12 UTC 2014 - w...@rosenauer.org
+
+- update to 3.17.3
+  * Firefox target release 36
+  New functionality:
+  * Support for TLS_FALLBACK_SCSV has been added to the ssltap and
+tstclnt utilities
+  Notable Changes:
+  * The QuickDER decoder now decodes lengths robustly
+(CVE-2014-1569)
+  * The following 1024-bit CA certificates were removed:
+- GTE CyberTrust Global Root
+- Thawte Server CA
+- Thawte Premium Server CA
+- America Online Root Certification Authority 1
+- America Online Root Certification Authority 2
+  * The following CA certificates had the Websites and Code Signing
+trust bits turned off:
+- Class 3 Public Primary Certification Authority - G2
+- Equifax Secure eBusiness CA-1
+  * The following CA certificates were added:
+- COMODO RSA Certification Authority
+- USERTrust RSA Certification Authority
+- USERTrust ECC Certification Authority
+- GlobalSign ECC Root CA - R4
+- GlobalSign ECC Root CA - R5
+  * the version number of the updated root CA list has been set
+to 2.2
+
+---

Old:

  nss-3.17.2.tar.gz

New:

  nss-3.17.3.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.y6f1VS/_old  2015-01-05 04:43:02.0 +0100
+++ /var/tmp/diff_new_pack.y6f1VS/_new  2015-01-05 04:43:02.0 +0100
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.17.2
+Version:3.17.3
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_2_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.17.2/nss ; cd 
nss-3.17.2/nss ; hg up NSS_3_17_2_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_3_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.17.3/nss ; cd 
nss-3.17.3/nss ; hg up NSS_3_17_3_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.17.2.tar.gz - nss-3.17.3.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.17.2.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.17.3.tar.gz differ: char 5, 
line 1

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2014-10-29 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2014-10-29 21:09:05

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2014-10-01 
11:22:08.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2014-10-29 21:09:13.0 +0100
@@ -1,0 +2,9 @@
+Thu Oct 16 19:15:27 UTC 2014 - w...@rosenauer.org
+
+- update to 3.17.2
+  Bugfix release
+  * bmo#1049435 - Importing an RSA private key fails if p  q
+  * bmo#1057161 - NSS hangs with 100% CPU on invalid EC key
+  * bmo#1078669 - certutil crashes when using the --certVersion parameter
+
+---

Old:

  nss-3.17.1.tar.gz

New:

  nss-3.17.2.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.f6DIgA/_old  2014-10-29 21:09:14.0 +0100
+++ /var/tmp/diff_new_pack.f6DIgA/_new  2014-10-29 21:09:14.0 +0100
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.17.1
+Version:3.17.2
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,9 +36,9 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-#Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_1_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.17.1/nss ; cd 
nss-3.17.1/nss ; hg up NSS_3_17_1_RTM
-Source: nss-%{version}.tar.gz
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_2_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.17.2/nss ; cd 
nss-3.17.2/nss ; hg up NSS_3_17_2_RTM
+#Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
 Source4:%{name}-rpmlintrc



++ nss-3.17.1.tar.gz - nss-3.17.2.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.17.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.17.2.tar.gz differ: char 4, 
line 1

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2014-10-01 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2014-10-01 11:22:06

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2014-09-08 
21:28:14.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2014-10-01 11:22:08.0 +0200
@@ -1,0 +2,14 @@
+Tue Sep 23 21:30:16 UTC 2014 - w...@rosenauer.org
+
+- update to 3.17.1 (bnc#897890)
+  * MFSA 2014-73/CVE-2014-1568 (bmo#1064636, bmo#1069405)
+RSA Signature Forgery in NSS
+  * Change library's signature algorithm default to SHA256
+  * Add support for draft-ietf-tls-downgrade-scsv
+  * Add clang-cl support to the NSS build system
+  * Implement TLS 1.3:
+* Part 1. Negotiate TLS 1.3
+* Part 2. Remove deprecated cipher suites andcompression.
+  * Add support for little-endian powerpc64
+
+---

Old:

  nss-3.17.tar.gz

New:

  nss-3.17.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.8b1hNR/_old  2014-10-01 11:22:10.0 +0200
+++ /var/tmp/diff_new_pack.8b1hNR/_new  2014-10-01 11:22:10.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.17
+Version:3.17.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,9 +36,9 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.17/nss ; cd nss-3.17/nss 
; hg up NSS_3_17_RTM
-#Source: nss-%{version}.tar.gz
+#Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_1_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.17.1/nss ; cd 
nss-3.17.1/nss ; hg up NSS_3_17_1_RTM
+Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
 Source4:%{name}-rpmlintrc



++ nss-3.17.tar.gz - nss-3.17.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.17.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.17.1.tar.gz differ: char 4, 
line 1

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2014-09-08 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2014-09-08 21:28:11

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2014-08-15 
09:58:21.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2014-09-08 21:28:14.0 +0200
@@ -1,0 +2,22 @@
+Fri Aug 29 11:53:10 UTC 2014 - w...@rosenauer.org
+
+- update to 3.17
+  * required for Firefox 33
+  New functionality:
+  * When using ECDHE, the TLS server code may be configured to generate
+a fresh ephemeral ECDH key for each handshake, by setting the
+SSL_REUSE_SERVER_ECDHE_KEY socket option to PR_FALSE. The
+SSL_REUSE_SERVER_ECDHE_KEY option defaults to PR_TRUE, which means
+the server's ephemeral ECDH key is reused for multiple handshakes.
+This option does not affect the TLS client code, which always
+generates a fresh ephemeral ECDH key for each handshake.
+  New Macros
+  * SSL_REUSE_SERVER_ECDHE_KEY
+  Notable Changes:
+  * The manual pages for the certutil and pp tools have been updated to
+document the new parameters that had been added in NSS 3.16.2.
+  * On Windows, the new build variable USE_STATIC_RTL can be used to
+specify the static C runtime library should be used. By default the
+dynamic C runtime library is used.
+
+---
@@ -4 +26 @@
-- update to 3.16.4
+- update to 3.16.4 (bnc#894201)

Old:

  nss-3.16.4.tar.gz

New:

  nss-3.17.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.aSWvdd/_old  2014-09-08 21:28:16.0 +0200
+++ /var/tmp/diff_new_pack.aSWvdd/_new  2014-09-08 21:28:16.0 +0200
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel = 4.10.5
+BuildRequires:  mozilla-nspr-devel = 4.10.7
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.16.4
+Version:3.17
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_16_4_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.16/nss ; cd nss-3.16/nss 
; hg up NSS_3_16_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.17/nss ; cd nss-3.17/nss 
; hg up NSS_3_17_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in



++ nss-3.16.4.tar.gz - nss-3.17.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.16.4.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.17.tar.gz differ: char 5, 
line 1

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2014-08-15 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2014-08-15 09:58:16

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2014-07-21 
21:39:03.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2014-08-15 09:58:21.0 +0200
@@ -1,0 +2,24 @@
+Tue Aug 12 10:56:55 UTC 2014 - w...@rosenauer.org
+
+- update to 3.16.4
+  * now required for Firefox 32
+  Notable Changes:
+  * The following 1024-bit root CA certificate was restored to allow more
+time to develop a better transition strategy for affected sites. It was
+removed in NSS 3.16.3, but discussion in the mozilla.dev.security.policy
+forum led to the decision to keep this root included longer in order to
+give website administrators more time to update their web servers.
+- CN = GTE CyberTrust Global Root
+  * In NSS 3.16.3, the 1024-bit Entrust.net Secure Server Certification
+Authority root CA certificate was removed. In NSS 3.16.4, a 2048-bit
+intermediate CA certificate has been included, without explicit trust.
+The intention is to mitigate the effects of the previous removal of the
+1024-bit Entrust.net root certificate, because many public Internet
+sites still use the USERTrust Legacy Secure Server CA intermediate
+certificate that is signed by the 1024-bit Entrust.net root certificate.
+The inclusion of the intermediate certificate is a temporary measure to
+allow those sites to function, by allowing them to find a trust path to
+another 2048-bit root CA certificate. The temporarily included
+intermediate certificate expires November 1, 2015.
+
+---

Old:

  nss-3.16.3.tar.gz

New:

  nss-3.16.4.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.mmtZJR/_old  2014-08-15 09:58:23.0 +0200
+++ /var/tmp/diff_new_pack.mmtZJR/_new  2014-08-15 09:58:23.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.16.3
+Version:3.16.4
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,7 +36,7 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_16_3_RTM/src/nss-%{version}.tar.gz
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_16_4_RTM/src/nss-%{version}.tar.gz
 # hg clone https://hg.mozilla.org/projects/nss nss-3.16/nss ; cd nss-3.16/nss 
; hg up NSS_3_16_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in



++ nss-3.16.3.tar.gz - nss-3.16.4.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.16.3.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.16.4.tar.gz differ: char 5, 
line 1

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2014-07-21 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2014-07-21 21:38:54

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2014-05-13 
20:48:04.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2014-07-21 21:39:03.0 +0200
@@ -1,0 +2,69 @@
+Sat Jul  5 12:10:36 UTC 2014 - w...@rosenauer.org
+
+- update to 3.16.3
+  * required for Firefox 32
+  New Functions:
+  * CERT_GetGeneralNameTypeFromString (This function was already added
+in NSS 3.16.2, however, it wasn't declared in a public header file.)
+  Notable Changes:
+  * The following 1024-bit CA certificates were removed
+- Entrust.net Secure Server Certification Authority
+- GTE CyberTrust Global Root
+- ValiCert Class 1 Policy Validation Authority
+- ValiCert Class 2 Policy Validation Authority
+- ValiCert Class 3 Policy Validation Authority
+  * Additionally, the following CA certificate was removed as
+requested by the CA:
+- TDC Internet Root CA
+  * The following CA certificates were added:
+- Certification Authority of WoSign
+- CA 沃通根证书
+- DigiCert Assured ID Root G2
+- DigiCert Assured ID Root G3
+- DigiCert Global Root G2
+- DigiCert Global Root G3
+- DigiCert Trusted Root G4
+- QuoVadis Root CA 1 G3
+- QuoVadis Root CA 2 G3
+- QuoVadis Root CA 3 G3
+  * The Trust Bits were changed for the following CA certificates
+- Class 3 Public Primary Certification Authority
+- Class 3 Public Primary Certification Authority
+- Class 2 Public Primary Certification Authority - G2
+- VeriSign Class 2 Public Primary Certification Authority - G3
+- AC Raíz Certicámara S.A.
+- NetLock Uzleti (Class B) Tanusitvanykiado
+- NetLock Expressz (Class C) Tanusitvanykiado
+- changes in 3.16.2
+  New functionality:
+  * DTLS 1.2 is supported.
+  * The TLS application layer protocol negotiation (ALPN) extension
+is also supported on the server side.
+  * RSA-OEAP is supported. Use the new PK11_PrivDecrypt and
+PK11_PubEncrypt functions with the CKM_RSA_PKCS_OAEP mechanism.
+  * New Intel AES assembly code for 32-bit and 64-bit Windows,
+contributed by Shay Gueron and Vlad Krasnov of Intel.
+  New Functions:
+  * CERT_AddExtensionByOID
+  * PK11_PrivDecrypt
+  * PK11_PubEncrypt
+  New Macros
+  * SSL_ERROR_NEXT_PROTOCOL_NO_CALLBACK
+  * SSL_ERROR_NEXT_PROTOCOL_NO_PROTOCOL
+  Notable Changes:
+  * The btoa command has a new command-line option -w suffix, which
+causes the output to be wrapped in BEGIN/END lines with the
+given suffix
+  * The certutil commands supports additionals types of subject
+alt name extensions.
+  * The certutil command supports generic certificate extensions,
+by loading binary data from files, which have been prepared using
+external tools, or which have been extracted from other existing
+certificates and dumped to file.
+  * The certutil command supports three new certificate usage specifiers.
+  * The pp command supports printing UTF-8 (-u).
+  * On Linux, NSS is built with the -ffunction-sections -fdata-sections
+compiler flags and the --gc-sections linker flag to allow unused
+functions to be discarded.
+
+---

Old:

  nss-3.16.1.tar.gz

New:

  nss-3.16.3.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.tTyHsP/_old  2014-07-21 21:39:05.0 +0200
+++ /var/tmp/diff_new_pack.tTyHsP/_new  2014-07-21 21:39:06.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.16.1
+Version:3.16.3
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,7 +36,7 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_16_1_RTM/src/nss-%{version}.tar.gz
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_16_3_RTM/src/nss-%{version}.tar.gz
 # hg clone https://hg.mozilla.org/projects/nss nss-3.16/nss ; cd nss-3.16/nss 
; hg up NSS_3_16_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
@@ -278,9 +278,9 @@
   %{SOURCE1}  $RPM_BUILD_ROOT%{_libdir}/pkgconfig/nss.pc
 # prepare nss-config file
 popd
-NSS_VMAJOR=`cat lib/nss/nss.h | grep #define.*NSS_VMAJOR | awk '{print $3}'`
-NSS_VMINOR=`cat lib/nss/nss.h | grep 

commit mozilla-nss for openSUSE:Factory

2014-05-13 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2014-05-13 20:47:44

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2014-04-01 
06:46:24.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2014-05-13 20:48:04.0 +0200
@@ -1,0 +2,32 @@
+Thu May  8 05:46:17 UTC 2014 - w...@rosenauer.org
+
+- update to 3.16.1
+  * required for Firefox 31
+  New functionality:
+  * Added the ECC flag for modutil to select the module used for
+elliptic curve cryptography (ECC) operations.
+  New Functions:
+  * PK11_ExportDERPrivateKeyInfo/PK11_ExportPrivKeyInfo
+exports a private key in a DER-encoded ASN.1 PrivateKeyInfo type
+or a SECKEYPrivateKeyInfo structure. Only RSA private keys are
+supported now.
+  * SECMOD_InternalToPubMechFlags
+converts from NSS-internal to public representation of mechanism
+flags
+  New Types:
+  * ssl_padding_xtn
+the value of this enum constant changed from the experimental
+value 35655 to the IANA-assigned value 21
+  New Macros
+  * PUBLIC_MECH_ECC_FLAG
+a public mechanism flag for elliptic curve cryptography (ECC)
+operations
+  * SECMOD_ECC_FLAG
+an NSS-internal mechanism flag for elliptic curve cryptography
+(ECC) operations. This macro has the same numeric value as
+PUBLIC_MECH_ECC_FLAG.
+  Notable Changes:
+  * Imposed name constraints on the French government root CA ANSSI
+(DCISS).
+
+---

Old:

  nss-3.16.tar.gz

New:

  nss-3.16.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.q9vfhr/_old  2014-05-13 20:48:07.0 +0200
+++ /var/tmp/diff_new_pack.q9vfhr/_new  2014-05-13 20:48:07.0 +0200
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel = 4.9
+BuildRequires:  mozilla-nspr-devel = 4.10.5
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.16
+Version:3.16.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,7 +36,7 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_16_RTM/src/nss-%{version}.tar.gz
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_16_1_RTM/src/nss-%{version}.tar.gz
 # hg clone https://hg.mozilla.org/projects/nss nss-3.16/nss ; cd nss-3.16/nss 
; hg up NSS_3_16_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in



++ nss-3.16.tar.gz - nss-3.16.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.16.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.16.1.tar.gz differ: char 5, 
line 1

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2014-03-31 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2014-04-01 06:46:22

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2014-02-26 
23:20:37.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2014-04-01 06:46:24.0 +0200
@@ -1,0 +2,37 @@
+Fri Mar 21 21:16:31 UTC 2014 - w...@rosenauer.org
+
+- update to 3.16
+  * required for Firefox 29
+  * bmo#903885 - (CVE-2014-1492) In a wildcard certificate, the wildcard
+character should not be embedded within the U-label of an
+internationalized domain name. See the last bullet point in RFC 6125,
+Section 7.2.
+  * Supports the Linux x32 ABI. To build for the Linux x32 target, set
+the environment variable USE_X32=1 when building NSS.
+  New Functions:
+  * NSS_CMSSignerInfo_Verify
+  New Macros
+  * TLS_RSA_WITH_RC4_128_SHA, TLS_RSA_WITH_3DES_EDE_CBC_SHA, etc.,
+cipher suites that were first defined in SSL 3.0 can now be referred
+to with their official IANA names in TLS, with the TLS_ prefix.
+Previously, they had to be referred to with their names in SSL 3.0,
+with the SSL_ prefix.
+  Notable Changes:
+  * ECC is enabled by default. It is no longer necessary to set the
+environment variable NSS_ENABLE_ECC=1 when building NSS. To disable
+ECC, set the environment variable NSS_DISABLE_ECC=1 when building NSS.
+  * libpkix should not include the common name of CA as DNS names when
+evaluating name constraints.
+  * AESKeyWrap_Decrypt should not return SECSuccess for invalid keys.
+  * Fix a memory corruption in sec_pkcs12_new_asafe.
+  * If the NSS_SDB_USE_CACHE environment variable is set, skip the runtime
+test sdb_measureAccess.
+  * The built-in roots module has been updated to version 1.97, which
+adds, removes, and distrusts several certificates.
+  * The atob utility has been improved to automatically ignore lines of
+text that aren't in base64 format.
+  * The certutil utility has been improved to support creation of
+version 1 and version 2 certificates, in addition to the existing
+version 3 support.
+
+---

Old:

  nss-3.15.5.tar.gz

New:

  nss-3.16.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.r2QsSh/_old  2014-04-01 06:46:25.0 +0200
+++ /var/tmp/diff_new_pack.r2QsSh/_new  2014-04-01 06:46:25.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.15.5
+Version:3.16
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_5_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.15.5/nss ; cd 
nss-3.15.5/nss ; hg up NSS_3_15_5_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_16_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.16/nss ; cd nss-3.16/nss 
; hg up NSS_3_16_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -195,7 +195,7 @@
 %endif
 export NSS_USE_SYSTEM_SQLITE=1
 #export SQLITE_LIB_NAME=nsssqlite3
-MAKE_FLAGS=BUILD_OPT=1 NSS_ENABLE_ECC=1
+MAKE_FLAGS=BUILD_OPT=1
 make nss_build_all $MAKE_FLAGS
 # run testsuite
 %if 0%{?run_testsuite}



++ nss-3.15.5.tar.gz - nss-3.16.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.15.5.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.16.tar.gz differ: char 5, 
line 1

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2014-02-26 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2014-02-26 23:20:34

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2014-02-06 
07:06:31.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2014-02-26 23:20:37.0 +0100
@@ -1,0 +2,32 @@
+Tue Feb 25 11:31:18 UTC 2014 - w...@rosenauer.org
+
+- update to 3.15.5
+  * required for Firefox 28
+  * export FREEBL_LOWHASH to get the correct default headers
+(bnc#865539)
+  New functionality
+  * Added support for the TLS application layer protocol negotiation
+(ALPN) extension. Two SSL socket options, SSL_ENABLE_NPN and
+SSL_ENABLE_ALPN, can be used to control whether NPN or ALPN (or both)
+should be used for application layer protocol negotiation.
+  * Added the TLS padding extension. The extension type value is 35655,
+which may change when an official extension type value is assigned
+by IANA. NSS automatically adds the padding extension to ClientHello
+when necessary.
+  * Added a new macro CERT_LIST_TAIL, defined in certt.h, for getting
+the tail of a CERTCertList.
+  Notable Changes
+  * bmo#950129: Improve the OCSP fetching policy when verifying OCSP
+responses
+  * bmo#949060: Validate the iov input argument (an array of PRIOVec
+structures) of ssl_WriteV (called via PR_Writev). Applications should
+still take care when converting struct iov to PRIOVec because the
+iov_len members of the two structures have different types
+(size_t vs. int). size_t is unsigned and may be larger than int.
+
+---
+Thu Feb 20 10:55:30 UTC 2014 - a...@ajaissle.de
+
+- BuildRequire mozilla-nspr = 4.9
+
+---

Old:

  nss-3.15.4.tar.gz

New:

  nss-3.15.5.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.7RKjuH/_old  2014-02-26 23:20:39.0 +0100
+++ /var/tmp/diff_new_pack.7RKjuH/_new  2014-02-26 23:20:39.0 +0100
@@ -21,11 +21,11 @@
 
 Name:   mozilla-nss
 BuildRequires:  gcc-c++
-BuildRequires:  mozilla-nspr-devel
+BuildRequires:  mozilla-nspr-devel = 4.9
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.15.4
+Version:3.15.5
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_4_RTM/src/nss-%{version}.tar.gz
-# hg clone https://hg.mozilla.org/projects/nss nss-3.15.4/nss ; cd 
nss-3.15.4/nss ; hg up NSS_3_15_4_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_5_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.15.5/nss ; cd 
nss-3.15.5/nss ; hg up NSS_3_15_5_RTM
 #Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
@@ -85,7 +85,7 @@
 Group:  Development/Libraries/Other
 Requires:   libfreebl3
 Requires:   libsoftokn3
-Requires:   mozilla-nspr-devel
+Requires:   mozilla-nspr-devel = 4.9
 Requires:   mozilla-nss = %{version}-%{release}
 # bug437293
 %ifarch ppc64
@@ -185,6 +185,7 @@
 find . -name '*.[ch]' -print -exec sed -i 
s/__DATE__/${DATE}/g;s/__TIME__/${TIME}/g {} +
 
 export FREEBL_NO_DEPEND=1
+export FREEBL_LOWHASH=1
 export NSPR_INCLUDE_DIR=`nspr-config --includedir`
 export NSPR_LIB_DIR=`nspr-config --libdir`
 export OPT_FLAGS=$RPM_OPT_FLAGS -fno-strict-aliasing



++ nss-3.15.4.tar.gz - nss-3.15.5.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.15.4.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.15.5.tar.gz differ: char 5, 
line 1

++ renegotiate-transitional.patch ++
--- /var/tmp/diff_new_pack.7RKjuH/_old  2014-02-26 23:20:39.0 +0100
+++ /var/tmp/diff_new_pack.7RKjuH/_new  2014-02-26 23:20:39.0 +0100
@@ -1,12 +1,8 @@
 diff --git a/lib/ssl/sslsock.c b/lib/ssl/sslsock.c
+index e6b2387..87fbe1d 100644
 --- a/lib/ssl/sslsock.c
 +++ b/lib/ssl/sslsock.c
-@@ -144,17 +144,17 @@ static sslOptions ssl_defaults = {
- PR_FALSE, /* fdx*/
- PR_FALSE, /* v2CompatibleHello  */ /* now defaults to off in NSS 3.13 */
- PR_TRUE,  /* detectRollBack */
- PR_FALSE,   /* noStepDown */
- PR_FALSE,   /* bypassPKCS11   

commit mozilla-nss for openSUSE:Factory

2014-02-05 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2014-02-06 07:06:30

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2014-01-10 
21:21:04.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2014-02-06 07:06:31.0 +0100
@@ -14,0 +15,2 @@
+  * MFSA 2014-12/CVE-2014-1490/CVE-2014-1491
+NSS ticket handling issues



Other differences:
--


-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2014-01-10 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2014-01-10 21:21:02

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2013-12-10 
17:43:54.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2014-01-10 21:21:04.0 +0100
@@ -1,0 +2,38 @@
+Tue Jan  7 08:39:04 UTC 2014 - w...@rosenauer.org
+
+- update to 3.15.4
+  * required for Firefox 27
+  * regular CA root store update (1.96)
+  * Reordered the cipher suites offered in SSL/TLS client hello
+messages to match modern best practices.
+  * Improved SSL/TLS false start. In addition to enabling the
+SSL_ENABLE_FALSE_START option, an application must now register
+a callback using the SSL_SetCanFalseStartCallback function.
+  * When false start is enabled, libssl will sometimes return
+unencrypted, unauthenticated data from PR_Recv
+(CVE-2013-1740, bmo#919877)
+  New functionality
+  * Implemented OCSP querying using the HTTP GET method, which is
+the new default, and will fall back to the HTTP POST method.
+  * Implemented OCSP server functionality for testing purposes
+(httpserv utility).
+  * Support SHA-1 signatures with TLS 1.2 client authentication.
+  * Added the --empty-password command-line option to certutil,
+to be used with -N: use an empty password when creating a new
+database.
+  * Added the -w command-line option to pp: don't wrap long output
+lines.
+  New functions
+  * CERT_ForcePostMethodForOCSP
+  * CERT_GetSubjectNameDigest
+  * CERT_GetSubjectPublicKeyDigest
+  * SSL_PeerCertificateChain
+  * SSL_RecommendedCanFalseStart
+  * SSL_SetCanFalseStartCallback
+  New types
+  * CERT_REV_M_FORCE_POST_METHOD_FOR_OCSP: When this flag is used,
+libpkix will never attempt to use the HTTP GET method for OCSP
+requests; it will always use POST.
+- removed obsolete char.patch
+
+---

Old:

  char.patch
  nss-3.15.3.1.tar.gz

New:

  nss-3.15.4.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.gBKKC8/_old  2014-01-10 21:21:06.0 +0100
+++ /var/tmp/diff_new_pack.gBKKC8/_new  2014-01-10 21:21:06.0 +0100
@@ -1,8 +1,8 @@
 #
 # spec file for package mozilla-nss
 #
-# Copyright (c) 2013 SUSE LINUX Products GmbH, Nuernberg, Germany.
-# Copyright (c) 2006-2013 Wolfgang Rosenauer
+# Copyright (c) 2014 SUSE LINUX Products GmbH, Nuernberg, Germany.
+# Copyright (c) 2006-2014 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.15.3.1
+Version:3.15.4
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,9 +36,9 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-# hg clone https://hg.mozilla.org/projects/nss nss-3.15.3.1 ; cd nss-3.15.3.1 
; hg up NSS_3_15_3_1_RTM
-#Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_3_1_RTM/src/nss-%{version}.tar.gz
-Source: nss-%{version}.tar.gz
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_4_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.15.4/nss ; cd 
nss-3.15.4/nss ; hg up NSS_3_15_4_RTM
+#Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
 Source4:%{name}-rpmlintrc
@@ -50,7 +50,6 @@
 #Source10:   PayPalEE.cert
 Patch1: nss-opt.patch
 Patch2: system-nspr.patch
-Patch3: char.patch
 Patch4: nss-no-rpath.patch
 Patch5: renegotiate-transitional.patch
 Patch6: malloc.patch
@@ -166,7 +165,6 @@
 cd nss
 %patch1 -p1
 %patch2 -p1
-%patch3 -p1
 %patch4 -p1
 %patch5 -p1
 %if %suse_version  1110



++ nss-3.15.3.1.tar.gz - nss-3.15.4.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.15.3.1.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.15.4.tar.gz differ: char 4, 
line 1

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2013-12-10 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2013-12-10 17:43:53

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2013-12-07 
07:46:24.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2013-12-10 17:43:54.0 +0100
@@ -1,0 +2,7 @@
+Thu Dec  5 18:59:27 UTC 2013 - w...@rosenauer.org
+
+- update to 3.15.3.1 (bnc#854367)
+  * includes certstore update (1.95) (bmo#946351)
+(explicitely distrust AC DG Tresor SSL)
+
+---

Old:

  nss-3.15.3.tar.gz

New:

  nss-3.15.3.1.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.XEuEpc/_old  2013-12-10 17:43:55.0 +0100
+++ /var/tmp/diff_new_pack.XEuEpc/_new  2013-12-10 17:43:55.0 +0100
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.15.3
+Version:3.15.3.1
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,9 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-# hg clone https://hg.mozilla.org/projects/nss nss-3.15.3 ; cd nss-3.15.3 ; hg 
up NSS_3_15_3_RTM
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_3_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.15.3.1 ; cd nss-3.15.3.1 
; hg up NSS_3_15_3_1_RTM
+#Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_3_1_RTM/src/nss-%{version}.tar.gz
+Source: nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
 Source4:%{name}-rpmlintrc



++ nss-3.15.3.tar.gz - nss-3.15.3.1.tar.gz ++
/work/SRC/openSUSE:Factory/mozilla-nss/nss-3.15.3.tar.gz 
/work/SRC/openSUSE:Factory/.mozilla-nss.new/nss-3.15.3.1.tar.gz differ: char 4, 
line 1

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2013-12-06 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2013-12-07 07:46:23

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2013-11-20 
10:48:48.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2013-12-07 07:46:24.0 +0100
@@ -1,0 +2,5 @@
+Wed Dec  4 14:40:39 CET 2013 - m...@suse.de
+
+- adapt specfile to ppc64le
+
+---



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.qEKsb1/_old  2013-12-07 07:46:25.0 +0100
+++ /var/tmp/diff_new_pack.qEKsb1/_new  2013-12-07 07:46:25.0 +0100
@@ -190,7 +190,7 @@
 export NSPR_LIB_DIR=`nspr-config --libdir`
 export OPT_FLAGS=$RPM_OPT_FLAGS -fno-strict-aliasing
 export LIBDIR=%{_libdir}
-%ifarch x86_64 s390x ppc64 ia64 aarch64
+%ifarch x86_64 s390x ppc64 ppc64le ia64 aarch64
 export USE_64=1
 %endif
 export NSS_USE_SYSTEM_SQLITE=1



-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2013-11-20 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2013-11-20 10:48:47

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2013-09-29 
17:50:28.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2013-11-20 10:48:48.0 +0100
@@ -1,0 +2,11 @@
+Mon Nov 11 22:11:57 UTC 2013 - w...@rosenauer.org
+
+- update to 3.15.3 (bnc#850148)
+  * CERT_VerifyCert returns SECSuccess (saying certificate is good)
+even for bad certificates, when the CERTVerifyLog log parameter
+is given (bmo#910438)
+  * NSS advertises TLS 1.2 ciphersuites in a TLS 1.1 ClientHello
+(bmo#919677)
+  * fix CVE-2013-5605
+
+---

Old:

  nss-3.15.2.tar.gz

New:

  nss-3.15.3.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.QbG10d/_old  2013-11-20 10:48:49.0 +0100
+++ /var/tmp/diff_new_pack.QbG10d/_new  2013-11-20 10:48:49.0 +0100
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.15.2
+Version:3.15.3
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-# hg clone https://hg.mozilla.org/projects/nss; hg up NSS_3_15_1_RTM
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_2_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss nss-3.15.3 ; cd nss-3.15.3 ; hg 
up NSS_3_15_3_RTM
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_3_RTM/src/nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
 Source4:%{name}-rpmlintrc
@@ -75,8 +75,8 @@
 %description
 Network Security Services (NSS) is a set of libraries designed to
 support cross-platform development of security-enabled server
-applications. Applications built with NSS can support SSL v2 and v3,
-TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3
+applications. Applications built with NSS can support SSL v3,
+TLS v1.0, v1.1, v1.2, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3
 certificates, and other security standards.
 
 
@@ -95,11 +95,10 @@
 %description devel
 Network Security Services (NSS) is a set of libraries designed to
 support cross-platform development of security-enabled server
-applications. Applications built with NSS can support SSL v2 and v3,
-TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3
+applications. Applications built with NSS can support SSL v3,
+TLS v1.0, v1.1, v1.2, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3
 certificates, and other security standards.
 
-
 %package tools
 Summary:Tools for developing, debugging, and managing applications 
that use NSS
 Group:  System/Management
@@ -130,8 +129,8 @@
 %description -n libfreebl3
 Network Security Services (NSS) is a set of libraries designed to
 support cross-platform development of security-enabled server
-applications. Applications built with NSS can support SSL v2 and v3,
-TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3
+applications. Applications built with NSS can support SSL v3,
+TLS v1.0, v1.1, v1.2, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3
 certificates, and other security standards.
 
 This package installs the freebl library from NSS.
@@ -145,8 +144,8 @@
 %description -n libsoftokn3
 Network Security Services (NSS) is a set of libraries designed to
 support cross-platform development of security-enabled server
-applications. Applications built with NSS can support SSL v2 and v3,
-TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3
+applications. Applications built with NSS can support SSL v3,
+TLS v1.0, v1.1, v1.2, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3
 certificates, and other security standards.
 
 Network Security Services Softoken Cryptographic Module



++ nss-3.15.2.tar.gz - nss-3.15.3.tar.gz ++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/nss-3.15.2/nss/.hg_archival.txt 
new/nss-3.15.3/nss/.hg_archival.txt
--- old/nss-3.15.2/nss/.hg_archival.txt 2013-09-25 15:57:55.0 +0200
+++ new/nss-3.15.3/nss/.hg_archival.txt 2013-11-09 18:23:30.0 +0100
@@ -1,4 +1,4 @@
 repo: 9949429068caa6bb8827a8ceeaa7c605d722f47f
-node: d7713e6888f1306b8f4e8afe6e5f897360007362

commit mozilla-nss for openSUSE:Factory

2013-09-29 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2013-09-29 17:50:27

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2013-07-05 
20:37:39.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2013-09-29 17:50:28.0 +0200
@@ -1,0 +2,16 @@
+Sat Sep 28 04:20:41 UTC 2013 - crrodrig...@opensuse.org
+
+- update to 3.15.2 (bnc#842979)
+  * Support for AES-GCM ciphersuites that use the SHA-256 PRF
+  * MD2, MD4, and MD5 signatures are no longer accepted for OCSP
+or CRLs
+  * Add PK11_CipherFinal macro
+  * sizeof() used incorrectly
+  * nssutil_ReadSecmodDB() leaks memory
+  * Allow SSL_HandshakeNegotiatedExtension to be called before
+the handshake is finished.
+  * Deprecate the SSL cipher policy code
+  * Avoid uninitialized data read in the event of a decryption
+failure. (CVE-2013-1739)
+
+---

Old:

  nss-3.15.1.tar.gz

New:

  nss-3.15.2.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.ob9yjC/_old  2013-09-29 17:50:29.0 +0200
+++ /var/tmp/diff_new_pack.ob9yjC/_new  2013-09-29 17:50:29.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.15.1
+Version:3.15.2
 Release:0
 # bug437293
 %ifarch ppc64
@@ -37,7 +37,7 @@
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
 # hg clone https://hg.mozilla.org/projects/nss; hg up NSS_3_15_1_RTM
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_1_RTM/src/nss-%{version}.tar.gz
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_15_2_RTM/src/nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
 Source4:%{name}-rpmlintrc



++ nss-3.15.1.tar.gz - nss-3.15.2.tar.gz ++
 4143 lines of diff (skipped)

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2013-07-05 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2013-07-05 20:37:37

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2013-07-04 
10:11:57.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2013-07-05 20:37:39.0 +0200
@@ -1,0 +2,5 @@
+Fri Jul  5 08:08:57 UTC 2013 - lnus...@suse.de
+
+- fix 32bit requirement, it's without () actually
+
+---



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.uAh1oX/_old  2013-07-05 20:37:40.0 +0200
+++ /var/tmp/diff_new_pack.uAh1oX/_new  2013-07-05 20:37:40.0 +0200
@@ -62,7 +62,7 @@
 %if %{_lib} == lib64
 Requires:   libnssckbi.so()(64bit)
 %else
-Requires:   libnssckbi.so()
+Requires:   libnssckbi.so
 %endif
 BuildRoot:  %{_tmppath}/%{name}-%{version}-build
 %define nssdbdir %{_sysconfdir}/pki/nssdb



-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2013-06-14 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2013-06-14 16:46:40

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2013-04-24 
12:23:41.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2013-06-14 16:46:42.0 +0200
@@ -1,0 +2,70 @@
+Tue Jun 11 04:58:56 UTC 2013 - w...@rosenauer.org
+
+- update to 3.15
+  * Packaging
++ removed obsolete patches
+  * nss-disable-expired-testcerts.patch
+  * bug-834091.patch
+  * New Functionality
++ Support for OCSP Stapling (RFC 6066, Certificate Status
+  Request) has been added for both client and server sockets.
+  TLS client applications may enable this via a call to
+  SSL_OptionSetDefault(SSL_ENABLE_OCSP_STAPLING, PR_TRUE);
++ Added function SECITEM_ReallocItemV2. It replaces function
+  SECITEM_ReallocItem, which is now declared as obsolete.
++ Support for single-operation (eg: not multi-part) symmetric
+  key encryption and decryption, via PK11_Encrypt and PK11_Decrypt.
++ certutil has been updated to support creating name constraints
+  extensions.
+  * New Functions
+in ssl.h
+  SSL_PeerStapledOCSPResponse - Returns the server's stapled
+OCSP response, when used with a TLS client socket that
+negotiated the status_request extension.
+  SSL_SetStapledOCSPResponses - Set's a stapled OCSP response
+for a TLS server socket to return when clients send the
+status_request extension.
+in ocsp.h
+  CERT_PostOCSPRequest - Primarily intended for testing, permits
+the sending and receiving of raw OCSP request/responses.
+in secpkcs7.h
+  SEC_PKCS7VerifyDetachedSignatureAtTime - Verifies a PKCS#7
+signature at a specific time other than the present time.
+in xconst.h
+  CERT_EncodeNameConstraintsExtension - Matching function for
+CERT_DecodeNameConstraintsExtension, added in NSS 3.10.
+in secitem.h
+  SECITEM_AllocArray
+  SECITEM_DupArray
+  SECITEM_FreeArray
+  SECITEM_ZfreeArray - Utility functions to handle the
+allocation and deallocation of SECItemArrays
+  SECITEM_ReallocItemV2 - Replaces SECITEM_ReallocItem, which is
+now obsolete. SECITEM_ReallocItemV2 better matches caller
+expectations, in that it updates item-len on allocation.
+For more details of the issues with SECITEM_ReallocItem,
+see Bug 298649 and Bug 298938.
+in pk11pub.h
+  PK11_Decrypt - Performs decryption as a single PKCS#11
+operation (eg: not multi-part). This is necessary for AES-GCM.
+  PK11_Encrypt - Performs encryption as a single PKCS#11
+operation (eg: not multi-part). This is necessary for AES-GCM.
+  * New Types
+in secitem.h
+  SECItemArray - Represents a variable-length array of SECItems.
+  * New Macros
+in ssl.h
+  SSL_ENABLE_OCSP_STAPLING - Used with SSL_OptionSet to configure
+TLS client sockets to request the certificate_status extension
+(eg: OCSP stapling) when set to PR_TRUE
+  * Notable changes
++ SECITEM_ReallocItem is now deprecated. Please consider using
+  SECITEM_ReallocItemV2 in all future code.
++ The list of root CA certificates in the nssckbi module has
+  been updated.
++ The default implementation of SSL_AuthCertificate has been
+  updated to add certificate status responses stapled by the TLS
+  server to the OCSP cache.
+  * a lot of bugfixes
+
+---

Old:

  bug-834091.patch
  nss-3.14.3.tar.gz
  nss-disable-expired-testcerts.patch

New:

  nss-3.15.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.H2ZqAb/_old  2013-06-14 16:46:44.0 +0200
+++ /var/tmp/diff_new_pack.H2ZqAb/_new  2013-06-14 16:46:44.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.14.3
+Version:3.15
 Release:0
 # bug437293
 %ifarch ppc64
@@ -36,8 +36,8 @@
 License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
-# cvs -d :pserver:anonym...@cvs-mirror.mozilla.org:/cvsroot co -r RTM_TAG NSS
-Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_14_3_RTM/src/nss-%{version}.tar.gz
+# hg clone https://hg.mozilla.org/projects/nss; hg up NSS_3_15_RTM
+Source: 

commit mozilla-nss for openSUSE:Factory

2013-04-24 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2013-04-24 10:47:42

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2013-04-05 
09:29:13.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2013-04-24 10:47:43.0 +0200
@@ -1,0 +2,5 @@
+Tue Apr 16 10:27:04 UTC 2013 - idon...@suse.com
+
+- Add Source URL, see https://en.opensuse.org/SourceUrls
+
+---

Old:

  nss-3.14.3.tar.bz2

New:

  nss-3.14.3.tar.gz



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.suJjEk/_old  2013-04-24 10:47:58.0 +0200
+++ /var/tmp/diff_new_pack.suJjEk/_new  2013-04-24 10:47:58.0 +0200
@@ -37,7 +37,7 @@
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
 # cvs -d :pserver:anonym...@cvs-mirror.mozilla.org:/cvsroot co -r RTM_TAG NSS
-Source: nss-%{version}.tar.bz2
+Source: 
https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_14_3_RTM/src/nss-%{version}.tar.gz
 Source1:nss.pc.in
 Source3:nss-config.in
 Source4:%{name}-rpmlintrc



-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2013-04-05 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2013-04-05 09:29:13

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2013-03-01 
10:52:37.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2013-04-05 09:29:13.0 +0200
@@ -1,0 +2,9 @@
+Sun Mar 24 20:07:59 UTC 2013 - w...@rosenauer.org
+
+- disable tests with expired certificates
+  (nss-disable-expired-testcerts.patch)
+- add SEC_PKCS7VerifyDetachedSignatureAtTime using patch from
+  mozilla tree to fulfill Firefox 21 requirements
+  (bug-834091.patch; bmo#834091)
+
+---
@@ -27,0 +37,2 @@
+  * MFSA 2013-40/CVE-2013-0791 (bmo#629816)
+Out-of-bounds array read in CERT_DecodeCertPackage

New:

  bug-834091.patch
  nss-disable-expired-testcerts.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.K7nq9L/_old  2013-04-05 09:29:16.0 +0200
+++ /var/tmp/diff_new_pack.K7nq9L/_new  2013-04-05 09:29:16.0 +0200
@@ -55,6 +55,8 @@
 Patch6: malloc.patch
 Patch7: nss-disable-ocsp-test.patch
 Patch8: nss-sqlitename.patch
+Patch9: nss-disable-expired-testcerts.patch
+Patch10:bug-834091.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr = %nspr_ver
 PreReq: libfreebl3 = %{nss_softokn_fips_version}
@@ -170,6 +172,8 @@
 %endif
 %patch7
 %patch8
+%patch9
+%patch10
 # additional CA certificates
 #cd security/nss/lib/ckfw/builtins
 #cat %{SOURCE2}  certdata.txt

++ bug-834091.patch ++
Index: security/nss/lib/pkcs7/p7decode.c
===
RCS file: /cvsroot/mozilla/security/nss/lib/pkcs7/p7decode.c,v
retrieving revision 1.31
diff -u -8 -p -r1.31 p7decode.c
--- security/nss/lib/pkcs7/p7decode.c   12 Dec 2012 19:25:36 -  1.31
+++ security/nss/lib/pkcs7/p7decode.c   25 Jan 2013 23:22:54 -
@@ -1276,17 +1276,18 @@ SEC_PKCS7ContentIsSigned(SEC_PKCS7Conten
  * there should be NO authenticatedAttributes (signerinfo-authAttr should
  * be NULL).
  */
 static PRBool
 sec_pkcs7_verify_signature(SEC_PKCS7ContentInfo *cinfo,
   SECCertUsage certusage,
   const SECItem *detached_digest,
   HASH_HashType digest_type,
-  PRBool keepcerts)
+  PRBool keepcerts,
+  PRTime atTime)
 {
 SECAlgorithmID **digestalgs, *bulkid;
 const SECItem *digest;
 SECItem **digests;
 SECItem **rawcerts;
 CERTSignedCrl **crls;
 SEC_PKCS7SignerInfo **signerinfos, *signerinfo;
 CERTCertificate *cert, **certs;
@@ -1294,17 +1295,18 @@ sec_pkcs7_verify_signature(SEC_PKCS7Cont
 CERTCertDBHandle *certdb, *defaultdb; 
 SECOidTag encTag,digestTag;
 HASH_HashType found_type;
 int i, certcount;
 SECKEYPublicKey *publickey;
 SECItem *content_type;
 PK11SymKey *sigkey;
 SECItem *encoded_stime;
-int64 stime;
+PRTime stime;
+PRTime verificationTime;
 SECStatus rv;
 
 /*
  * Everything needed in order to goto done safely.
  */
 goodsig = PR_FALSE;
 certcount = 0;
 cert = NULL;
@@ -1431,18 +1433,20 @@ sec_pkcs7_verify_signature(SEC_PKCS7Cont
 /*
  * XXX  This uses the signing time, if available.  Additionally, we
  * might want to, if there is no signing time, get the message time
  * from the mail header itself, and use that.  That would require
  * a change to our interface though, and for S/MIME callers to pass
  * in a time (and for non-S/MIME callers to pass in nothing, or
  * maybe make them pass in the current time, always?).
  */
+verificationTime = atTime ? atTime
+ : (encoded_stime ? stime : PR_Now());
 if (CERT_VerifyCert (certdb, cert, PR_TRUE, certusage,
-encoded_stime != NULL ? stime : PR_Now(),
+verificationTime,
 cinfo-pwfn_arg, NULL) != SECSuccess)
{
/*
 * XXX Give the user an option to check the signature anyway?
 * If we want to do this, need to give a way to leave and display
 * some dialog and get the answer and come back through (or do
 * the rest of what we do below elsewhere, maybe by putting it
 * in a function that we call below and could 

commit mozilla-nss for openSUSE:Factory

2013-03-01 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2013-03-01 10:52:35

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2013-01-10 
13:33:25.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2013-03-01 10:52:37.0 +0100
@@ -1,0 +2,31 @@
+Thu Feb 28 21:55:49 UTC 2013 - w...@rosenauer.org
+
+- update to 3.14.3
+  * No new major functionality is introduced in this release. This
+release is a patch release to address CVE-2013-1620 (bmo#822365)
+  * certutil -a was not correctly producing ASCII output as
+requested. (bmo#840714)
+  * NSS 3.14.2 broke compilation with older versions of sqlite that
+lacked the SQLITE_FCNTL_TEMPFILENAME file control. NSS 3.14.3 now
+properly compiles when used with older versions of sqlite
+(bmo#837799) - remove system-sqlite.patch
+- add aarch64 support
+
+---
+Tue Feb  5 12:51:56 UTC 2013 - w...@rosenauer.org
+
+- added system-sqlite.patch (bmo#837799)
+  * do not depend on latest sqlite just for a #define
+- enable system sqlite usage again
+
+---
+Sat Feb  2 16:05:20 UTC 2013 - w...@rosenauer.org
+
+- update to 3.14.2
+  * required for Firefox = 20
+  * removed obsolete nssckbi update patch
+- disable system sqlite usage since we depend on 3.7.15 which is
+  not provided in any openSUSE distribution
+  * add nss-sqlitename.patch to avoid any name clash
+
+---

Old:

  nss-3.14.1.tar.bz2
  nssckbi-1.93.patch

New:

  nss-3.14.3.tar.bz2
  nss-sqlitename.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.5dxhf7/_old  2013-03-01 10:52:39.0 +0100
+++ /var/tmp/diff_new_pack.5dxhf7/_new  2013-03-01 10:52:39.0 +0100
@@ -2,7 +2,7 @@
 # spec file for package mozilla-nss
 #
 # Copyright (c) 2013 SUSE LINUX Products GmbH, Nuernberg, Germany.
-# Copyright (c) 2006-2012 Wolfgang Rosenauer
+# Copyright (c) 2006-2013 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -23,9 +23,9 @@
 BuildRequires:  gcc-c++
 BuildRequires:  mozilla-nspr-devel
 BuildRequires:  pkg-config
-BuildRequires:  sqlite3-devel
+BuildRequires:  sqlite-devel
 BuildRequires:  zlib-devel
-Version:3.14.1
+Version:3.14.3
 Release:0
 # bug437293
 %ifarch ppc64
@@ -54,7 +54,7 @@
 Patch5: renegotiate-transitional.patch
 Patch6: malloc.patch
 Patch7: nss-disable-ocsp-test.patch
-Patch8: nssckbi-1.93.patch
+Patch8: nss-sqlitename.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr = %nspr_ver
 PreReq: libfreebl3 = %{nss_softokn_fips_version}
@@ -187,12 +187,11 @@
 export NSPR_LIB_DIR=`nspr-config --libdir`
 export OPT_FLAGS=$RPM_OPT_FLAGS -fno-strict-aliasing
 export LIBDIR=%{_libdir}
-%ifarch x86_64 s390x ppc64 ia64
+%ifarch x86_64 s390x ppc64 ia64 aarch64
 export USE_64=1
 %endif
-%if %suse_version  1020
 export NSS_USE_SYSTEM_SQLITE=1
-%endif
+#export SQLITE_LIB_NAME=nsssqlite3
 MAKE_FLAGS=BUILD_OPT=1 NSS_ENABLE_ECC=1
 make nss_build_all $MAKE_FLAGS
 # run testsuite
@@ -236,10 +235,8 @@
 cp -L  lib/libfreebl3.so \
lib/libfreebl3.chk \
$RPM_BUILD_ROOT/%{_lib}
-%if %suse_version  1030
-cp -L  lib/libnsssqlite3.so \
-   $RPM_BUILD_ROOT%{_libdir}
-%endif
+#cp -L  lib/libnsssqlite3.so \
+#   $RPM_BUILD_ROOT%{_libdir}
 # copy static libs
 cp -L  lib/libcrmf.a \
lib/libnssb.a \
@@ -347,9 +344,7 @@
 %{_libdir}/libnssutil3.so
 %{_libdir}/libsmime3.so
 %{_libdir}/libssl3.so
-%if %suse_version  1030
-%{_libdir}/libnsssqlite3.so
-%endif
+#%{_libdir}/libnsssqlite3.so
 
 %files devel
 %defattr(644, root, root, 755)



++ nss-3.14.1.tar.bz2 - nss-3.14.3.tar.bz2 ++
 205782 lines of diff (skipped)

++ nss-disable-ocsp-test.patch ++
--- /var/tmp/diff_new_pack.5dxhf7/_old  2013-03-01 10:52:43.0 +0100
+++ /var/tmp/diff_new_pack.5dxhf7/_new  2013-03-01 10:52:43.0 +0100
@@ -1,16 +1,14 @@
 Index: security/nss/tests/chains/scenarios/scenarios
 ===
 RCS file: /cvsroot/mozilla/security/nss/tests/chains/scenarios/scenarios,v
-retrieving revision 1.9
-diff -u -p -6 -r1.9 

commit mozilla-nss for openSUSE:Factory

2013-01-10 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2013-01-10 13:33:23

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2013-01-04 
13:11:55.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2013-01-10 13:33:25.0 +0100
@@ -4,2 +4,3 @@
-- updated CA database (nssckbi-1.93.patch) (bmo#825022)
-  * revoke mis-issued intermediate certificates from TURKTRUST
+- updated CA database (nssckbi-1.93.patch)
+  * MFSA 2013-20/CVE-2013-0743 (bmo#825022, bnc#796628)
+revoke mis-issued intermediate certificates from TURKTRUST



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.5DUTf9/_old  2013-01-10 13:33:26.0 +0100
+++ /var/tmp/diff_new_pack.5DUTf9/_new  2013-01-10 13:33:26.0 +0100
@@ -1,7 +1,7 @@
 #
 # spec file for package mozilla-nss
 #
-# Copyright (c) 2012 SUSE LINUX Products GmbH, Nuernberg, Germany.
+# Copyright (c) 2013 SUSE LINUX Products GmbH, Nuernberg, Germany.
 # Copyright (c) 2006-2012 Wolfgang Rosenauer
 #
 # All modifications and additions to the file contributed by third parties



-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2013-01-04 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2013-01-04 13:11:52

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2012-12-28 
22:45:33.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2013-01-04 13:11:55.0 +0100
@@ -1,0 +2,6 @@
+Sun Dec 30 17:59:34 UTC 2012 - w...@rosenauer.org
+
+- updated CA database (nssckbi-1.93.patch) (bmo#825022)
+  * revoke mis-issued intermediate certificates from TURKTRUST
+
+---

New:

  nssckbi-1.93.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.sI8jK7/_old  2013-01-04 13:11:56.0 +0100
+++ /var/tmp/diff_new_pack.sI8jK7/_new  2013-01-04 13:11:56.0 +0100
@@ -54,6 +54,7 @@
 Patch5: renegotiate-transitional.patch
 Patch6: malloc.patch
 Patch7: nss-disable-ocsp-test.patch
+Patch8: nssckbi-1.93.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr = %nspr_ver
 PreReq: libfreebl3 = %{nss_softokn_fips_version}
@@ -168,6 +169,7 @@
 %patch6
 %endif
 %patch7
+%patch8
 # additional CA certificates
 #cd security/nss/lib/ckfw/builtins
 #cat %{SOURCE2}  certdata.txt



++ nssckbi-1.93.patch ++
diff -uprN --exclude CVS 
nss-3.14.1/mozilla/security/nss/lib/ckfw/builtins/certdata.txt 
mozilla/security/nss/lib/ckfw/builtins/certdata.txt
--- nss-3.14.1/mozilla/security/nss/lib/ckfw/builtins/certdata.txt  
2012-10-18 18:26:52.0 +0200
+++ security/nss/lib/ckfw/builtins/certdata.txt 2012-12-29 17:32:45.0 
+0100
@@ -2,7 +2,7 @@
 # This Source Code Form is subject to the terms of the Mozilla Public
 # License, v. 2.0. If a copy of the MPL was not distributed with this
 # file, You can obtain one at http://mozilla.org/MPL/2.0/.
-CVS_ID @(#) $RCSfile: certdata.txt,v $ $Revision: 1.86 $ $Date: 2012/10/18 
16:26:52 $
+CVS_ID @(#) $RCSfile: certdata.txt,v $ $Revision: 1.87 $ $Date: 2012/12/29 
16:32:45 $
 
 #
 # certdata.txt
@@ -24424,171 +24424,6 @@ CKA_TRUST_CODE_SIGNING CK_TRUST CKT_NSS_
 CKA_TRUST_STEP_UP_APPROVED CK_BBOOL CK_FALSE
 
 #
-# Certificate TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı
-#
-# Issuer: O=T..RKTRUST Bilgi ..leti..im ve Bili..im G..venli..i Hizmetleri 
A...,L=Ankara,C=TR,CN=T..RKTRUST Elektronik Sertifika Hizmet Sa..lay..c..s..
-# Serial Number: 1 (0x1)
-# Subject: O=T..RKTRUST Bilgi ..leti..im ve Bili..im G..venli..i Hizmetleri 
A...,L=Ankara,C=TR,CN=T..RKTRUST Elektronik Sertifika Hizmet Sa..lay..c..s..
-# Not Valid Before: Tue Dec 25 18:37:19 2007
-# Not Valid After : Fri Dec 22 18:37:19 2017
-# Fingerprint (MD5): 2B:70:20:56:86:82:A0:18:C8:07:53:12:28:70:21:72
-# Fingerprint (SHA1): 
F1:7F:6F:B6:31:DC:99:E3:A3:C8:7F:FE:1C:F1:81:10:88:D9:60:33
-CKA_CLASS CK_OBJECT_CLASS CKO_CERTIFICATE
-CKA_TOKEN CK_BBOOL CK_TRUE
-CKA_PRIVATE CK_BBOOL CK_FALSE
-CKA_MODIFIABLE CK_BBOOL CK_FALSE
-CKA_LABEL UTF8 TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı
-CKA_CERTIFICATE_TYPE CK_CERTIFICATE_TYPE CKC_X_509
-CKA_SUBJECT MULTILINE_OCTAL
-\060\201\277\061\077\060\075\006\003\125\004\003\014\066\124\303
-\234\122\113\124\122\125\123\124\040\105\154\145\153\164\162\157
-\156\151\153\040\123\145\162\164\151\146\151\153\141\040\110\151
-\172\155\145\164\040\123\141\304\237\154\141\171\304\261\143\304
-\261\163\304\261\061\013\060\011\006\003\125\004\006\023\002\124
-\122\061\017\060\015\006\003\125\004\007\014\006\101\156\153\141
-\162\141\061\136\060\134\006\003\125\004\012\014\125\124\303\234
-\122\113\124\122\125\123\124\040\102\151\154\147\151\040\304\260
-\154\145\164\151\305\237\151\155\040\166\145\040\102\151\154\151
-\305\237\151\155\040\107\303\274\166\145\156\154\151\304\237\151
-\040\110\151\172\155\145\164\154\145\162\151\040\101\056\305\236
-\056\040\050\143\051\040\101\162\141\154\304\261\153\040\062\060
-\060\067
-END
-CKA_ID UTF8 0
-CKA_ISSUER MULTILINE_OCTAL
-\060\201\277\061\077\060\075\006\003\125\004\003\014\066\124\303
-\234\122\113\124\122\125\123\124\040\105\154\145\153\164\162\157
-\156\151\153\040\123\145\162\164\151\146\151\153\141\040\110\151
-\172\155\145\164\040\123\141\304\237\154\141\171\304\261\143\304
-\261\163\304\261\061\013\060\011\006\003\125\004\006\023\002\124
-\122\061\017\060\015\006\003\125\004\007\014\006\101\156\153\141
-\162\141\061\136\060\134\006\003\125\004\012\014\125\124\303\234
-\122\113\124\122\125\123\124\040\102\151\154\147\151\040\304\260

commit mozilla-nss for openSUSE:Factory

2012-12-28 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2012-12-28 22:45:31

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2012-10-26 
17:26:32.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2012-12-28 22:45:33.0 +0100
@@ -1,0 +2,7 @@
+Tue Dec 18 13:36:09 UTC 2012 - w...@rosenauer.org
+
+- update to 3.14.1 RTM
+  * minimal requirement for Gecko 20
+  * several bugfixes
+
+---

Old:

  nss-3.14.tar.bz2

New:

  nss-3.14.1.tar.bz2



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.t29570/_old  2012-12-28 22:45:34.0 +0100
+++ /var/tmp/diff_new_pack.t29570/_new  2012-12-28 22:45:34.0 +0100
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite3-devel
 BuildRequires:  zlib-devel
-Version:3.14
+Version:3.14.1
 Release:0
 # bug437293
 %ifarch ppc64



++ nss-3.14.tar.bz2 - nss-3.14.1.tar.bz2 ++
 28759 lines of diff (skipped)

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2012-10-26 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2012-10-26 17:26:31

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2012-08-16 
21:45:01.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2012-10-26 17:26:32.0 +0200
@@ -1,0 +2,21 @@
+Thu Oct 25 12:02:22 UTC 2012 - w...@rosenauer.org
+
+- update to 3.14 RTM
+  * Support for TLS 1.1 (RFC 4346)
+  * Experimental support for DTLS 1.0 (RFC 4347) and DTLS-SRTP (RFC 5764)
+  * Support for AES-CTR, AES-CTS, and AES-GCM
+  * Support for Keying Material Exporters for TLS (RFC 5705)
+  * Support for certificate signatures using the MD5 hash algorithm
+is now disabled by default
+  * The NSS license has changed to MPL 2.0. Previous releases were
+released under a MPL 1.1/GPL 2.0/LGPL  2.1 tri-license. For more
+information about MPL 2.0, please see
+http://www.mozilla.org/MPL/2.0/FAQ.html. For an additional
+explanation on GPL/LGPL compatibility, see security/nss/COPYING
+in the source code.
+  * Export and DES cipher suites are disabled by default. Non-ECC
+AES and Triple DES cipher suites are enabled by default
+- disabled OCSP testcases since they need external network
+  (nss-disable-ocsp-test.patch)
+
+---

Old:

  nss-3.13.6.tar.bz2

New:

  nss-3.14.tar.bz2
  nss-disable-ocsp-test.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.N9dmrS/_old  2012-10-26 17:26:33.0 +0200
+++ /var/tmp/diff_new_pack.N9dmrS/_new  2012-10-26 17:26:33.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite3-devel
 BuildRequires:  zlib-devel
-Version:3.13.6
+Version:3.14
 Release:0
 # bug437293
 %ifarch ppc64
@@ -33,7 +33,7 @@
 %endif
 #
 Summary:Network Security Services
-License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
+License:MPL-2.0
 Group:  System/Libraries
 Url:http://www.mozilla.org/projects/security/pki/nss/
 # cvs -d :pserver:anonym...@cvs-mirror.mozilla.org:/cvsroot co -r RTM_TAG NSS
@@ -53,6 +53,7 @@
 Patch4: nss-no-rpath.patch
 Patch5: renegotiate-transitional.patch
 Patch6: malloc.patch
+Patch7: nss-disable-ocsp-test.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr = %nspr_ver
 PreReq: libfreebl3 = %{nss_softokn_fips_version}
@@ -166,6 +167,7 @@
 %if %suse_version  1110
 %patch6
 %endif
+%patch7
 # additional CA certificates
 #cd security/nss/lib/ckfw/builtins
 #cat %{SOURCE2}  certdata.txt



++ nss-3.13.6.tar.bz2 - nss-3.14.tar.bz2 ++
 110375 lines of diff (skipped)

++ nss-disable-ocsp-test.patch ++
Index: security/nss/tests/chains/scenarios/scenarios
===
RCS file: /cvsroot/mozilla/security/nss/tests/chains/scenarios/scenarios,v
retrieving revision 1.9
diff -u -p -6 -r1.9 scenarios
--- security/nss/tests/chains/scenarios/scenarios   9 Nov 2009 14:18:58 
-   1.9
+++ security/nss/tests/chains/scenarios/scenarios   25 Oct 2012 13:40:00 
-
@@ -46,8 +46,7 @@ aia.cfg
 bridgewithaia.cfg
 bridgewithhalfaia.cfg
 bridgewithpolicyextensionandmapping.cfg
 realcerts.cfg
 dsa.cfg
 revoc.cfg
-ocsp.cfg
 crldp.cfg
++ nss-no-rpath.patch ++
--- /var/tmp/diff_new_pack.N9dmrS/_old  2012-10-26 17:26:36.0 +0200
+++ /var/tmp/diff_new_pack.N9dmrS/_new  2012-10-26 17:26:36.0 +0200
@@ -1,13 +1,16 @@
 Index: security/nss/cmd/platlibs.mk
 ===
 RCS file: /cvsroot/mozilla/security/nss/cmd/platlibs.mk,v
-retrieving revision 1.64
-diff -u -r1.64 platlibs.mk
 security/nss/cmd/platlibs.mk   17 Jun 2009 23:01:48 -  1.64
-+++ security/nss/cmd/platlibs.mk   31 Jul 2009 08:04:09 -
-@@ -53,9 +53,9 @@
+retrieving revision 1.71
+diff -u -p -6 -r1.71 platlibs.mk
+--- security/nss/cmd/platlibs.mk   17 Jul 2012 15:22:42 -  1.71
 security/nss/cmd/platlibs.mk   25 Oct 2012 12:07:35 -
+@@ -15,15 +15,15 @@ else
+ EXTRA_SHARED_LIBS += -R '$$ORIGIN/../lib:/usr/lib/mps/secv1:/usr/lib/mps'
+ endif
+ endif
+ 
  ifeq ($(OS_ARCH), Linux)
- ifeq ($(BUILD_SUN_PKG), 1)
  ifeq ($(USE_64), 1)
 -EXTRA_SHARED_LIBS += 
-Wl,-rpath,'$$ORIGIN/../lib64:/opt/sun/private/lib64:$$ORIGIN/../lib'
 +#EXTRA_SHARED_LIBS += 

commit mozilla-nss for openSUSE:Factory

2012-08-16 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2012-08-16 21:45:00

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2012-06-06 
16:08:59.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2012-08-16 21:45:01.0 +0200
@@ -1,0 +2,7 @@
+Wed Aug 15 13:57:42 UTC 2012 - w...@rosenauer.org
+
+- update to 3.13.6 RTM
+  * root CA update
+  * other bugfixes
+
+---

Old:

  nss-3.13.5.tar.bz2

New:

  nss-3.13.6.tar.bz2



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.QHYGcQ/_old  2012-08-16 21:45:18.0 +0200
+++ /var/tmp/diff_new_pack.QHYGcQ/_new  2012-08-16 21:45:18.0 +0200
@@ -25,7 +25,7 @@
 BuildRequires:  pkg-config
 BuildRequires:  sqlite3-devel
 BuildRequires:  zlib-devel
-Version:3.13.5
+Version:3.13.6
 Release:0
 # bug437293
 %ifarch ppc64



++ nss-3.13.5.tar.bz2 - nss-3.13.6.tar.bz2 ++
 3443 lines of diff (skipped)

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2012-06-06 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2012-06-06 16:08:48

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2012-04-17 
22:00:05.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2012-06-06 16:08:59.0 +0200
@@ -1,0 +2,5 @@
+Fri Jun  1 18:46:28 UTC 2012 - w...@rosenauer.org
+
+- update to 3.13.5 RTM
+
+---

Old:

  nss-3.13.4.tar.bz2

New:

  nss-3.13.5.tar.bz2



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.c779qQ/_old  2012-06-06 16:09:02.0 +0200
+++ /var/tmp/diff_new_pack.c779qQ/_new  2012-06-06 16:09:02.0 +0200
@@ -23,9 +23,9 @@
 BuildRequires:  gcc-c++
 BuildRequires:  mozilla-nspr-devel
 BuildRequires:  pkg-config
-BuildRequires:  zlib-devel
 BuildRequires:  sqlite3-devel
-Version:3.13.4
+BuildRequires:  zlib-devel
+Version:3.13.5
 Release:0
 # bug437293
 %ifarch ppc64
@@ -77,10 +77,10 @@
 %package devel
 Summary:Network (Netscape) Security Services development files
 Group:  Development/Libraries/Other
-Requires:   mozilla-nspr-devel
-Requires:   mozilla-nss = %{version}-%{release}
 Requires:   libfreebl3
 Requires:   libsoftokn3
+Requires:   mozilla-nspr-devel
+Requires:   mozilla-nss = %{version}-%{release}
 # bug437293
 %ifarch ppc64
 Obsoletes:  mozilla-nss-devel-64bit



++ nss-3.13.4.tar.bz2 - nss-3.13.5.tar.bz2 ++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/nss-3.13.4/mozilla/security/nss/lib/certdb/stanpcertdb.c 
new/nss-3.13.5/mozilla/security/nss/lib/certdb/stanpcertdb.c
--- old/nss-3.13.4/mozilla/security/nss/lib/certdb/stanpcertdb.c
2012-04-13 20:53:00.0 +0200
+++ new/nss-3.13.5/mozilla/security/nss/lib/certdb/stanpcertdb.c
2012-05-17 23:40:53.0 +0200
@@ -311,13 +311,15 @@
 }
 stanNick = nssCertificate_GetNickname(c, NULL);
 if (stanNick  nickname  strcmp(nickname, stanNick) != 0) {
-   /* take the new nickname */
+   /* different: take the new nickname */
cert-nickname = NULL;
+nss_ZFreeIf(stanNick);
stanNick = NULL;
 }
 if (!stanNick  nickname) {
-   stanNick = nssUTF8_Duplicate((NSSUTF8 *)nickname, c-object.arena);
-}
+/* Either there was no nickname yet, or we have a new nickname */
+   stanNick = nssUTF8_Duplicate((NSSUTF8 *)nickname, NULL);
+} /* else: old stanNick is identical to new nickname */
 /* Delete the temp instance */
 nssCertificateStore_Lock(context-certStore, lockTrace);
 nssCertificateStore_RemoveCertLOCKED(context-certStore, c);
@@ -336,6 +338,8 @@
   c-serial,
  cert-emailAddr,
   PR_TRUE);
+nss_ZFreeIf(stanNick);
+stanNick = NULL;
 PK11_FreeSlot(slot);
 if (!permInstance) {
if (NSS_GetError() == NSS_ERROR_INVALID_CERTIFICATE) {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/nss-3.13.4/mozilla/security/nss/lib/certhigh/certhigh.c 
new/nss-3.13.5/mozilla/security/nss/lib/certhigh/certhigh.c
--- old/nss-3.13.4/mozilla/security/nss/lib/certhigh/certhigh.c 2011-03-10 
05:29:04.0 +0100
+++ new/nss-3.13.5/mozilla/security/nss/lib/certhigh/certhigh.c 2012-05-17 
23:40:54.0 +0200
@@ -394,6 +394,8 @@
 stanNickname = nssCertificate_GetNickname(c,NULL);
 
 if ( stanNickname ) {
+nss_ZFreeIf(stanNickname);
+stanNickname = NULL;
if (names-what == SEC_CERT_NICKNAMES_USER) {
saveit = NSSCertificate_IsPrivateKeyAvailable(c, NULL, NULL);
}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/nss-3.13.4/mozilla/security/nss/lib/certhigh/certvfy.c 
new/nss-3.13.5/mozilla/security/nss/lib/certhigh/certvfy.c
--- old/nss-3.13.4/mozilla/security/nss/lib/certhigh/certvfy.c  2011-09-14 
02:28:47.0 +0200
+++ new/nss-3.13.5/mozilla/security/nss/lib/certhigh/certvfy.c  2012-04-24 
02:33:27.0 +0200
@@ -96,7 +96,7 @@
rv = NSS_GetAlgorithmPolicy(hashAlg, policyFlags);
if (rv == SECSuccess  
!(policyFlags  NSS_USE_ALG_IN_CERT_SIGNATURE)) {
-   PORT_SetError(SEC_ERROR_INVALID_ALGORITHM);
+   

commit mozilla-nss for openSUSE:Factory

2012-04-17 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2012-04-17 21:59:52

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2012-02-24 
12:06:12.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2012-04-17 22:00:05.0 +0200
@@ -1,0 +2,8 @@
+Fri Apr 13 18:55:57 UTC 2012 - w...@rosenauer.org
+
+- update to 3.13.4 RTM
+  * fixed some bugs
+  * fixed cert verification regression in PKIX mode (bmo#737802)
+introduced in 3.13.2
+
+---

Old:

  nss-3.13.3.tar.bz2

New:

  nss-3.13.4.tar.bz2



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.oKflLN/_old  2012-04-17 22:00:09.0 +0200
+++ /var/tmp/diff_new_pack.oKflLN/_new  2012-04-17 22:00:09.0 +0200
@@ -24,13 +24,8 @@
 BuildRequires:  mozilla-nspr-devel
 BuildRequires:  pkg-config
 BuildRequires:  zlib-devel
-%if %suse_version == 1030
-BuildRequires:  sqlite-devel
-%endif
-%if %suse_version  1030
 BuildRequires:  sqlite3-devel
-%endif
-Version:3.13.3
+Version:3.13.4
 Release:0
 # bug437293
 %ifarch ppc64



++ nss-3.13.3.tar.bz2 - nss-3.13.4.tar.bz2 ++
 2254 lines of diff (skipped)

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2012-02-24 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2012-02-24 12:06:05

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2012-02-17 
15:00:52.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2012-02-24 12:06:12.0 +0100
@@ -1,0 +2,7 @@
+Thu Feb 23 15:06:34 UTC 2012 - w...@rosenauer.org
+
+- update to 3.13.3 RTM
+  - distrust Trustwave's MITM certificates (bmo#724929)
+  - fix generic blacklisting mechanism (bmo#727204)
+
+---

Old:

  nss-3.13.2.tar.bz2

New:

  nss-3.13.3.tar.bz2



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.fD1iIu/_old  2012-02-24 12:06:14.0 +0100
+++ /var/tmp/diff_new_pack.fD1iIu/_new  2012-02-24 12:06:14.0 +0100
@@ -30,7 +30,7 @@
 %if %suse_version  1030
 BuildRequires:  sqlite3-devel
 %endif
-Version:3.13.2
+Version:3.13.3
 Release:0
 # bug437293
 %ifarch ppc64



++ nss-3.13.2.tar.bz2 - nss-3.13.3.tar.bz2 ++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/nss-3.13.2/mozilla/security/nss/lib/certhigh/certvfypkix.c 
new/nss-3.13.3/mozilla/security/nss/lib/certhigh/certvfypkix.c
--- old/nss-3.13.2/mozilla/security/nss/lib/certhigh/certvfypkix.c  
2011-11-17 01:20:21.0 +0100
+++ new/nss-3.13.3/mozilla/security/nss/lib/certhigh/certvfypkix.c  
2012-02-17 23:22:43.0 +0100
@@ -859,7 +859,7 @@
 void *plContext)
 {
 int errLevel = 0;
-PKIX_UInt32 nssErr = 0;
+PKIX_Int32 nssErr = 0;
 PKIX_Error *errPtr = error;
 
 PKIX_ENTER(CERTVFYPKIX, cert_PkixErrorToNssCode);
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/nss-3.13.2/mozilla/security/nss/lib/ckfw/builtins/certdata.c 
new/nss-3.13.3/mozilla/security/nss/lib/ckfw/builtins/certdata.c
--- old/nss-3.13.2/mozilla/security/nss/lib/ckfw/builtins/certdata.c
2012-01-17 23:02:37.0 +0100
+++ new/nss-3.13.3/mozilla/security/nss/lib/ckfw/builtins/certdata.c
2012-02-18 22:41:45.0 +0100
@@ -35,7 +35,7 @@
  *
  * * END LICENSE BLOCK * */
 #ifdef DEBUG
-static const char CVS_ID[] = @(#) $RCSfile: certdata.c,v $ $Revision: 1.84 $ 
$Date: 2012/01/17 22:02:37 $; @(#) $RCSfile: certdata.c,v $ $Revision: 1.84 $ 
$Date: 2012/01/17 22:02:37 $;
+static const char CVS_ID[] = @(#) $RCSfile: certdata.c,v $ $Revision: 1.85 $ 
$Date: 2012/02/18 21:41:45 $; @(#) $RCSfile: certdata.c,v $ $Revision: 1.85 $ 
$Date: 2012/02/18 21:41:45 $;
 #endif /* DEBUG */
 
 #ifndef BUILTINS_H
@@ -1075,6 +1075,12 @@
 static const CK_ATTRIBUTE_TYPE nss_builtins_types_339 [] = {
  CKA_CLASS,  CKA_TOKEN,  CKA_PRIVATE,  CKA_MODIFIABLE,  CKA_LABEL,  
CKA_CERT_SHA1_HASH,  CKA_CERT_MD5_HASH,  CKA_ISSUER,  CKA_SERIAL_NUMBER,  
CKA_TRUST_SERVER_AUTH,  CKA_TRUST_EMAIL_PROTECTION,  CKA_TRUST_CODE_SIGNING,  
CKA_TRUST_STEP_UP_APPROVED
 };
+static const CK_ATTRIBUTE_TYPE nss_builtins_types_340 [] = {
+ CKA_CLASS,  CKA_TOKEN,  CKA_PRIVATE,  CKA_MODIFIABLE,  CKA_LABEL,  
CKA_ISSUER,  CKA_SERIAL_NUMBER,  CKA_TRUST_SERVER_AUTH,  
CKA_TRUST_EMAIL_PROTECTION,  CKA_TRUST_CODE_SIGNING,  CKA_TRUST_STEP_UP_APPROVED
+};
+static const CK_ATTRIBUTE_TYPE nss_builtins_types_341 [] = {
+ CKA_CLASS,  CKA_TOKEN,  CKA_PRIVATE,  CKA_MODIFIABLE,  CKA_LABEL,  
CKA_ISSUER,  CKA_SERIAL_NUMBER,  CKA_TRUST_SERVER_AUTH,  
CKA_TRUST_EMAIL_PROTECTION,  CKA_TRUST_CODE_SIGNING,  CKA_TRUST_STEP_UP_APPROVED
+};
 #ifdef DEBUG
 static const NSSItem nss_builtins_items_0 [] = {
   { (void *)cko_data, (PRUint32)sizeof(CK_OBJECT_CLASS) },
@@ -1083,7 +1089,7 @@
   { (void *)ck_false, (PRUint32)sizeof(CK_BBOOL) },
   { (void *)CVS ID, (PRUint32)7 },
   { (void *)NSS, (PRUint32)4 },
-  { (void *)@(#) $RCSfile: certdata.c,v $ $Revision: 1.84 $ $Date: 2012/01/17 
22:02:37 $; @(#) $RCSfile: certdata.c,v $ $Revision: 1.84 $ $Date: 2012/01/17 
22:02:37 $, (PRUint32)160 }
+  { (void *)@(#) $RCSfile: certdata.c,v $ $Revision: 1.85 $ $Date: 2012/02/18 
21:41:45 $; @(#) $RCSfile: certdata.c,v $ $Revision: 1.85 $ $Date: 2012/02/18 
21:41:45 $, (PRUint32)160 }
 };
 #endif /* DEBUG */
 static const NSSItem nss_builtins_items_1 [] = {
@@ -22713,6 +22719,56 @@
   { (void *)ckt_nss_trusted_delegator, (PRUint32)sizeof(CK_TRUST) },
   { (void *)ck_false, (PRUint32)sizeof(CK_BBOOL) }
 };
+static const NSSItem nss_builtins_items_340 [] = {
+  { (void *)cko_nss_trust, 

commit mozilla-nss for openSUSE:Factory

2011-12-21 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2011-12-21 14:57:40

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2011-11-16 
17:19:59.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2011-12-21 14:57:40.0 +0100
@@ -1,0 +2,5 @@
+Sun Dec 18 15:59:08 UTC 2011 - adr...@suse.de
+
+- fix spec file syntax for qemu-workaround
+
+---



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.wQRzu8/_old  2011-12-21 14:57:42.0 +0100
+++ /var/tmp/diff_new_pack.wQRzu8/_new  2011-12-21 14:57:42.0 +0100
@@ -16,29 +16,31 @@
 # Please submit bugfixes or comments via http://bugs.opensuse.org/
 #
 
-# norootforbuild
 
 %global nss_softokn_fips_version 3.12.4
 
 Name:   mozilla-nss
-BuildRequires:  gcc-c++ mozilla-nspr-devel pkg-config zlib-devel
+BuildRequires:  gcc-c++
+BuildRequires:  mozilla-nspr-devel
+BuildRequires:  pkg-config
+BuildRequires:  zlib-devel
 %if %suse_version == 1030
 BuildRequires:  sqlite-devel
 %endif
 %if %suse_version  1030
 BuildRequires:  sqlite3-devel
 %endif
-License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Version:3.13.1
-Release:2
+Release:0
 # bug437293
 %ifarch ppc64
 Obsoletes:  mozilla-nss-64bit
 %endif
 #
 Summary:Network Security Services
-Url:http://www.mozilla.org/projects/security/pki/nss/
+License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Group:  System/Libraries
+Url:http://www.mozilla.org/projects/security/pki/nss/
 # cvs -d :pserver:anonym...@cvs-mirror.mozilla.org:/cvsroot co -r RTM_TAG NSS
 Source: nss-%{version}.tar.bz2
 Source1:nss.pc.in
@@ -65,9 +67,11 @@
 Requires:   mozilla-nss-certs
 BuildRoot:  %{_tmppath}/%{name}-%{version}-build
 %define nssdbdir %{_sysconfdir}/pki/nssdb
-%ifnarch %sparc  ! 0%{?qemu_user_space_build}
+%ifnarch %sparc 
+%if ! 0%{?qemu_user_space_build}
 %define run_testsuite 1
 %endif
+%endif
 
 %description
 Network Security Services (NSS) is a set of libraries designed to
@@ -78,7 +82,6 @@
 
 
 %package devel
-License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:Network (Netscape) Security Services development files
 Group:  Development/Libraries/Other
 Requires:   mozilla-nspr-devel
@@ -99,7 +102,6 @@
 
 
 %package tools
-License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:Tools for developing, debugging, and managing applications 
that use NSS
 Group:  System/Management
 PreReq: mozilla-nss = %{version}
@@ -110,7 +112,6 @@
 
 
 %package sysinit
-License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:System NSS Initialization
 Group:  System/Management
 Requires:   mozilla-nss = %{version}
@@ -124,7 +125,6 @@
 
 
 %package -n libfreebl3
-License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:Freebl library for the Network Security Services
 Group:  System/Libraries
 
@@ -139,7 +139,6 @@
 
 
 %package -n libsoftokn3
-License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:Network Security Services Softoken Module
 Group:  System/Libraries
 Requires:   libfreebl3 = %{version}-%{release}
@@ -155,7 +154,6 @@
 
 
 %package certs
-License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:CA certificates for NSS
 Group:  Productivity/Networking/Security
 



-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2011-12-06 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2011-12-06 18:29:55

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:




Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.EvWkDA/_old  2011-12-06 18:52:02.0 +0100
+++ /var/tmp/diff_new_pack.EvWkDA/_new  2011-12-06 18:52:02.0 +0100
@@ -28,7 +28,7 @@
 %if %suse_version  1030
 BuildRequires:  sqlite3-devel
 %endif
-License:MPLv1.1 or GPLv2+ or LGPLv2.1+
+License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Version:3.13.1
 Release:2
 # bug437293
@@ -78,7 +78,7 @@
 
 
 %package devel
-License:MPLv1.1 or GPLv2+ or LGPLv2.1+
+License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:Network (Netscape) Security Services development files
 Group:  Development/Libraries/Other
 Requires:   mozilla-nspr-devel
@@ -99,7 +99,7 @@
 
 
 %package tools
-License:MPLv1.1 or GPLv2+ or LGPLv2.1+
+License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:Tools for developing, debugging, and managing applications 
that use NSS
 Group:  System/Management
 PreReq: mozilla-nss = %{version}
@@ -110,7 +110,7 @@
 
 
 %package sysinit
-License:MPLv1.1 or GPLv2+ or LGPLv2.1+
+License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:System NSS Initialization
 Group:  System/Management
 Requires:   mozilla-nss = %{version}
@@ -124,7 +124,7 @@
 
 
 %package -n libfreebl3
-License:MPLv1.1 or GPLv2+ or LGPLv2.1+
+License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:Freebl library for the Network Security Services
 Group:  System/Libraries
 
@@ -139,7 +139,7 @@
 
 
 %package -n libsoftokn3
-License:MPLv1.1 or GPLv2+ or LGPLv2.1+
+License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:Network Security Services Softoken Module
 Group:  System/Libraries
 Requires:   libfreebl3 = %{version}-%{release}
@@ -155,7 +155,7 @@
 
 
 %package certs
-License:MPLv1.1 or GPLv2+ or LGPLv2.1+
+License:MPL-1.1 or GPL-2.0+ or LGPL-2.1+
 Summary:CA certificates for NSS
 Group:  Productivity/Networking/Security
 



-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2011-11-16 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2011-11-16 17:19:33

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2011-11-07 
14:22:40.0 +0100
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2011-11-16 17:19:59.0 +0100
@@ -1,0 +2,28 @@
+Mon Nov 14 10:13:17 UTC 2011 - j...@redux.org.uk
+
+- Added a patch to fix errors in the pkcs11n.h header file.
+  (bmo#702090)
+
+---
+Sat Nov  5 10:58:20 UTC 2011 - wolfg...@rosenauer.org
+
+- update to 3.13.1 RTM
+  * better SHA-224 support (bmo#647706)
+  * fixed a regression (causing hangs in some situations)
+introduced in 3.13 (bmo#693228)
+- update to 3.13.0 RTM
+  * SSL 2.0 is disabled by default
+  * A defense against the SSL 3.0 and TLS 1.0 CBC chosen plaintext
+attack demonstrated by Rizzo and Duong (CVE-2011-3389) is
+enabled by default. Set the SSL_CBC_RANDOM_IV SSL option to
+PR_FALSE to disable it.
+  * SHA-224 is supported
+  * Ported to iOS. (Requires NSPR 4.9.)
+  * Added PORT_ErrorToString and PORT_ErrorToName to return the
+error message and symbolic name of an NSS error code
+  * Added NSS_GetVersion to return the NSS version string
+  * Added experimental support of RSA-PSS to the softoken only
+  * NSS_NoDB_Init does not try to open /pkcs11.txt and /secmod.db
+anymore (bmo#641052, bnc#726096)
+
+---

Old:

  nss-3.12.11.tar.bz2
  nss-3.12.11_CVE-2011-3640.patch

New:

  nss-3.13.1.tar.bz2
  pkcs11n-header-fix.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.bVXNny/_old  2011-11-16 17:20:02.0 +0100
+++ /var/tmp/diff_new_pack.bVXNny/_new  2011-11-16 17:20:02.0 +0100
@@ -29,8 +29,8 @@
 BuildRequires:  sqlite3-devel
 %endif
 License:MPLv1.1 or GPLv2+ or LGPLv2.1+
-Version:3.12.11
-Release:6
+Version:3.13.1
+Release:2
 # bug437293
 %ifarch ppc64
 Obsoletes:  mozilla-nss-64bit
@@ -57,7 +57,7 @@
 Patch6: renegotiate-transitional.patch
 Patch9: malloc.patch
 Patch10:ckbi-1_88.patch
-Patch11:nss-3.12.11_CVE-2011-3640.patch
+Patch11:pkcs11n-header-fix.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr = %nspr_ver
 PreReq: libfreebl3 = %{nss_softokn_fips_version}
@@ -189,7 +189,6 @@
 find . -name '*.[ch]' -print -exec sed -i 
s/__DATE__/${DATE}/g;s/__TIME__/${TIME}/g {} +
 
 cd mozilla/security/nss
-#cp %SOURCE10 tests/libpkix/certs/PayPalEE.cert
 export FREEBL_NO_DEPEND=1
 export NSPR_INCLUDE_DIR=`nspr-config --includedir`
 export NSPR_LIB_DIR=`nspr-config --libdir`


++ ckbi-1_88.patch ++
 3534 lines (skipped)
 between /work/SRC/openSUSE:Factory/mozilla-nss/ckbi-1_88.patch
 and /work/SRC/openSUSE:Factory/.mozilla-nss.new/ckbi-1_88.patch


++ nss-3.12.11.tar.bz2 - nss-3.13.1.tar.bz2 ++
 36559 lines of diff (skipped)

++ pkcs11n-header-fix.patch ++
diff -r -U 10 nss-3.13.1.orig/mozilla/security/nss/lib/util/pkcs11n.h 
nss-3.13.1/mozilla/security/nss/lib/util/pkcs11n.h
--- security/nss/lib/util/pkcs11n.h 2011-11-14 09:53:46.703144803 +
+++ security/nss/lib/util/pkcs11n.h 2011-11-14 09:59:07.226273312 +
@@ -339,37 +339,37 @@
  * to cache resolution data.
  */
 #define CKT_NSS_VALID_DELEGATOR(CKT_NSS + 11)
 
 
 /*
  * old definitions. They still exist, but the plain meaning of the
  * labels have never been accurate to what was really implemented.
  * The new labels correctly reflect what the values effectively mean.
  */
-#if __GNUC__  3
+#if defined(__GNUC__)  (__GNUC__  3)
 /* make GCC warn when we use these #defines */
 /*
  *  This is really painful because GCC doesn't allow us to mark random
  *  #defines as deprecated. We can only mark the following:
  *  functions, variables, and types.
  *  const variables will create extra storage for everyone including this
  *   header file, so it's undesirable.
  *  functions could be inlined to prevent storage creation, but will fail
  *   when constant values are expected (like switch statements).
  *  enum types do not seem to pay attention to the deprecated attribute.
  *
  *  That leaves typedefs. We declare new types that we then deprecate, then
  *  cast the resulting value to the deprecated type in the #define, thus
  *  producting the 

commit mozilla-nss for openSUSE:Factory

2011-11-07 Thread h_root
Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory 
checked in at 2011-11-07 14:22:38

Comparing /work/SRC/openSUSE:Factory/mozilla-nss (Old)
 and  /work/SRC/openSUSE:Factory/.mozilla-nss.new (New)


Package is mozilla-nss, Maintainer is gnome-maintain...@suse.de

Changes:

--- /work/SRC/openSUSE:Factory/mozilla-nss/mozilla-nss.changes  2011-10-02 
10:18:58.0 +0200
+++ /work/SRC/openSUSE:Factory/.mozilla-nss.new/mozilla-nss.changes 
2011-11-07 14:22:40.0 +0100
@@ -1,0 +2,7 @@
+Sat Nov  5 10:47:51 UTC 2011 - w...@rosenauer.org
+
+- explicitely distrust DigiCert Sdn. Bhd (bnc#728520, bmo#698753)
+- make sure NSS_NoDB_Init does not try to use wrong certificate
+  databases (CVE-2011-3640, bnc#726096, bmo#641052)
+
+---

Old:

  nss-3.12.11-diginotar.patch

New:

  ckbi-1_88.patch
  nss-3.12.11_CVE-2011-3640.patch



Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.CUe4UH/_old  2011-11-07 14:22:42.0 +0100
+++ /var/tmp/diff_new_pack.CUe4UH/_new  2011-11-07 14:22:42.0 +0100
@@ -56,7 +56,8 @@
 Patch5: nss-no-rpath.patch
 Patch6: renegotiate-transitional.patch
 Patch9: malloc.patch
-Patch10:nss-3.12.11-diginotar.patch
+Patch10:ckbi-1_88.patch
+Patch11:nss-3.12.11_CVE-2011-3640.patch
 %define nspr_ver %(rpm -q --queryformat '%{VERSION}' mozilla-nspr)
 PreReq: mozilla-nspr = %nspr_ver
 PreReq: libfreebl3 = %{nss_softokn_fips_version}
@@ -174,7 +175,8 @@
 %if %suse_version  1110
 %patch9
 %endif
-%patch10 -p2
+%patch10 -p1
+%patch11
 # additional CA certificates
 #cd security/nss/lib/ckfw/builtins
 #cat %{SOURCE2}  certdata.txt


++ ckbi-1_88.patch ++
 3930 lines (skipped)


++ nss-3.12.11_CVE-2011-3640.patch ++
Index: security/nss/lib/softoken/sftkmod.c
===
RCS file: /cvsroot/mozilla/security/nss/lib/softoken/sftkmod.c,v
retrieving revision 1.7
diff -u -p -r1.7 sftkmod.c
--- security/nss/lib/softoken/sftkmod.c 11 Jun 2009 06:28:07 -  1.7
+++ security/nss/lib/softoken/sftkmod.c 5 Nov 2011 11:55:24 -
@@ -179,15 +179,18 @@ char *sftk_getOldSecmodName(const char *
 char *sep;
 
 sep = PORT_Strrchr(dirPath,*PATH_SEPARATOR);
-#ifdef WINDOWS
+#ifdef _WIN32
 if (!sep) {
-   sep = PORT_Strrchr(dirPath,'/');
+   /* pkcs11i.h defines PATH_SEPARATOR as / for all platforms. */
+   sep = PORT_Strrchr(dirPath,'\\');
 }
 #endif
 if (sep) {
-   *(sep)=0;
+   *sep = 0;
+   file = PR_smprintf(%sPATH_SEPARATOR%s, dirPath, filename);
+} else {
+   file = PR_smprintf(%s, filename);
 }
-file= PR_smprintf(%sPATH_SEPARATOR%s, dirPath, filename);
 PORT_Free(dirPath);
 return file;
 }
@@ -242,13 +245,18 @@ sftkdb_ReadSecmodDB(SDBType dbType, cons
 char *paramsValue=NULL;
 PRBool failed = PR_TRUE;
 
-if ((dbType == SDB_LEGACY) || (dbType == SDB_MULTIACCESS)) {
+if ((dbname != NULL) 
+   ((dbType == SDB_LEGACY) || (dbType == SDB_MULTIACCESS))) {
return sftkdbCall_ReadSecmodDB(appName, filename, dbname, params, rw);
 }
 
 moduleList = (char **) PORT_ZAlloc(useCount*sizeof(char **));
 if (moduleList == NULL) return NULL;
 
+if (dbname == NULL) {
+   goto return_default;
+}
+
 /* do we really want to use streams here */
 fd = fopen(dbname, r);
 if (fd == NULL) goto done;
@@ -405,7 +413,11 @@ sftkdb_ReadSecmodDB(SDBType dbType, cons
moduleString = NULL;
 }
 done:
-/* if we couldn't open a pkcs11 database, look for the old one */
+/* If we couldn't open a pkcs11 database, look for the old one.
+ * This is necessary to maintain the semantics of the transition from
+ * old to new DB's. If there is an old DB and not new DB, we will
+ * automatically use the old DB. If the DB was opened read/write, we
+ * create a new db and upgrade it from the old one. */
 if (fd == NULL) {
char *olddbname = sftk_getOldSecmodName(dbname,filename);
PRStatus status;
@@ -462,6 +474,8 @@ bail:
PR_smprintf_free(olddbname);
}
 }
+
+return_default:

 if (!moduleList[0]) {
char * newParams;
@@ -515,7 +529,8 @@ sftkdb_ReleaseSecmodDBData(SDBType dbTyp
const char *filename, const char *dbname, 
char **moduleSpecList, PRBool rw)
 {
-if ((dbType == SDB_LEGACY) || (dbType == SDB_MULTIACCESS)) {
+if ((dbname != NULL) 
+   ((dbType == SDB_LEGACY) || (dbType == SDB_MULTIACCESS))) {
return 

commit mozilla-nss for openSUSE:Factory

2011-10-02 Thread h_root

Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory
checked in at Sun Oct 2 10:19:00 CEST 2011.




--- openSUSE:Factory/mozilla-nss/mozilla-nss.changes2011-09-23 
02:13:22.0 +0200
+++ /mounts/work_src_done/STABLE/mozilla-nss/mozilla-nss.changes
2011-10-01 01:27:40.0 +0200
@@ -1,0 +2,5 @@
+Fri Sep 30 23:27:07 UTC 2011 - crrodrig...@opensuse.org
+
+- Workaround qemu-arm bugs. 
+
+---

calling whatdependson for head-i586




Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.gBx6F9/_old  2011-10-02 10:18:57.0 +0200
+++ /var/tmp/diff_new_pack.gBx6F9/_new  2011-10-02 10:18:57.0 +0200
@@ -64,7 +64,7 @@
 Requires:   mozilla-nss-certs
 BuildRoot:  %{_tmppath}/%{name}-%{version}-build
 %define nssdbdir %{_sysconfdir}/pki/nssdb
-%ifnarch %sparc
+%ifnarch %sparc  ! 0%{?qemu_user_space_build}
 %define run_testsuite 1
 %endif
 



continue with q...



Remember to have fun...

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



commit mozilla-nss for openSUSE:Factory

2011-09-11 Thread h_root

Hello community,

here is the log from the commit of package mozilla-nss for openSUSE:Factory
checked in at Sun Sep 11 19:30:51 CEST 2011.




--- GNOME/mozilla-nss/mozilla-nss.changes   2011-09-02 17:49:38.0 
+0200
+++ /mounts/work_src_done/STABLE/mozilla-nss/mozilla-nss.changes
2011-09-09 07:51:09.0 +0200
@@ -1,0 +2,6 @@
+Fri Sep  9 05:44:15 UTC 2011 - w...@rosenauer.org
+
+- explicitely distrust/override DigiNotar certs (bmo#683261)
+  (trustdb version 1.87)
+
+---
@@ -4 +10 @@
-- removed DigiNotar root certifiate from trusted db
+- removed DigiNotar root certificate from trusted db

calling whatdependson for head-i586




Other differences:
--
++ mozilla-nss.spec ++
--- /var/tmp/diff_new_pack.06dbHs/_old  2011-09-11 19:30:43.0 +0200
+++ /var/tmp/diff_new_pack.06dbHs/_new  2011-09-11 19:30:43.0 +0200
@@ -30,7 +30,7 @@
 %endif
 License:MPLv1.1 or GPLv2+ or LGPLv2.1+
 Version:3.12.11
-Release:4
+Release:6
 # bug437293
 %ifarch ppc64
 Obsoletes:  mozilla-nss-64bit



++ nss-3.12.11-diginotar.patch ++
 3105 lines (skipped)
 between GNOME/mozilla-nss/nss-3.12.11-diginotar.patch
 and /mounts/work_src_done/STABLE/mozilla-nss/nss-3.12.11-diginotar.patch






Remember to have fun...

-- 
To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org
For additional commands, e-mail: opensuse-commit+h...@opensuse.org



  1   2   >